Guide · IR Plan Starter

Incident Response Plan Starter

A practical starting point for small and mid-market organizations that need a credible incident response plan today. Aligned to NIST SP 800-61r2. Use it as a baseline, then tailor to your environment.

The six phases

Phase 1
Prepare

Roles named (commander, scribe, comms, legal, exec sponsor). Contact tree printed and stored offline. Tooling and access verified.

Phase 2
Detect & Analyze

Triage source (SIEM, MDR, user report). Confirm scope, classify severity, open incident record, start the timeline.

Phase 3
Contain

Short-term containment (isolate hosts, block IOCs) then long-term (rotate creds, rebuild). Preserve evidence before wiping.

Phase 4
Eradicate

Remove attacker persistence: accounts, scheduled tasks, web shells, golden tickets. Patch the root cause.

Phase 5
Recover

Restore from known-good backups. Validate integrity. Re-enable monitoring on the recovered estate before re-opening to users.

Phase 6
Lessons Learned

Post-incident review within 10 business days. Track corrective actions to closure. Update detections, playbooks, and the IR plan itself.

Core roles

RoleResponsibility
Incident CommanderOwns decisions, scope, and escalation. Single point of accountability.
Technical LeadDrives investigation, containment, and eradication actions.
ScribeMaintains the timeline, decisions log, and evidence chain.
Communications LeadInternal updates, executive briefings, customer comms drafts.
Legal / PrivacyRegulatory notification clocks, breach counsel, contractual obligations.
Executive SponsorAuthorizes business-impacting actions (shutdowns, public statements).

Severity matrix

SEV-1

Material business disruption or confirmed sensitive data loss.

IC engaged ≤ 15 min · exec brief ≤ 1 hr

SEV-2

Significant degradation, contained but spreading risk.

IC engaged ≤ 1 hr · daily exec brief

SEV-3

Limited scope, single system or user.

Handled in-team · weekly summary

First-24-hour runbook

  1. 0:00 — Open incident record. Assign IC, Tech Lead, Scribe.
  2. 0:15 — Initial severity call. Notify exec sponsor and legal if ≥ SEV-2.
  3. 0:30 — Begin containment. Preserve volatile evidence first (memory, sessions).
  4. 1:00 — Stand up secure comms channel out-of-band from the affected estate.
  5. 2:00 — Engage IR retainer / MDR / breach counsel if SEV-1.
  6. 4:00 — First written executive brief: what we know, what we don't, what we're doing.
  7. 8:00 — Validate containment held. Begin eradication planning.
  8. 12:00 — Notification clock review with legal (GDPR 72h, sector regulators, contractual SLAs).
  9. 24:00 — Status update to all stakeholders. Decision: continue, escalate, or stand down.

Want this tailored and tabletop-tested?

Dephiant builds organization-specific IR plans and runs facilitated tabletop exercises with your executive team, IT, and legal.