Cyber Incident Response Plan

Purpose

This plan defines how the company should identify, coordinate, contain, investigate, communicate, recover from, and review a cybersecurity incident.

The objective is to provide a clear process before an emergency occurs so employees and leadership do not have to invent one during a crisis.

Scope

This plan may be activated for incidents involving:

  • Compromised accounts
  • Phishing or business email compromise
  • Ransomware
  • Malware
  • Data exposure
  • Payment fraud
  • Lost or stolen devices
  • Unauthorized access
  • Cloud or SaaS compromise
  • Vendor compromise
  • Insider misuse
  • Website compromise
  • Denial of service
  • Significant security control failure

Incident Ownership

Primary Incident Response Lead: ____________________

Backup Incident Response Lead: ____________________

Leadership Contact: ____________________

IT / MSP Contact: ____________________

Legal Contact: ____________________

Cyber Insurance Contact: ____________________

External Incident Response Provider: ____________________

1. Activate the Incident Response Process

Activate this plan when an event may create meaningful:

  • Business disruption
  • Financial loss
  • Data exposure
  • Unauthorized access
  • Customer impact
  • Legal or regulatory risk
  • Security compromise

The Incident Response Lead should establish:

  • An incident identifier
  • A central incident record
  • A secure communication channel
  • A timeline
  • Assigned responsibilities

2. Perform Initial Triage

Determine:

  • What happened?
  • When was it discovered?
  • Is the activity still occurring?
  • Which accounts, devices, systems, or data may be affected?
  • Is there immediate business or safety impact?
  • Does the attacker still appear to have access?
  • Is sensitive information involved?
  • Could other systems be affected?

Record facts separately from assumptions.

3. Preserve Evidence

Before making unnecessary changes, preserve relevant information where practical.

This may include:

  • Security alerts
  • Authentication logs
  • Email messages
  • Cloud audit logs
  • Endpoint logs
  • Network logs
  • Screenshots
  • Files
  • Malware samples
  • Account activity
  • Administrative changes
  • Relevant communications

Do not unnecessarily wipe, rebuild, delete, or modify affected systems before considering evidence requirements.

4. Contain the Incident

Containment actions may include:

  • Disabling compromised accounts
  • Revoking active sessions
  • Resetting credentials
  • Blocking malicious domains or IP addresses
  • Isolating devices
  • Removing public sharing
  • Restricting remote access
  • Disabling compromised integrations
  • Suspending vendor access
  • Protecting backups
  • Removing unnecessary internet exposure

Containment should reduce attacker access while considering operational impact and evidence preservation.

5. Escalate Appropriate Support

Depending on the incident, contact:

  • Leadership
  • MSP or IT provider
  • Cyber insurer
  • Incident response provider
  • Legal counsel
  • Privacy or compliance adviser
  • Cloud or SaaS provider
  • Bank or payment provider
  • Relevant vendor
  • Law enforcement where appropriate

Do not make ransomware payment or attacker negotiation decisions without appropriate leadership, legal, insurance, and specialist advice.

6. Determine Scope

Investigate whether similar activity exists elsewhere.

Review:

  • Other accounts
  • Other endpoints
  • Administrator accounts
  • Cloud services
  • Email
  • Remote access
  • Vendor access
  • Data sharing
  • Backups
  • Security tools
  • Network infrastructure

Identify what is:

  • Confirmed affected
  • Possibly affected
  • Checked and not affected
  • Still unknown

7. Eradicate the Cause

Before normal recovery, address the cause where practical.

Examples include:

  • Removing malware
  • Closing vulnerabilities
  • Removing malicious accounts
  • Revoking compromised credentials
  • Removing persistence
  • Fixing insecure configurations
  • Removing unauthorized OAuth applications
  • Updating firewall rules
  • Patching exploited systems

8. Recover Safely

Restore systems according to business priorities.

Confirm:

  • Restore source is trustworthy
  • Required security fixes are applied
  • Credentials are safe
  • Access is appropriate
  • Monitoring is operating
  • Backups resume
  • Business owners validate functionality

Recovery should not recreate the conditions that caused the incident.

9. Communicate

Communications should be accurate, controlled, and approved.

Consider communications to:

  • Leadership
  • Employees
  • Customers
  • Vendors
  • Insurers
  • Legal advisers
  • Regulators
  • Banks
  • Law enforcement

Avoid making unverified statements such as “no data was affected” before the facts support them.

10. Close and Review

Before closing the incident:

  • Confirm containment
  • Confirm recovery
  • Document remaining risks
  • Preserve required evidence
  • Complete required reporting
  • Assign improvement actions
  • Conduct a post-incident review

Practical Rule

During an incident:

Coordinate, preserve, contain, escalate, investigate, recover, and learn.