Incident Response

Building an Incident Response Plan Before You Need One

September 2026 · 4 min read

The worst time to decide who is in charge of a security incident is during one. An incident response plan does not need to be long, but it does need to exist and be understood.

Start with roles. Name an incident lead, a technical lead, someone responsible for communications and someone with authority to make business decisions. Include deputies, because incidents do not wait for holidays.

Define what counts as an incident and how severity is judged. A simple three-level scale is enough. What matters is that everyone agrees when to escalate.

Write down the first hour. Decide who is contacted, which systems can be isolated without asking permission, how evidence is preserved and where the team communicates if email is compromised.

Prepare contacts in advance: legal advice, insurers, key suppliers, your regulator if one applies and an external response partner. Finding phone numbers in the middle of an incident wastes time.

Then test it. A tabletop exercise, where the team talks through a realistic scenario, exposes gaps in a couple of hours and costs almost nothing.

Keep the plan short enough to be used under stress. A five-page plan people know beats a fifty-page plan nobody has read.

Want Help With This?

If this touched on something you are dealing with right now, we are happy to talk it through.

More Reading

Related Articles