Free resource
Cyber incident response plan pack
An incident response plan is a decision document, written in advance, for people who will be tired and missing information. This is one you can adapt, plus the Australian notification clock and a ninety minute tabletop exercise that shows you where the gaps are.
What is inside
Four parts, seven pages
Short steps, named roles, and no sentence that requires interpretation at two in the morning.
Who it is for
Two situations this is written for
It assumes you do not have a security operations centre, because most organisations do not.
You have no plan and need one
Part two is the document. Fill in the names, agree the severity levels, and run the tabletop in part four to find what you have missed.
Start at part two
You have a plan nobody has tested
Go straight to part four. Ninety minutes with the right people will tell you more about the plan than another read-through of it.
Start at part four
Free download
Send me the incident response pack
We use your details to send you this document and to answer you if you get in touch. We do not add you to a mailing list and we do not pass your details to anybody else. See our privacy policy.
Common questions
Questions about the pack
What people ask before giving an email address for something.
What does it cost?
Nothing. We are vendor funded, so the service costs your business nothing.
Will I be added to a sales sequence?
No. You receive the pack, and we contact you only if you ask us to.
Is this legal advice on our notification obligations?
No. Part three is a summary to plan against, and you should confirm your own obligations with your adviser before an incident rather than during one.
We use a managed security provider. Do we still need this?
Yes, and it is arguably more important. The questions the pack forces you to answer are about your decisions, not theirs, and the most useful one is what your provider is permitted to do without you at two in the morning.
What is the single most common gap you see?
No named person who is allowed to disconnect something without approval. That one missing sentence turns a ninety minute incident into a six hour one.
How often should we run the tabletop?
Once a year is enough to keep it real, and after any change to the people in the named roles. A plan full of people who have left is the usual state of an untested one.
We are vendor funded and completely free to your business. Always focused on the right outcome.
The gaps are usually in what you bought
Response cover that stops before your business day does, a provider who can alert but not act, telemetry you cannot reach, and detection rules that stay with the provider when you leave.
Book a Call
Independent guidance at no cost to your business.
Read further on this
The pages and articles that answer the next question a buyer usually asks.

