FREE TEMPLATE

Incident Response Plan

Who to call, in what order, and what not to do. Written to be read at 11pm by whoever is awake, with the call list you keep printed.

[COMPANY NAME]

Effective date: [DATE] · Owner: [NAME, TITLE] · Review: annually, and after every incident

Purpose

This plan says who does what when something goes wrong, so that the answer is not decided at 11pm by whoever happens to be awake.

Scope

Applies to any suspected or confirmed security incident affecting [COMPANY NAME] systems, accounts or data — including malware and ransomware, a compromised account, a wire or payment fraud attempt, lost or stolen equipment, unauthorized access, or a breach at a vendor holding your data.

Call list

Fill this in now. During an incident is the wrong time to look up a phone number.

RoleNamePhoneAlternate contact
Incident lead
Business owner / executive
IT provider
Cyber insurance carrier — claimsPolicy #:
Legal counsel
Bank — fraud department
Payroll provider
Primary software vendor

Keep a printed copy. If the incident takes out email and file storage, a contact list stored in email and file storage is not a contact list.

What counts as an incident

Report it if you see any of the following, even if you are not sure:

  • A ransom message, or files that will not open and have odd extensions
  • Multiple systems slowing or failing at once
  • MFA prompts you did not request
  • An email from a colleague or vendor asking to change bank details or move money
  • A sent-items folder containing messages you did not send
  • A lost or stolen laptop, phone or backup drive
  • Notice from a vendor that they have been breached
  • A customer telling you they received something strange from your address

Reporting a false alarm carries no penalty. Staying quiet does.

Immediate actions

If you think a device is infected:

Disconnect it from the network — unplug the cable, turn off wireless. Do not turn it off. Powering down can destroy evidence stored in memory that helps determine what happened and what was taken.

Then call the incident lead.

If you think you gave away credentials: change that password from a different device and call the incident lead.

If money has moved: call the bank’s fraud line immediately, then the incident lead. The window to recall a wire is measured in hours.

Response steps

1 — Contain. Isolate affected systems. Disable affected accounts, reset credentials and revoke active sessions. Preserve evidence; do not wipe or rebuild anything before the incident lead approves it.

2 — Notify. The incident lead contacts the business owner, the IT provider, and — for anything beyond a single contained device — the cyber insurance carrier. Notify the carrier early. Most policies require prompt notice, and many will deny a claim, or refuse to pay for a responder you chose yourself, if you brought them in late.

3 — Assess. Determine what systems and accounts were involved, what data was reachable, whether data left the environment, and whether that data includes personal information triggering notification obligations.

4 — Eradicate and recover. Remove the cause. Rebuild from known-good images where compromise is suspected. Restore from backup only after confirming the backup predates the compromise. Reset every credential that was, or may have been, exposed.

5 — Communicate. Counsel and the carrier direct external communication. Do not notify customers, post publicly or speculate about cause before that direction. Do keep staff informed of what they need to do.

6 — Review. Within [NUMBER] days of closure, the incident lead documents what happened, how it was found, what worked, what did not, and what changes follow. Update this plan accordingly.

Legal notification

Breaches involving personal information carry notification deadlines under state law, and potentially under HIPAA, GLBA, PCI DSS or your customer contracts. Deadlines are short and they vary.

Counsel determines what notice is required and when. This plan does not.

Evidence

Preserve logs, affected devices, ransom notes, suspicious emails with full headers, and a written timeline of who did what and when. Start the timeline at the first report and keep it as the incident runs — reconstructing it afterward is unreliable, and it is the first thing an insurer asks for.

Testing

This plan is walked through at least annually as a tabletop exercise: a scenario, the people who would actually respond, and an honest look at where the plan breaks. The date and findings of each exercise are recorded.

An untested plan is a document. A tested plan is a capability.

Review

Reviewed at least annually by [POLICY OWNER], and after every incident and every tabletop exercise.

Template provided free by Cybertitans LLC, Woodbury, Minnesota. It is a starting point, not legal advice, and it has not been reviewed against your contracts, your industry’s regulations or your state’s notification statutes. Have counsel review it before you adopt it. Downloading or using this template does not create a client relationship with Cybertitans, and Cybertitans makes no representation that adopting it satisfies any insurer, regulator, auditor or customer requirement.

EDITABLE VERSION

Want the Word version you can edit?

The policy above is free to read, copy and adapt — that is the point of publishing it. The Word file is the same text with every fill-in field marked, our formatting, and the contact and escalation tables ready to fill in. Tell us where to send it.

Free. About 20 seconds.

THE REST OF THE SET

Nine more, and someone to run them.

This is one of ten free templates written for businesses with no IT department. The others are on the resource library, and the editable Word versions are a name and an email away.

A policy nobody operates is a document. If you would rather someone owned this — and the offboarding, the backups and the MFA behind it — that is what TiTAN is.

Book 20 Minutes