Most incident response plans sit in a folder and are never tested. This guide shows you how to build, test, and continuously improve an IR plan that contains breaches before they become catastrophes.
IBM's Cost of a Data Breach Report consistently finds that organisations with a tested incident response plan contain breaches 54 days faster and spend an average of $2.66 million less per incident than those without one. The difference between a company that recovers and one that folds after a breach is almost always preparation.
Yet most IR plans are documents created once, filed away, and never revisited until a crisis — at which point they are outdated, incomplete, and useless. This guide walks you through building a living incident response programme that actually works under pressure.
NIST SP 800-61 defines the six phases that every IR programme must cover:
1. Preparation — Build the team, tools, and processes before an incident occurs.
2. Identification — Detect and confirm that a security incident has taken place.
3. Containment — Stop the spread of the incident, both short-term and long-term.
4. Eradication — Remove the root cause — malware, compromised accounts, vulnerabilities.
5. Recovery — Restore systems to normal operation safely and verifiably.
6. Lessons Learned — Document what happened, what worked, and what must improve.
An IR team is not just IT staff. Effective response requires a cross-functional group with defined roles before an incident begins:
Incident Commander: Owns the response and makes final decisions. Usually the CISO or senior security manager.
Technical Lead: Directs the investigation and technical containment actions.
Legal Counsel: Advises on regulatory notification requirements and legal exposure.
Communications Lead: Manages internal communications and external statements.
HR Representative: Handles insider threat scenarios and employee communications.
Executive Sponsor: Escalation point for business decisions with major financial or reputational impact.
Every role should have a primary and a backup. Attackers do not respect working hours or holidays.
Not every security alert is a major incident. Define severity tiers upfront so your team knows exactly how to respond at each level without needing to convene a committee meeting:
Critical (P1): Active data exfiltration, ransomware, complete system compromise. All-hands response, executive notification within 15 minutes.
High (P2): Confirmed malware infection, credential compromise with evidence of misuse, significant system outage. Core IR team engaged within 1 hour.
Medium (P3): Suspicious activity requiring investigation, policy violations, potential phishing compromise. Security team response within 4 hours.
Low (P4): Alerts that are likely false positives, routine security events. Normal business-hours response.
Generic IR plans fail under pressure. Specific playbooks succeed. Write a dedicated playbook for each likely incident type:
Ransomware: Immediate isolation procedures, backup verification steps, ransomware family identification process, decision framework for negotiation vs recovery.
Business Email Compromise: Email account quarantine steps, financial transaction reversal contacts, forensic preservation checklist.
Data Breach: Data scope assessment process, regulatory notification timelines (GDPR: 72 hours), affected individual communication templates.
Insider Threat: Evidence preservation without alerting the subject, HR coordination procedures, system access revocation sequence.
Each playbook should be written as a step-by-step checklist that a competent responder can follow under stress, at 2am, with their hands shaking. Assume nothing.
Having the right tools available before an incident is critical. During a crisis is the worst time to evaluate vendors or request procurement approvals. Your IR toolkit should include:
Forensic imaging software, memory acquisition tools, centralised logging and SIEM access, network traffic capture capability, out-of-band communication channel (attackers may be monitoring your email), pre-approved legal hold procedures for evidence preservation, and contact details for your cyber insurance provider and a retainer with an external IR firm.
A plan that has never been tested is not a plan — it is a hypothesis. Conduct tabletop exercises at least twice per year, presenting realistic scenarios to your IR team and walking through the response step by step.
Effective tabletop scenarios include: a ransomware attack discovered on a Monday morning with three key staff on leave; a credential compromise where the attacker has been inside for 60 days; a supply chain attack via a trusted vendor's software update.
After each exercise, document gaps in the plan, tools that were missing, and decisions that took too long. Update playbooks within two weeks while the lessons are fresh.
Before an incident, map your notification obligations for every jurisdiction you operate in. GDPR requires notification to supervisory authorities within 72 hours. HIPAA requires notification within 60 days. SEC rules require material incident disclosure within four business days of determining materiality. Engaging legal counsel after a breach to discover these obligations for the first time costs precious hours.
The average time to identify and contain a breach without a tested IR plan is 277 days. With a tested plan, it drops to 197 days — an 80-day difference that translates directly to lower breach costs, less regulatory exposure, and faster return to normal operations.
CyberPhoenix offers complete IR programme development, playbook creation, tabletop exercise facilitation, and 24/7 emergency retainer services. Reach out before you need us — not after.