How to Write an Incident Response Plan (+ Template)

An incident response plan is a short, practical document that says what to do when a security incident happens – who is in charge, who to call, how to contain it, and how to recover. Written before an incident, it turns panic into a checklist.

The six phases

  • Prepare – the plan, contacts, tools and training in place beforehand
  • Detect – how an incident is identified and reported (staff, EDR, monitoring)
  • Contain – isolate affected systems, disable compromised accounts, stop the spread
  • Eradicate – remove the cause – malware, the foothold, the vulnerability
  • Recover – restore from clean backups, verify, return to normal
  • Review – what happened, what worked, what to fix

Who does what

  • Incident lead – makes decisions, coordinates
  • Technical – contains and recovers (often your IT provider)
  • Communications – staff, customers, and regulators if personal data is involved
  • Legal / management – breach-notification obligations, insurer, decisions

Template outline (copy this)

  • Purpose and scope
  • Definitions – what counts as an incident, severity levels
  • Roles and contacts – internal, IT provider, insurer, legal, police / anti-fraud centre, key vendors (kept offline)
  • Detection and reporting – how staff raise an alarm
  • Response steps by incident type – ransomware, account compromise, lost device, data breach
  • Communication plan and holding statements
  • Recovery – backup locations, restore order, verification
  • Post-incident review and revision history

Pair it with your business continuity plan and disaster recovery plan. We help you write and test all three as part of our cybersecurity work.

Related security guides

Want this handled? See our cybersecurity service or talk to our Edmonton team.

Frequently asked questions

How long should an incident response plan be?

A few pages. It is used under stress – roles, contacts, and a clear checklist per incident type matter more than detail.

Who should be the incident lead?

Someone with authority to make decisions quickly – usually an owner or senior manager – not necessarily the most technical person. The technical work is often the IT provider’s.

Do we have to report a breach?

In Canada, PIPEDA requires reporting breaches of personal information that pose a real risk of significant harm to the Privacy Commissioner and affected individuals. Health information and some sectors have additional rules. Build the obligation into the plan.

How does Scandifix help?

We help you write the plan, run a tabletop exercise, and act as your technical responder – containment and recovery – when an incident happens.