The Plan You Need Before the Worst Day
Your cyber insurer requires it, regulators from the FTC to New York’s DFS expect it, and the first hour of a real incident is decided by whether it exists. Here’s what a working incident response plan contains, and a starter kit that gives you the template.
Get the Free Incident Response Plan Starter Kit
Six plain English pages including a fill in the blanks IR plan template, the first hour playbook, and the tabletop exercise. Instant delivery.
No spam. Unsubscribe anytime. Your information stays private.
Why a Written Plan, Why Now
An incident response plan stopped being a best practice and became a requirement, from three directions at once.
Your Insurer Requires It
Cyber insurance applications ask directly whether a written incident response plan exists and gets tested. Answering yes without one risks the claim exactly when you need it. Answering no raises the premium or kills the quote.
Regulators Expect It
The FTC Safeguards Rule requires a written incident response plan. New York’s DFS regulation adds a 72 hour reporting clock. HIPAA expects breach response procedures. Whatever your industry, at least one of these probably reaches you.
The First Hour Is Unforgiving
Disconnect or preserve, pay or refuse, call whom first: incidents force decisions immediately, under stress, with incomplete information. A plan makes those decisions in advance, calmly, which is the entire point.
What a Working Plan Contains
Forget the 40 page binder. A plan people actually use fits on a few pages and answers four things.
Who Does What
An incident commander with a deputy, and named owners for technical response, communications, legal and insurance contact, and documentation. Small businesses double up roles, and that’s fine. Unnamed roles are the failure mode.
The First Hour Steps
Isolate affected systems without wiping evidence, preserve logs, engage your IT or security partner, notify the insurer’s breach hotline before authorizing spending, and start the written timeline. In that order, on a card.
The Contacts and Clocks
Insurer hotline, IT partner, counsel, and regulator channels, with the notification deadlines that apply to your business written next to them. Clocks like 72 hours are only survivable when nobody has to research them mid crisis.
The Communication Lines
Who speaks to employees, customers, and if needed the public, and who explicitly doesn’t. Also: how the team talks if email itself is compromised, decided before it is.
What's in the Starter Kit
The guide is a working document, not a lecture. Adapt the template, run the exercise, and put the card in the drawer.
The Fill In the Blanks Template
A complete one page IR plan with bracketed placeholders: roles, severity levels, first hour steps, contacts, and clocks. Replace the brackets and publish.
The First Hour Playbook
The numbered sequence for the moment of discovery, including the do not list: don’t wipe, don’t pay, don’t email about the breach from breached systems.
The Severity Ladder
Three levels that tell your team what counts as an incident, who gets woken up, and when the full plan activates, so nobody debates definitions at 2 AM.
The Notification Clock Map
The common regulator and insurer deadlines in one place, matched to the kinds of data your business holds.
The Tabletop Exercise
A one hour scripted walkthrough your leadership team can run this quarter, because a plan that’s never been rehearsed is a theory.
The Leadership Checklist
Ten items that keep the plan alive: review dates, contact updates, and the evidence insurers and regulators ask to see.
Common Questions
Do we really need a written incident response plan?
Yes, and probably by requirement, not just prudence. Cyber insurance applications ask for one, the FTC Safeguards Rule requires one for covered businesses, New York’s DFS regulation expects one behind its 72 hour reporting clock, and HIPAA expects breach response procedures. Beyond compliance, the first hour of a real incident goes dramatically better with decisions made in advance.
What should we do in the first hour of a cyber incident?
Isolate affected systems without destroying evidence, preserve logs, engage your IT or security partner, call your insurer’s breach hotline before authorizing response spending, and start a written timeline of everything known and done. Equally important is the do not list: don’t wipe systems, don’t pay anything, and don’t discuss the breach over potentially compromised email.
Who should be on our incident response team?
An incident commander with authority to make decisions, plus named owners for technical response, communications, legal and insurance contact, and documentation. In a small business people hold multiple roles, which works fine. The failure mode is roles nobody claimed, discovered during the incident.
What is a tabletop exercise?
A scheduled walkthrough of a realistic scenario, ransomware on a Friday, a compromised email account, a lost laptop, where the team talks through the plan step by step. It takes about an hour, costs nothing, and reliably finds the gaps: outdated contacts, unclear authority, missing steps, before a real incident finds them for you.
What is in the free incident response plan starter kit?
A six page kit containing a fill in the blanks one page IR plan template, the first hour playbook with the do not list, a three level severity ladder, a notification clock reference, a one hour tabletop exercise script, and a leadership checklist that keeps the plan current.
Start With the Guide. Decide From There.
Download the Incident Response Plan Starter Kit and have a working plan drafted this week. If you’d rather have your whole security posture verified first, a free confidential assessment is available too.