Guided template

Build an incident response plan before you need it.

Follow guided prompts for roles, first-hour actions, and common scenarios, then download a filled PDF your team can keep as response reference material.

Start guided template Build incident readiness
Guided template

Build a short incident response plan your team can follow.

This is not a formal enterprise plan. It helps a small team decide who responds, what happens first, and when to call for help.

Roles and authority

Name people before an incident. During stress, unclear ownership wastes time.

Who is the primary responder?

This is the person who coordinates the first technical response. It can be an internal staff member or a trusted provider.

Example: Operations manager, with IT provider as backup.

Who can make disruptive decisions?

This person can approve disabling accounts, taking systems offline, notifying stakeholders, or calling outside support.

Example: Executive director; deputy director if unavailable.

Who owns communications?

This person drafts staff, funder, customer, affected-person, or public messages. They should coordinate with leadership and legal if needed.

Example: Director of communications, with executive director approval.

Who are your outside support contacts?

Include IT, security, legal, insurance, hosting, and platform support. Add after-hours paths where available.

Example: IT provider helpdesk, cyber insurance hotline, outside counsel, Google Workspace admin support.

First 60 minutes

These are the first actions that keep a small incident from becoming chaos.

How will you confirm what was reported?

Record who noticed it, what account/system/device is affected, when it started, and what business impact exists.

Example: Responder opens an incident log and records reporter, time, affected account, screenshots, and current impact.

What evidence should be preserved?

Do not wipe or delete first. Save screenshots, alerts, messages, logs, file names, timestamps, and affected usernames.

Example: Take screenshots of suspicious emails, save alert IDs, record file names, and note exact times.

What containment actions are allowed?

Containment may include revoking sessions, resetting passwords, isolating a device, disabling an exposed link, or pausing an integration.

Example: Responder may revoke sessions and reset passwords; decision maker approves taking a system offline.

Where will you keep the incident log?

Use a place available even if email or internal systems are down. Log time, action, owner, and result.

Example: Shared emergency document and offline copy in the operations folder.

Scenario playbooks

Pick likely scenarios and write the first action, what to check next, and when to communicate.

What is the playbook for a compromised account?

Think about password resets, session revocation, MFA, forwarding rules, connected apps, and file/email activity.

Example: Revoke sessions, reset password, verify MFA, check forwarding rules and connected apps, review recent file access.

What is the playbook for a compromised device?

Disconnect the device, preserve evidence, and identify which accounts and files were used on it.

Example: Disconnect from network, do not wipe, record symptoms, reset key accounts from another device, check local files and backups.

What is the playbook for ransomware or malware?

Focus on isolation, backup integrity, shared drives, admin accounts, and lateral movement.

Example: Isolate affected systems, preserve evidence, pause sync if needed, verify backups, call external support.

What is the playbook for exposed data?

Find out what data was exposed, who could access it, how long it was exposed, and whether notification obligations may apply.

Example: Restrict access, preserve link settings and access logs, identify affected data, escalate notification decision to leadership/legal.

More resources

Keep going with related resources.

Review the plan

Want a tabletop-ready version?

Secure Origin helps small teams turn this template into a tested incident response plan, tabletop exercise, or Protect The Organization readiness track with owners and follow-up fixes.

PGP for sensitive email
hello@secureorigin.io fingerprint:
0BA7 6A2D 2761 340E 394F 7F13 129B A65D 2CA7 34C5
Request review Book call