Cyber Incident Response Plan
Purpose
This plan defines how the company should identify, coordinate, contain, investigate, communicate, recover from, and review a cybersecurity incident.
The objective is to provide a clear process before an emergency occurs so employees and leadership do not have to invent one during a crisis.
Scope
This plan may be activated for incidents involving:
- Compromised accounts
- Phishing or business email compromise
- Ransomware
- Malware
- Data exposure
- Payment fraud
- Lost or stolen devices
- Unauthorized access
- Cloud or SaaS compromise
- Vendor compromise
- Insider misuse
- Website compromise
- Denial of service
- Significant security control failure
Incident Ownership
Primary Incident Response Lead: ____________________
Backup Incident Response Lead: ____________________
Leadership Contact: ____________________
IT / MSP Contact: ____________________
Legal Contact: ____________________
Cyber Insurance Contact: ____________________
External Incident Response Provider: ____________________
1. Activate the Incident Response Process
Activate this plan when an event may create meaningful:
- Business disruption
- Financial loss
- Data exposure
- Unauthorized access
- Customer impact
- Legal or regulatory risk
- Security compromise
The Incident Response Lead should establish:
- An incident identifier
- A central incident record
- A secure communication channel
- A timeline
- Assigned responsibilities
2. Perform Initial Triage
Determine:
- What happened?
- When was it discovered?
- Is the activity still occurring?
- Which accounts, devices, systems, or data may be affected?
- Is there immediate business or safety impact?
- Does the attacker still appear to have access?
- Is sensitive information involved?
- Could other systems be affected?
Record facts separately from assumptions.
3. Preserve Evidence
Before making unnecessary changes, preserve relevant information where practical.
This may include:
- Security alerts
- Authentication logs
- Email messages
- Cloud audit logs
- Endpoint logs
- Network logs
- Screenshots
- Files
- Malware samples
- Account activity
- Administrative changes
- Relevant communications
Do not unnecessarily wipe, rebuild, delete, or modify affected systems before considering evidence requirements.
4. Contain the Incident
Containment actions may include:
- Disabling compromised accounts
- Revoking active sessions
- Resetting credentials
- Blocking malicious domains or IP addresses
- Isolating devices
- Removing public sharing
- Restricting remote access
- Disabling compromised integrations
- Suspending vendor access
- Protecting backups
- Removing unnecessary internet exposure
Containment should reduce attacker access while considering operational impact and evidence preservation.
5. Escalate Appropriate Support
Depending on the incident, contact:
- Leadership
- MSP or IT provider
- Cyber insurer
- Incident response provider
- Legal counsel
- Privacy or compliance adviser
- Cloud or SaaS provider
- Bank or payment provider
- Relevant vendor
- Law enforcement where appropriate
Do not make ransomware payment or attacker negotiation decisions without appropriate leadership, legal, insurance, and specialist advice.
6. Determine Scope
Investigate whether similar activity exists elsewhere.
Review:
- Other accounts
- Other endpoints
- Administrator accounts
- Cloud services
- Remote access
- Vendor access
- Data sharing
- Backups
- Security tools
- Network infrastructure
Identify what is:
- Confirmed affected
- Possibly affected
- Checked and not affected
- Still unknown
7. Eradicate the Cause
Before normal recovery, address the cause where practical.
Examples include:
- Removing malware
- Closing vulnerabilities
- Removing malicious accounts
- Revoking compromised credentials
- Removing persistence
- Fixing insecure configurations
- Removing unauthorized OAuth applications
- Updating firewall rules
- Patching exploited systems
8. Recover Safely
Restore systems according to business priorities.
Confirm:
- Restore source is trustworthy
- Required security fixes are applied
- Credentials are safe
- Access is appropriate
- Monitoring is operating
- Backups resume
- Business owners validate functionality
Recovery should not recreate the conditions that caused the incident.
9. Communicate
Communications should be accurate, controlled, and approved.
Consider communications to:
- Leadership
- Employees
- Customers
- Vendors
- Insurers
- Legal advisers
- Regulators
- Banks
- Law enforcement
Avoid making unverified statements such as “no data was affected” before the facts support them.
10. Close and Review
Before closing the incident:
- Confirm containment
- Confirm recovery
- Document remaining risks
- Preserve required evidence
- Complete required reporting
- Assign improvement actions
- Conduct a post-incident review
Practical Rule
During an incident:
Coordinate, preserve, contain, escalate, investigate, recover, and learn.