◆ traztech
Incident Response Plan Template
A lightweight IR plan skeleton you can fill in. Auditors, insurers, and enterprise buyers all ask whether you have one and whether it has been tested.
A plan on paper is not enough. Run a tabletop at least once a year and keep the after-action notes as evidence.
1. Roles & contacts
- Incident lead (name, backup)
- Engineering, legal, and communications contacts
- Executive escalation path
- External contacts: IR partner, cyber insurer, counsel
2. Detection & triage
- How incidents are detected (alerts, reports, monitoring)
- Severity levels defined (SEV1-SEV3) with examples
- Who declares an incident and starts the clock
3. Containment & eradication
- Immediate containment steps by scenario (account compromise, data exposure, ransomware)
- Preserve evidence and logs before remediation
- Root-cause identification
4. Notification
- Customer and regulator notification thresholds and timelines (e.g. HIPAA 60 days, Law 25 requirements)
- Communication templates prepared in advance
- Who approves external statements
5. Recovery & review
- Restore from tested backups
- Post-incident review within 5 business days
- After-action report and control improvements
- Update the plan and re-test