## Purpose

This plan defines how the company should identify, coordinate, contain, investigate, communicate, recover from, and review a cybersecurity incident.

The objective is to provide a clear process before an emergency occurs so employees and leadership do not have to invent one during a crisis.

## Scope

This plan may be activated for incidents involving:

- Compromised accounts
- Phishing or business email compromise
- Ransomware
- Malware
- Data exposure
- Payment fraud
- Lost or stolen devices
- Unauthorized access
- Cloud or SaaS compromise
- Vendor compromise
- Insider misuse
- Website compromise
- Denial of service
- Significant security control failure

## Incident Ownership

Primary Incident Response Lead: ____________________

Backup Incident Response Lead: ____________________

Leadership Contact: ____________________

IT / MSP Contact: ____________________

Legal Contact: ____________________

Cyber Insurance Contact: ____________________

External Incident Response Provider: ____________________

## 1. Activate the Incident Response Process

**Activate this plan when an event may create meaningful:**

- Business disruption
- Financial loss
- Data exposure
- Unauthorized access
- Customer impact
- Legal or regulatory risk
- Security compromise

**The Incident Response Lead should establish:**

- An incident identifier
- A central incident record
- A secure communication channel
- A timeline
- Assigned responsibilities

## 2. Perform Initial Triage

**Determine:**

- What happened?
- When was it discovered?
- Is the activity still occurring?
- Which accounts, devices, systems, or data may be affected?
- Is there immediate business or safety impact?
- Does the attacker still appear to have access?
- Is sensitive information involved?
- Could other systems be affected?

Record facts separately from assumptions.

## 3. Preserve Evidence

Before making unnecessary changes, preserve relevant information where practical.

**This may include:**

- Security alerts
- Authentication logs
- Email messages
- Cloud audit logs
- Endpoint logs
- Network logs
- Screenshots
- Files
- Malware samples
- Account activity
- Administrative changes
- Relevant communications

Do not unnecessarily wipe, rebuild, delete, or modify affected systems before considering evidence requirements.

## 4. Contain the Incident

**Containment actions may include:**

- Disabling compromised accounts
- Revoking active sessions
- Resetting credentials
- Blocking malicious domains or IP addresses
- Isolating devices
- Removing public sharing
- Restricting remote access
- Disabling compromised integrations
- Suspending vendor access
- Protecting backups
- Removing unnecessary internet exposure

Containment should reduce attacker access while considering operational impact and evidence preservation.

## 5. Escalate Appropriate Support

**Depending on the incident, contact:**

- Leadership
- MSP or IT provider
- Cyber insurer
- Incident response provider
- Legal counsel
- Privacy or compliance adviser
- Cloud or SaaS provider
- Bank or payment provider
- Relevant vendor
- Law enforcement where appropriate

Do not make ransomware payment or attacker negotiation decisions without appropriate leadership, legal, insurance, and specialist advice.

## 6. Determine Scope

Investigate whether similar activity exists elsewhere.

**Review:**

- Other accounts
- Other endpoints
- Administrator accounts
- Cloud services
- Email
- Remote access
- Vendor access
- Data sharing
- Backups
- Security tools
- Network infrastructure

**Identify what is:**

- Confirmed affected
- Possibly affected
- Checked and not affected
- Still unknown

## 7. Eradicate the Cause

Before normal recovery, address the cause where practical.

**Examples include:**

- Removing malware
- Closing vulnerabilities
- Removing malicious accounts
- Revoking compromised credentials
- Removing persistence
- Fixing insecure configurations
- Removing unauthorized OAuth applications
- Updating firewall rules
- Patching exploited systems

## 8. Recover Safely

Restore systems according to business priorities.

**Confirm:**

- Restore source is trustworthy
- Required security fixes are applied
- Credentials are safe
- Access is appropriate
- Monitoring is operating
- Backups resume
- Business owners validate functionality

Recovery should not recreate the conditions that caused the incident.

## 9. Communicate

Communications should be accurate, controlled, and approved.

**Consider communications to:**

- Leadership
- Employees
- Customers
- Vendors
- Insurers
- Legal advisers
- Regulators
- Banks
- Law enforcement

Avoid making unverified statements such as “no data was affected” before the facts support them.

## 10. Close and Review

**Before closing the incident:**

- Confirm containment
- Confirm recovery
- Document remaining risks
- Preserve required evidence
- Complete required reporting
- Assign improvement actions
- Conduct a post-incident review

## Practical Rule

During an incident:

Coordinate, preserve, contain, escalate, investigate, recover, and learn.
