Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Field Manual

Incident Response Plan Template

Copy, adapt and use this as a starting point for your organisation.

Disclaimer: Template only. Not legal advice. Adapt before use.

Purpose

This plan defines how the organisation will respond to suspected cyber incidents.

Immediate actions

  1. Stop and preserve evidence.
  2. Report to the named incident contact.
  3. Contain affected accounts, devices or services.
  4. Record decisions and times.
  5. Escalate where data, money or critical services may be affected.

Roles

RoleNameContact
Incident Lead[Name][Contact]
IT Provider[Name][Contact]
Senior Decision Maker[Name][Contact]