← All articles

The one-page incident response plan

·2 min read·By Adrian

Also available in ES, RO

Incident response plans fail for a mundane reason: they are stored on the systems that are down, in a format nobody reads under pressure.

Make it one page, printed

Genuinely printed, and in the folder in the office, because during an incident your file server may be encrypted and your email unavailable.

What belongs on it

Who decides. One named person with authority to disconnect systems, stop trading and spend money, plus a deputy. Ambiguity here costs hours.

Who to call, with numbers. IT provider, cyber insurer, legal adviser, data protection authority, bank fraud line, key customers. Mobile numbers, not internal extensions.

The first five actions. Written as instructions, not principles:

  1. Isolate affected machines from the network, do not power them off
  2. Call the decision-maker
  3. Start a written log with timestamps
  4. Preserve evidence — no reimaging until told
  5. Do not pay anything, and do not reply to the attacker

"Do not power off" surprises people. Memory contents are often the only evidence of how the intrusion worked.

What must keep running. The three systems the business genuinely cannot trade without, and the manual fallback for each.

Reporting deadlines. Under GDPR, seventy-two hours to notify the supervisory authority of a personal data breach. Under NIS2, if in scope, twenty-four hours for an early warning. Write the actual deadlines and the actual contacts.

Rehearse it once a year

Ninety minutes around a table. Describe a scenario, and have people say what they would do. You are looking for the gaps:

  • The only person who can authorise a shutdown is on a flight
  • Nobody knows the insurance policy number
  • The backup administrator left in March
  • The out-of-hours number rings in an empty office

Every one of those is trivial to fix in advance and expensive to discover live.

The plan's purpose is not to cover every scenario. It is to make sure the first hour is not spent deciding who is in charge.

We write and rehearse these with clients as part of cybersecurity work.

← Blog