Home › Free tools › Incident response plan
An auditor will ask for your incident response plan. Most small companies do not have one, not because it is hard, but because nobody has sat down for twenty minutes to write it. This produces a real one-page plan from a dozen answers.
Runs in your browser. Nothing is sent anywhereTwo or three levels is plenty. Edit these to match how you actually talk.
Saved in this browser as you type. Download a copy to keep it somewhere your team can reach during an outage.
At minimum: who is notified first and how to reach them, how severity is judged, who can declare an incident, where the team communicates during one, when customers and regulators must be told, and what happens afterwards. One page covering those honestly is worth more than twenty pages of generic text.
An auditor is looking for evidence that a documented, followed process exists - not length. A short plan that names real people, real channels and real timescales is more credible than a long template with placeholders left in. What matters is that it is written down, current, and that the team knows it.
At least annually, and after any real incident or near miss. The parts that go stale fastest are the contact details and the names, which is exactly the part that matters at two in the morning.
No. The plan is assembled in your browser and saved only in your own browser storage. Nothing is transmitted. Use the download button to keep a copy.