Services / Incident Response Plan Checklist
Checklist

Incident Response Plan Checklist

The best time to write this checklist is before you need it. Use it to evaluate whatever plan you already have, or to build one from scratch if you don't.

Key Takeaways
  • A single named decision-maker, reachable outside business hours, is the single highest-leverage thing a plan can define.
  • Clear incident criteria prevent both under-reaction and alert fatigue from false alarms.
  • Containment steps must isolate without destroying the evidence you'll need later.
  • A plan that isn't updated after each incident is a plan that keeps making the same mistakes.

Before an Incident

Preparation is what separates an organized response from chaos. Without a named point of contact and decision-maker, precious time gets lost figuring out who's actually authorized to make containment decisions while an incident is actively unfolding.

Clear criteria for what counts as an incident versus routine noise also matters more than people expect — without it, teams either under-react to genuine threats or burn out from treating every anomaly as a five-alarm fire.

  • A named point of contact and decision-maker, available outside business hours
  • Clear criteria for what counts as an incident vs. routine noise
  • Contact information for legal counsel, insurance, and any required regulators
  • A communications plan for employees, customers, and press if needed
  • A pre-vetted external response partner, so you're not searching for help mid-crisis

During an Incident

The first hour disproportionately determines how the rest of the incident unfolds. Fast, accurate triage and severity assessment lets you make containment decisions based on facts rather than assumptions or panic.

Containment steps need to isolate affected systems without destroying the evidence you'll need for root-cause analysis, insurance claims, or potential legal proceedings — a rushed, poorly executed containment can sometimes cause as much damage as the incident itself.

  • Triage and severity assessment within the first hour
  • Containment steps that isolate without destroying evidence
  • A single source of truth for status updates, to avoid conflicting information
  • A clear escalation path if the incident turns out to be more severe than initially assessed

After an Incident

The work isn't done when systems come back online. A genuine root-cause analysis — not just a summary of what happened — is what prevents the same gap from being exploited again.

A concrete hardening plan, with named owners and real deadlines, needs to follow every incident. And the plan itself should be updated based on what was learned; an incident response plan that never changes after an actual incident isn't really being used.

  • A root-cause analysis, not just a summary of what happened
  • A concrete hardening plan with owners and deadlines
  • An updated plan reflecting what was learned
  • A timeline of the incident, useful for insurance, legal, or regulatory purposes
Questions
Do we need a written plan even if we're a small business?

Yes — even a one-page plan with a clear point of contact and a first-hour checklist beats scrambling to figure out who does what during an actual incident. Size doesn't reduce the value of basic preparation.

How often should the plan be reviewed?

At minimum annually, and always after any real incident, near-miss, or significant change to your infrastructure or team structure.

Who should have access to the plan?

Everyone likely to be involved in a response should know where it is and their specific role in it — a plan that only the IT lead has seen isn't much of a plan when that person is unreachable.

Related Reading

Have a Question We Didn’t Cover?

Email Our Team