Template

Incident response plan template for small teams.

A lightweight structure for organizations that need to know who does what, how to contain common incidents, and what to communicate when something goes wrong.

Use the template Get response planning help
Plan template

Fill this in before you need it.

Keep a copy somewhere available when email or internal systems are unavailable. The goal is not a perfect plan; it is a short plan your team can actually follow under stress.

Role Name Phone / backup contact Authority
Primary responderName...Phone...Coordinates first technical response.
Decision makerName...Phone...Can disable accounts, take systems offline, notify stakeholders.
Communications ownerName...Phone...Drafts staff, funder, customer, or public communications.
External supportProvider...After-hours contact...IT, security, legal, insurance, hosting, or platform support.

First 60 minutes

Scenario playbook

Scenario Immediate action Check next Communication trigger
Compromised accountReset password, revoke sessions, verify MFA.Forwarding rules, connected apps, recent file/email activity.If sensitive data, donors, sources, clients, or funders may be affected.
Compromised deviceDisconnect from network, do not wipe immediately.Accounts used on device, files stored locally, backups.If device contained regulated, legal, source, or beneficiary data.
Ransomware or malwareIsolate affected systems and preserve evidence.Backup integrity, shared drives, admin accounts, lateral movement.If services, records, or personal data are unavailable or exposed.
Data exposureRemove exposure or restrict access.What data, who accessed it, how long it was exposed.If notification obligations or ethical obligations may apply.
Review the plan

Want a tabletop-ready version?

Secure Origin helps small teams turn this template into a tested incident response plan with roles, escalation, containment steps, and practical exercises.

PGP for sensitive email
hello@secureorigin.io fingerprint:
0BA7 6A2D 2761 340E 394F 7F13 129B A65D 2CA7 34C5