Most plans fail for two reasons at once: nobody had read it, and it lived on the share that just got encrypted.
This document gets judged exactly once, at speed, by people who had no hand in writing it. Everything follows from that. It has to be short, reachable when the network is not, unambiguous about who has authority over what, and rehearsed enough that the first run-through is not the actual emergency.

- Findable offlineBecause the file share may be down
- Named decisionsWho declares, who authorizes, who speaks
- ExercisedA plan never rehearsed is a document
- CIS Control 17Incident response management, in the eighteen
Seven things that separate a plan from a document.
Named people, named deputies, and current numbers
Naming only roles ages badly. Naming individuals without a backup collapses the moment one of them is on a plane. What works is the person, their deputy, and a way to reach either that does not run through corporate email or the corporate network, since in a real incident both may be down or actively untrustworthy.
A declaration threshold somebody can apply at 3am
The single most consequential moment is the one where somebody says this is now an incident. A plan promising that the security team will assess severity and respond appropriately gives absolutely nothing to the person actually holding the phone at midnight. What helps is a threshold written as things you can observe, plus the name of whoever is allowed to make the call.
Decision rights, especially the expensive ones
Who is allowed to pull a production system down. Who can cut an entire site off the network. Who can commit money to external responders, and how much before a second signature is needed. Who decides that no ransom will be paid. In practice these get decided under pressure by whoever happens to be awake, and pre-authorizing them removes the single largest source of delay in most real incidents.
External contacts, gathered before you need them
Incident response retainer, cyber insurance carrier notification route and policy number, breach counsel, key vendors, and the account team at each critical supplier. For public companies, the officers involved in a materiality determination belong on this list too. Assembling it is an afternoon of work in peacetime and a very bad hour during an incident.
Scenario playbooks, not one general procedure
Ransomware, a compromised mailbox, data walking out the door, a trusted insider, and a critical supplier going dark all behave differently and demand different opening moves. One general procedure handles every one of them poorly. Three or four playbooks of two pages each handle the realistic cases properly, and people actually read them.
Exercised, because that is where the plan gets fixed
Rehearsal surfaces what reading never will: the contact who resigned in March, the decision everybody deferred, the quiet assumption that a particular system would still be up. The federal guidance is built around preparing for incident responses, and an exercise is the moment preparation stops being a document.
Available when the network is not
Kept only on the file share, or only inside Teams, it is unreachable in precisely the incidents where it counts. Paper copies in the hands of the people who need them, plus one copy stored entirely outside the environment, is unfashionable and it is the whole difference between having a plan and having had one.
Three questions decide everything: is this an incident, who says so, and can that server be pulled off the network.
Nearly every plan we are asked to review answers all three in language nobody could act on at two in the morning.
- Whether this counts as an incident. Written as conditions somebody can observe rather than a severity judgment, so whoever is on call can apply it without first needing to be the most senior person in the company.
- Who has the authority. One named person and one named deputy, contactable by a route that does not rely on the corporate network or corporate mail, since either may be down or compromised.
- Can we take that offline. Pre-authorized containment decisions with a named authorizer and a clear boundary, because the delay between recognizing containment is needed and being permitted to do it is where most damage accumulates.
- Everything else in the document matters less than these three. Two pages that answer them concretely beat forty pages that answer them in principle and cannot be located while the incident is running.
Four things that decide whether it holds up on the day.
We agree the decisions before we write the document
Who calls it, at what threshold, who may disconnect systems, who may commit money, who talks to the outside, and where counsel comes in. That is the plan. A document written before those are settled is a tidy list of unanswered questions, and every one of them gets asked again at the worst imaginable moment.
Short enough that somebody reads it while the room is loud
A core document readable in ten minutes, plus two-page playbooks for the scenarios that could actually happen to you. Length and use run in opposite directions. The exhaustive plan covering every conceivable eventuality is the one that stays closed, because nobody reads forty pages at two in the morning with the phone ringing.
We verify the contact pack by calling it
The responder retainer, your carrier and its policy number, breach counsel, and the critical vendors with named account teams. A contact list nobody has dialed is a list of assumptions. Calling every entry on a quiet Tuesday takes one afternoon and reliably turns up two or three that are wrong.
We exercise it before we call it finished
A tabletop with the real response team against a scenario that fits your business. What comes out is a list of corrections, not a grade, because the objective is finding the gaps while fixing them still costs almost nothing. An unexercised plan is a draft no matter how well it reads.
