Back to Resources
Incident Response Plan Template: visual preview
Template

Incident Response Plan Template

End-to-End Incident Management Procedures

Overview

An incident response plan is the operational backbone of any cybersecurity program. It defines how your organization detects, contains, eradicates, and recovers from security incidents while preserving evidence and maintaining communications. This template follows the NIST SP 800-61 lifecycle and can be adapted to any industry or regulatory environment.

Incident Response Lifecycle Phases

  • Preparation: establish policies, train staff, and deploy detection tooling
  • Detection and Analysis: monitor alerts, validate indicators, and classify severity
  • Containment: isolate affected systems to prevent lateral movement
  • Eradication: remove the root cause, patch vulnerabilities, and harden controls
  • Recovery: restore services, verify system integrity, and monitor for recurrence
  • Post-Incident Activity: conduct a lessons-learned review and update the plan

Severity Classification Matrix

SeverityDescriptionResponse SLAEscalation
Critical (P1)Active data exfiltration or ransomware impacting production15 minutesCISO, Legal, CEO
High (P2)Confirmed compromise with no active exfiltration1 hourCISO, SOC Lead
Medium (P3)Suspicious activity requiring investigation4 hoursSOC Lead, IR Team
Low (P4)Policy violation or informational alert24 hoursSOC Analyst

Roles and Responsibilities

Define an incident commander who owns decision-making authority during active incidents. Assign a communications lead responsible for internal updates and external notifications. The forensics lead manages evidence collection, chain of custody, and analysis. Each role must have a primary and backup to ensure 24/7 coverage. Document escalation paths and contact lists, and test them quarterly.

Communication and Notification Procedures

  • Establish pre-approved notification templates for customers, regulators, and law enforcement
  • Define internal communication channels separate from potentially compromised systems
  • Set clear criteria for when to engage outside counsel and forensic vendors
  • Maintain a stakeholder contact list with phone, email, and backup communication methods
  • Document regulatory notification deadlines for each applicable framework

Evidence Preservation Guidelines

Preserve volatile data first: memory dumps, running processes, and network connections. Use write-blockers when imaging disks. Log all actions taken with timestamps and analyst names. Store evidence in a secure, access-controlled repository with documented chain of custody. Engage legal counsel early if litigation or law-enforcement involvement is anticipated.

Testing and Maintenance

Conduct at least two tabletop exercises per year, one focused on ransomware and one on data exfiltration. Run a full functional exercise annually that tests technical playbooks end to end. After every real incident and every exercise, update the plan with lessons learned. Review contact lists and escalation paths quarterly to ensure accuracy.

Frequently asked questions