The Incident Response Plan You Can Actually Run

The 40-page IR framework helps no one at 2 a.m. The first-hour moves, the five named roles, and the pre-made decisions that make a plan runnable.

Illustration of a clock face with the first hour highlighted as a sunset gradient wedge

Most incident response plans fail the only test that matters: 2 a.m., systems down, and the person holding the plan has never read it. The 40-page framework document satisfied the auditor and helps no one under pressure. What a growing company needs is a plan short enough to execute while adrenaline is doing the thinking.

The first hour, decided in advance

When something's wrong, four moves happen in order. Isolate, don't wipe — disconnect affected machines from the network but leave them running; wiping destroys the forensic evidence your insurer and investigators need. Call the insurer's hotline — most cyber policies require notification before you engage help, and using non-approved vendors can jeopardize coverage; the hotline number belongs on the first page of the plan, printed, because the plan stored on the encrypted server is a joke that writes itself. Move to out-of-band communications — if email is compromised, coordinating the response over email briefs the attacker; pre-agree on a channel that isn't your corporate stack. Convene the named roles — which brings us to the plan itself.

Names, not titles

A runnable plan assigns five roles to actual humans with phone numbers: an incident commander with authority to make expensive calls (take systems offline, engage counsel) without convening a committee; a technical lead; a communications owner for customers and staff; a legal/compliance contact; and an executive sponsor who keeps ownership informed without letting panic drive. Every role has a backup, because incidents schedule themselves for vacation weeks.

The decisions to pre-make

The worst time to form policy is mid-crisis. Decide now, in writing: what severity triggers full activation versus watch-and-log; who may speak to customers, and what the first holding statement says; under what circumstances you'd consider paying a ransom (and the sanctions-screening step that legally must precede it); and what your breach-notification obligations are by state and by contract — your enterprise customers' MSAs almost certainly contain notification clocks measured in hours.

Rehearse it or it isn't real

A tabletop exercise twice a year — ninety minutes, one scenario, walk the plan — finds the broken assumptions cheaply: the hotline number that changed, the backup contact who left the company, the "isolate the server" step nobody actually knows how to perform. Insurers increasingly ask for tabletop dates on the questionnaire, so the rehearsal that makes you competent also makes you cheaper to insure.

Where to start

If you have no plan, a one-page version with the four first-hour moves and five named roles beats every framework binder ever printed — you can draft it this week. Building, testing, and maintaining that plan is standing work in our security practice and a core artifact in renewal readiness. Book a call and we'll pressure-test whatever you have — including if what you have is nothing.