Free resource

Cyber incident response plan pack

An incident response plan is a decision document, written in advance, for people who will be tired and missing information. This is one you can adapt, plus the Australian notification clock and a ninety minute tabletop exercise that shows you where the gaps are.

What is inside

Four parts, seven pages

Short steps, named roles, and no sentence that requires interpretation at two in the morning.

01

The decisions to settle before anything happens

Who declares an incident, who can isolate a machine without asking anybody, who speaks to customers, when legal and insurance are told, and who keeps the timeline.

02

The first hour, step by step

Declare and record the time, contain, preserve evidence, assess what was reachable, and tell staff. Including the containment error we see most often, which is resetting a password without revoking active sessions and leaving the intruder signed in.

03

The Australian notification clock

The notifiable data breaches obligation and when the clock starts, your insurer notification window, contractual periods that are often shorter than the statutory one, and the state government frameworks.

04

A ninety minute tabletop exercise

A realistic Friday afternoon scenario and seven questions to work through as a group. Every one you cannot answer with a name and a next step is a gap, and finding it there costs ninety minutes rather than a weekend.

Who it is for

Two situations this is written for

It assumes you do not have a security operations centre, because most organisations do not.

You have no plan and need one

Part two is the document. Fill in the names, agree the severity levels, and run the tabletop in part four to find what you have missed.

Start at part two

You have a plan nobody has tested

Go straight to part four. Ninety minutes with the right people will tell you more about the plan than another read-through of it.

Start at part four

Free download

Send me the incident response pack

We use your details to send you this document and to answer you if you get in touch. We do not add you to a mailing list and we do not pass your details to anybody else. See our privacy policy.

Common questions

Questions about the pack

What people ask before giving an email address for something.

What does it cost?

Nothing. We are vendor funded, so the service costs your business nothing.

Will I be added to a sales sequence?

No. You receive the pack, and we contact you only if you ask us to.

Is this legal advice on our notification obligations?

No. Part three is a summary to plan against, and you should confirm your own obligations with your adviser before an incident rather than during one.

We use a managed security provider. Do we still need this?

Yes, and it is arguably more important. The questions the pack forces you to answer are about your decisions, not theirs, and the most useful one is what your provider is permitted to do without you at two in the morning.

What is the single most common gap you see?

No named person who is allowed to disconnect something without approval. That one missing sentence turns a ninety minute incident into a six hour one.

How often should we run the tabletop?

Once a year is enough to keep it real, and after any change to the people in the named roles. A plan full of people who have left is the usual state of an untested one.

We are vendor funded and completely free to your business. Always focused on the right outcome.

The gaps are usually in what you bought

Response cover that stops before your business day does, a provider who can alert but not act, telemetry you cannot reach, and detection rules that stay with the provider when you leave.

Book a Call

Independent guidance at no cost to your business.

Read further on this

The pages and articles that answer the next question a buyer usually asks.