Four phases, and it is the rehearsal that finishes the plan rather than the writing.
- 01Weeks 1 to 2
Establish the decisions before the document
Who declares one, against what threshold, who authorizes containment, who authorizes spending money, who speaks to the outside world, and who notifies whom, including the point where breach counsel takes over. Those answers are the plan. Drafting the document before settling them produces a beautifully formatted list of open questions.
- Declaration threshold expressed in observable conditions
- Named decision makers with named deputies
- Pre-authorized containment boundaries
- Spend authority for external response agreed in advance
- 02Weeks 3 to 4
Write it short, and build the contact pack
A core document short enough to read while an incident is running, with playbooks of roughly two pages per scenario. Then the external contact pack: responders, your carrier with the policy number, breach counsel, and critical vendors with their account teams, each one verified by an actual phone call rather than copied out of a three-year-old file.
- A core document short enough that somebody will genuinely read it
- Scenario playbooks for the realistic cases
- A verified external contact pack, tested by calling
- Out-of-band communication arrangements agreed
- 03Weeks 5 to 6
Exercise it, and fix what the exercise finds
A tabletop run with the people who would really be in the room, against a scenario that could plausibly happen to your business. Nobody passes or fails. What comes out is a correction list: the contact who left last spring, the decision nobody felt authorized to make, the system everybody assumed would still be reachable.
- A tabletop exercise with the real response team
- A findings list from the exercise, not a certificate
- Plan corrected against what the exercise revealed
- Second exercise scheduled before the engagement closes
- 04Ongoing
Keep it current, because it decays quietly
People resign, numbers get reassigned, systems get replaced, and suppliers change hands. The document rots quietly and the rot is invisible right up until somebody opens it in anger. A short quarterly pass over the contact list and a written review after any material change is what keeps it usable.
- Quarterly contact verification
- Review after any material change to people or systems
- An exercise at least annually, ideally more often
- Offline copies refreshed when the plan changes
Six moments when American companies write one of these, and one where they wish they had.
A company with notification obligations and a clock that starts on recognition
State breach notification statutes, sector rules such as HIPAA, and SEC disclosure obligations for public companies all share one property: the process starts at a point somebody has to recognize. That makes the declaration threshold and the escalation to counsel a compliance control rather than an operational preference, and it needs to be written, exercised, and evidenced rather than understood.
An organization renewing cyber insurance
Underwriters now routinely ask three things: is there a plan, when was it last rehearsed, and is the notification route written down. Each takes a sentence to answer if the work exists and produces an awkward silence if it does not. The route to your carrier, with the policy number beside it, belongs inside the plan itself, because a great many policies make coverage conditional on prompt notice.
A group of companies where nobody can say who actually decides
Multi-company groups face the worst version of this, because whoever can authorize taking a subsidiary system offline may sit in a different legal entity and a different time zone. Establishing that during an incident burns hours. Establishing it beforehand takes a single meeting.
An operator where disconnecting means stopping production
Containment is easy when unplugging something merely annoys people. It becomes a real commercial decision when unplugging stops a plant, a production line, or a distribution center. IT cannot make that call, and nobody can make it quickly unless the authority and its limits were settled in advance.
A healthcare organization where systems cannot simply be turned off
Clinical systems change the containment arithmetic completely, and the plan has to be written with clinical staff in the room rather than assuming a standard playbook transfers. It must name who weighs patient safety against containment, what information they need to do it, and exactly what falling back to paper looks like, with the HIPAA notification obligations run through counsel in parallel.
An organization that has just watched a peer be attacked
This is the cheapest prompt available and by far the best moment to do the work. Attention exists, the board is already asking, and nobody is operating under duress. A plan written and rehearsed in that window costs a fraction of one assembled in the wreckage of your own incident, and it turns out considerably better.
How US organizations are prepared for an incident.
| Feature | Exercised and current | A plan that has never been used | No plan |
|---|---|---|---|
A written plan exists | Yes | Yes | No |
Available when the network is not | Yes | No | Not applicable |
Declaration threshold actionable | Yes | Vague | Not applicable |
Containment pre-authorized | Yes | No | No |
Contacts verified | Yes | Stale | None |
Scenario playbooks | Yes | One general procedure | No |
Exercised in the last year | Yes | No | No |
External responders identified in advance | Yes | No | No |
Insurer notification route known | Yes | Rarely | No |
First hour of a real incident | Structured | Improvised | Chaotic |
Five scenarios, and why the opening hour looks nothing alike across them.
