Free template

Incident response plan template

An outline for a working incident response plan, with what each section should contain and why. It follows the lifecycle in NIST SP 800-61 so your plan fits the way auditors, insurers and responders already think about incidents.

  • Aligned to NIST SP 800-61 and NIST CSF 2.0
  • Twelve sections, from roles to playbooks
  • Built to be tested with a tabletop exercise
Incident response team working together at a laptop

Before you start

How this template maps to NIST

NIST Special Publication 800-61 is a widely referenced guide to incident response. Revision 2 described a four-phase lifecycle: preparation; detection and analysis; containment, eradication and recovery; and post-incident activity. Revision 3, published in April 2024, organizes incident response around the six functions of NIST CSF 2.0: Govern, Identify, Protect, Detect, Respond and Recover.

This template uses the familiar phases for the operational sections, because that’s how responders work during an incident, and maps each phase to the CSF 2.0 functions so the plan fits your wider risk program.

  • Govern, Identify and Protect: sections 1 to 4 and 5 (preparation)
  • Detect: section 6 (detection and analysis)
  • Respond: sections 7 and 8 (containment, eradication and communication)
  • Recover: sections 9 and 10 (recovery and lessons learned)

Keep the plan short enough to use under pressure. Put detailed technical steps in playbooks and contact details in appendices so you can update them without rewriting the plan. Store a copy somewhere you can reach if your main systems are down.

The template

Incident response plan outline

1. Purpose, scope and authority

State why the plan exists, which systems, data, locations and business units it covers, and who approved it. Give the incident response lead the authority to make decisions during an incident, such as taking a system offline, and say who can overrule them.

2. Roles and responsibilities

Name the incident response team and a backup for every role. Typical roles are incident lead, technical lead, communications lead, legal counsel, executive sponsor and a note taker. List external parties you would call: your incident response retainer provider, cyber insurance carrier, outside counsel, IT and managed service providers, and law enforcement contacts.

  • A RACI table showing who decides, who acts and who is informed
  • Escalation paths for nights, weekends and holidays
  • Who is authorized to engage outside responders and approve spending

3. Definitions and severity levels

Define what counts as an event and what counts as an incident. Set severity levels, for example low, medium, high and critical, based on the data affected, the number of systems or people involved, operational impact and regulatory exposure. Link each level to who must be notified and how quickly the team assembles.

4. Governance and legal obligations

List the laws, regulations and contracts that affect how you respond, such as HIPAA, PCI DSS, CMMC and DFARS reporting, SEC disclosure rules, state breach notification laws and customer contract terms. Note your cyber insurance requirements, including whether you must notify the carrier before engaging outside responders.

5. Preparation

Describe what’s in place before an incident so the team can act quickly.

  • Current inventory of critical systems, data and owners
  • Logging, monitoring and alerting coverage, and where logs are kept
  • Backups, including immutable or offline copies, and restore testing
  • Out-of-band communication, such as phone trees or a separate chat tool
  • Retainers and contracts set up in advance with responders and recovery engineers
  • Training and a regular schedule of tabletop exercises

6. Detection and analysis

Explain how incidents are reported and detected: alerts from your monitoring or MDR provider, help desk tickets, user reports and third-party notifications. Describe how the team validates an event, assigns a severity, records a timeline and preserves evidence. Include a simple intake form: who reported it, when, what was observed and which systems are involved.

7. Containment and eradication

Set out containment options and who can approve them, such as isolating devices, disabling accounts, blocking addresses or taking systems offline. Describe short-term containment to stop the spread and longer-term containment while you investigate. Then cover eradication: removing malware and attacker access, resetting credentials, fixing the vulnerability that was exploited and confirming the root cause.

  • Evidence handling and chain of custody before systems are wiped
  • Criteria for when to bring in forensic responders
  • How you confirm the attacker no longer has access

8. Communication and notification

Decide who speaks for the organization and what gets said to whom: employees, executives, the board, customers, partners, regulators, insurers, law enforcement and the media. Route external statements through legal counsel. Include pre-approved message templates and a log of every notification made.

9. Recovery

Describe how systems are restored and returned to service: restore order based on business priority, how clean backups are verified, how restored systems are monitored for signs of reinfection and who signs off that operations are back to normal.

10. Post-incident review

Hold a lessons-learned review after every significant incident. Document the timeline, root cause, what worked, what didn’t, and the actions you’ll take, with owners and due dates. Feed the results back into your risk register, controls and this plan.

11. Playbooks

Attach short, step-by-step playbooks for the incidents you’re most likely to face. Each playbook should cover triggers, first steps, containment decisions, who to call and recovery.

  • Ransomware
  • Business email compromise and wire fraud
  • Compromised user or administrator account
  • Lost or stolen device
  • Data exposure or third-party breach
  • Misuse of AI tools or AI agents

12. Testing and maintenance

Name the plan owner. Review the plan at least annually and after major changes to systems, staff or vendors. Test it with a tabletop exercise at least once a year, with both technical and executive participants, and update it based on what you learn.

Appendices

  • Contact list for the team, executives, vendors, insurer, counsel and law enforcement
  • Critical systems list with owners and recovery priority
  • Incident intake form and incident log template
  • Evidence handling and chain of custody form
  • Communication templates
  • Plan revision history

Readiness check

Is your plan ready to use?

  • Every role has a named owner and a backup
  • Contact details are current and available offline
  • Your insurer’s notification requirements are written into the plan
  • Responders and recovery engineers are under agreement before you need them
  • Backups have been restored successfully in a test
  • The plan was tested in a tabletop exercise in the past year

FAQ

Incident response plan questions

Scope and authority, roles and contacts, severity definitions, legal and insurance obligations, preparation, detection and analysis, containment and eradication, communication, recovery, post-incident review, playbooks and a testing schedule. The outline on this page covers each.

Revision 3 aligns incident response to the six NIST CSF 2.0 functions instead of a standalone lifecycle. The four phases are still a practical way to organize the operational steps, which is why this template maps them to the CSF functions.

At least once a year, and after major changes to your systems, team or vendors. A tabletop exercise is the most efficient way to find gaps before a real incident does.

IT and security, a decision-maker from leadership, legal counsel, communications and the business owners of critical systems. Many organizations add an outside responder through a retainer so forensic and recovery skills are available when needed.

It depends on whether you need a review of an existing plan, a new plan and playbooks, a tabletop exercise, or a retainer with responders on standby. Your environment’s size and the regulations that apply also affect scope.

Get help building your plan

Turn this template into a plan your team can run

Tell us where your plan stands today. An advisor will reply by email to talk through a plan review, playbooks, a tabletop exercise or a retainer.

  • Plan and playbook reviews by Triden advisors
  • Tabletop exercises and retainers set up in advance

Prefer email? Write to [email protected] or call (858) 712-0040.

Send us a message