For business management solutions email us or call 020 3004 4600

What is an Incident Response Plan?

An incident response plan is a documented set of procedures that sets out how a business will detect, respond to and recover from a cyber security incident, such as a ransomware attack, data breach or Business Email Compromise, so the organisation can act quickly and consistently rather than improvising under pressure.

How an incident response plan works

A good incident response plan defines who leads the response and who communicates externally, sets out detection and triage steps, and covers containment actions to limit an incident's spread while preserving evidence. It includes a communication plan for staff, customers and regulators, such as the ICO for a personal data breach, and links through to a business's wider Disaster Recovery and Business Continuity Planning for full recovery. Plans are only as good as their last test, so most organisations run tabletop exercises or simulations to check the plan works in practice, then carry out a post-incident review after any real event to feed lessons back in.

How UK businesses use incident response plans

  • A business tests its incident response plan through a tabletop exercise simulating a ransomware attack, identifying gaps in its communication process before a real incident occurs.
  • An IT team follows its incident response plan to isolate an infected device from the network within minutes of detecting suspicious activity, containing the spread of an attack.
  • A company's incident response plan sets out when and how a data breach must be reported to the ICO, ensuring regulatory deadlines are met.
  • A business reviews and updates its incident response plan after a genuine security incident, incorporating lessons learned into future procedures.

How Advantage helps SMEs prepare an incident response plan

Advantage helps SMEs develop and test incident response plans, combining this with managed detection and response services so that when an incident does occur, the right people and processes are ready to act quickly.

Explore Advantage's cyber security services →

Frequently Asked Questions

Do small businesses really need a formal incident response plan?

Yes. Any business handling data or reliant on IT systems benefits from a plan, since even a small business can suffer significant disruption or reputational damage from an unmanaged cyber incident.

Who should be involved in creating an incident response plan?

Typically IT or a managed service provider, senior management, and where relevant, legal and communications staff, since an incident can involve technical, legal and reputational considerations.

How often should an incident response plan be tested?

Good practice is to test it at least annually through a tabletop exercise or simulation, and to review it after any real incident to incorporate lessons learned.