Scenario
Ransomware
- What the first hour is about
- Determining spread and stopping it, before anything else
- The decision that cannot wait
- Whether to disconnect, and who is permitted to authorize it
Scenario
Business email compromise
- What the first hour is about
- Working out what the account touched and whether any money has already left
- The decision that cannot wait
- Contacting the bank, and who can instruct a recall
Scenario
Data exfiltration
- What the first hour is about
- Establishing what left, when, and whose it was
- The decision that cannot wait
- Whether counsel needs to start a notification analysis now
Scenario
Insider action
- What the first hour is about
- Preserving evidence before the person is aware
- The decision that cannot wait
- Who gets told, in which sequence, and where HR and counsel come in
Scenario
Critical vendor outage or compromise
- What the first hour is about
- Establishing your exposure through their access and their data
- The decision that cannot wait
- Whether to cut the connection at all, and who actually owns that vendor relationship
Five steps, finishing with a rehearsal rather than a delivered file.
- 1
Establish the decisions and the obligations
Who declares an incident and at what threshold, who authorizes containment and within what boundary, who authorizes emergency spend and up to what value, who speaks externally, and what notification obligations apply from state statutes, sector regulation, contracts, or insurance, mapped with your counsel. These are agreed before anything is written.
- 2
Write a core plan somebody will read
Kept short, with the three questions answered on page one: is this an incident, who calls it, and what may be disconnected. Roles carry named people and named deputies. Communication arrangements assume neither the corporate network nor corporate email is available or trustworthy.
- 3
Build scenario playbooks for the realistic cases
Five playbooks of roughly two pages: ransomware, a compromised mailbox, data leaving the building, a trusted insider, and a breach at a critical supplier. They are separate because the opening hour is genuinely different in each. One catch-all procedure handles every case poorly and reads as though nobody had a specific incident in mind while writing it.
- 4
Assemble and verify the contact pack
Your responders, your carrier with both the policy number and the notification route, breach counsel, and each critical supplier with a named account team. Then we phone every one of them, because a list nobody has dialed is a set of assumptions, and two or three usually turn out to be wrong.
- 5
Exercise, correct, and schedule the next one
A tabletop with the genuine response team against a scenario that fits your business, producing corrections rather than a score. The document is then updated against what the exercise exposed, offline copies go out to the people who need them, and the next rehearsal is in the calendar before we leave, because scheduling it later never happens.
What organizations ask about incident response plans.
Fifteen questions worth putting to the plan sitting in your drive right now.
Could you find it
- Where is it stored?If the only answer is the file share, write that down as finding one.
- Is there an offline copy?With the people who would need it.
- When did anyone last open it?Access logs answer this honestly.
- How long is it?Length is inversely related to use.
- Would a new hire understand it?They may be the one on call.
Could you act on it
- What is the declaration threshold?Observable conditions, not a judgment.
- Who declares, and who deputizes?Both named, not roles.
- Who can take a system offline?Pre-authorized, with a boundary.
- Who can authorize emergency spend?And up to what value.
- Who speaks to customers and press?Decided now, not then.
Is it current
- Are all the contacts still employed?Check, do not assume.
- Have the numbers been dialed?A contact pack is untested until called.
- Does it reference systems you still run?Plans outlive platforms.
- Is your insurer notification route in it?With the policy number.
- When was it last exercised?If never, it is a draft.
The pages around this one.
Pick three colleagues and ask where the incident response plan lives. Then ask when they last opened it.
If the first answer is the file share and the second is never, you have already found the two most common failures without our help. Both take weeks to fix. Neither can be fixed while an incident is underway.
Related Services
Explore more solutions that work great with this service
Cyber Incident Response
Cyber incident response for US businesses. 24/7 on-call IR engineers
Learn moreRansomware Protection
Layered ransomware protection for US businesses covering prevention
Learn moreSecurity Policy Development
Security policy development for US organizations: obligations
Learn moreSOC-as-a-Service
24/7 security operations delivered as a service
Learn moreData Backup
Automated backup and data protection
Learn moreIT Compliance
HIPAA, SOC 2, NIST, CMMC, CCPA readiness
Learn more