What Is a Cyber Incident Response Plan?
A plain-English explanation of what an incident response plan actually is, what it covers, and why having one written down before something happens changes how an incident plays out.
The short answer
A cyber incident response plan is a written document that tells your business what to do when something goes wrong - a phishing compromise, ransomware, a lost laptop, or a supplier telling you your data might be exposed. It sets out who does what, in what order, and how decisions get made, so the first hour of an incident is spent acting rather than arguing about who's in charge.
It's not antivirus software, it's not a piece of IT infrastructure, and it doesn't stop an incident from happening. It's a process document - the same category of thing as a fire evacuation plan. You hope you never need it, but the businesses that have one tend to come out of an incident faster, calmer, and with a clearer record of what happened.
What it typically covers
Most incident response plans work through a lifecycle: identify the incident and work out what kind it is, contain it so it stops getting worse, investigate to understand scope and root cause, eradicate the cause, recover systems and data, and review what happened afterwards so it doesn't repeat.
A good plan also covers the parts that aren't purely technical: who's allowed to make the call to shut a system down, who talks to affected customers, what gets recorded for insurance or regulatory purposes, and when to bring in outside help rather than trying to handle everything internally.
Why 'we'll figure it out at the time' doesn't work
Incidents are stressful, time-pressured, and often ambiguous - you rarely know at 9am on a Tuesday whether what you're looking at is a minor phishing email or the start of something much bigger. Without a plan, that ambiguity gets resolved by whoever's in the room shouting loudest, which is a bad way to make decisions about evidence preservation, customer communication, or whether to pay a ransom.
A written plan moves those decisions to a calmer moment - before the incident - so that during the incident, people are following a process rather than inventing one.
Do small businesses actually need one?
Yes, arguably more than large ones. A large business often has a security team who can improvise competently under pressure. A small business usually doesn't, which means the plan is doing more of the work - it's the closest thing to that expertise most SMEs have in the room when something happens.
See our guide on incident response plans for small businesses specifically for what a realistic, right-sized version looks like.
Where to start
If you're starting from nothing, the fastest route is a template written for businesses like yours - one that assumes you don't have a dedicated security team, rather than one written for an enterprise security operations centre. Our Cyber Incident Response Plan & Toolkit is built specifically for UK SMEs: a practical plan, a workbook for logging what happens, five playbooks for common scenarios, and the communications templates you need on the day.