FREE TEMPLATE
Incident Response Plan
Who to call, in what order, and what not to do. Written to be read at 11pm by whoever is awake, with the call list you keep printed.
[COMPANY NAME]
Effective date: [DATE] · Owner: [NAME, TITLE] · Review: annually, and after every incident
Purpose
This plan says who does what when something goes wrong, so that the answer is not decided at 11pm by whoever happens to be awake.
Scope
Applies to any suspected or confirmed security incident affecting [COMPANY NAME] systems, accounts or data — including malware and ransomware, a compromised account, a wire or payment fraud attempt, lost or stolen equipment, unauthorized access, or a breach at a vendor holding your data.
Call list
Fill this in now. During an incident is the wrong time to look up a phone number.
| Role | Name | Phone | Alternate contact |
|---|---|---|---|
| Incident lead | |||
| Business owner / executive | |||
| IT provider | |||
| Cyber insurance carrier — claims | Policy #: | ||
| Legal counsel | |||
| Bank — fraud department | |||
| Payroll provider | |||
| Primary software vendor |
Keep a printed copy. If the incident takes out email and file storage, a contact list stored in email and file storage is not a contact list.
What counts as an incident
Report it if you see any of the following, even if you are not sure:
- A ransom message, or files that will not open and have odd extensions
- Multiple systems slowing or failing at once
- MFA prompts you did not request
- An email from a colleague or vendor asking to change bank details or move money
- A sent-items folder containing messages you did not send
- A lost or stolen laptop, phone or backup drive
- Notice from a vendor that they have been breached
- A customer telling you they received something strange from your address
Reporting a false alarm carries no penalty. Staying quiet does.
Immediate actions
If you think a device is infected:
Disconnect it from the network — unplug the cable, turn off wireless. Do not turn it off. Powering down can destroy evidence stored in memory that helps determine what happened and what was taken.
Then call the incident lead.
If you think you gave away credentials: change that password from a different device and call the incident lead.
If money has moved: call the bank’s fraud line immediately, then the incident lead. The window to recall a wire is measured in hours.
Response steps
1 — Contain. Isolate affected systems. Disable affected accounts, reset credentials and revoke active sessions. Preserve evidence; do not wipe or rebuild anything before the incident lead approves it.
2 — Notify. The incident lead contacts the business owner, the IT provider, and — for anything beyond a single contained device — the cyber insurance carrier. Notify the carrier early. Most policies require prompt notice, and many will deny a claim, or refuse to pay for a responder you chose yourself, if you brought them in late.
3 — Assess. Determine what systems and accounts were involved, what data was reachable, whether data left the environment, and whether that data includes personal information triggering notification obligations.
4 — Eradicate and recover. Remove the cause. Rebuild from known-good images where compromise is suspected. Restore from backup only after confirming the backup predates the compromise. Reset every credential that was, or may have been, exposed.
5 — Communicate. Counsel and the carrier direct external communication. Do not notify customers, post publicly or speculate about cause before that direction. Do keep staff informed of what they need to do.
6 — Review. Within [NUMBER] days of closure, the incident lead documents what happened, how it was found, what worked, what did not, and what changes follow. Update this plan accordingly.
Legal notification
Breaches involving personal information carry notification deadlines under state law, and potentially under HIPAA, GLBA, PCI DSS or your customer contracts. Deadlines are short and they vary.
Counsel determines what notice is required and when. This plan does not.
Evidence
Preserve logs, affected devices, ransom notes, suspicious emails with full headers, and a written timeline of who did what and when. Start the timeline at the first report and keep it as the incident runs — reconstructing it afterward is unreliable, and it is the first thing an insurer asks for.
Testing
This plan is walked through at least annually as a tabletop exercise: a scenario, the people who would actually respond, and an honest look at where the plan breaks. The date and findings of each exercise are recorded.
An untested plan is a document. A tested plan is a capability.
Review
Reviewed at least annually by [POLICY OWNER], and after every incident and every tabletop exercise.
Template provided free by Cybertitans LLC, Woodbury, Minnesota. It is a starting point, not legal advice, and it has not been reviewed against your contracts, your industry’s regulations or your state’s notification statutes. Have counsel review it before you adopt it. Downloading or using this template does not create a client relationship with Cybertitans, and Cybertitans makes no representation that adopting it satisfies any insurer, regulator, auditor or customer requirement.
EDITABLE VERSION
Want the Word version you can edit?
The policy above is free to read, copy and adapt — that is the point of publishing it. The Word file is the same text with every fill-in field marked, our formatting, and the contact and escalation tables ready to fill in. Tell us where to send it.
Free. About 20 seconds.
Where should we send it?
THE REST OF THE SET
Nine more, and someone to run them.
This is one of ten free templates written for businesses with no IT department. The others are on the resource library, and the editable Word versions are a name and an email away.
A policy nobody operates is a document. If you would rather someone owned this — and the offboarding, the backups and the MFA behind it — that is what TiTAN is.
