Incident Response Plan

Answer key questions about your organization to generate a customized IR plan outline you can build upon.

Your data stays in your browser
No signup required
No tracking or data collection

Who this tool is for

This builder is for organizations that know they need an incident response plan and do not have one — or have one that nobody has read since it was written. That includes companies where IT handles everything, nonprofits where the executive director is also the crisis lead, professional firms with client confidentiality obligations, and any organization whose cyber insurance application or customer contract asks "do you have a documented IR plan?" It is also useful for larger teams with a mature plan who want a quick check on whether roles, communication paths, and testing cadence are still current.

What it measures — and what “in scope” means

The questions establish where your program stands today: whether a plan exists and how complete it is, whether there is a designated response team or point of contact, whether incident categories and severity levels are defined, whether there is a communication plan for notifying leadership, customers, and regulators, and whether the plan has been tested through tabletop exercises and reviewed after real incidents. From those answers the tool generates a plan outline that follows the NIST SP 800-61 lifecycle — preparation, detection and analysis, containment, eradication and recovery, and post-incident review — with sections sized to your current maturity. "In scope" means the plan covers cybersecurity incidents affecting your systems and data; physical security and business continuity are related but separate documents.

What your result is not

The output is an outline, not a finished plan. It does not know your systems, your vendors, your regulators, your insurer's notification requirements, or your legal obligations, and it cannot tell you who to call at 2 a.m. Those details are the plan; the outline is the scaffolding. It is also not a playbook for an incident in progress — if you are responding to something right now, involve counsel, your insurer, and an incident response firm before taking action that could destroy evidence.

Frequently asked questions

QWhat should an incident response plan include?

At minimum: who declares an incident and who leads it, how incidents are categorized by severity, containment steps for common scenarios, an internal and external communication plan, notification triggers for regulators and customers, and a post-incident review process.

QHow often should we test the plan?

A tabletop exercise at least annually, and after any significant change to systems, staff, or vendors. Plans that are never tested fail in predictable ways the first time they are used.

QWe have no security staff. Who should own incident response?

Someone with authority to make decisions, not necessarily someone technical. The related article on the first four hours without a CISO explains how to structure that role.

QIs this plan enough for cyber insurance or SOC 2?

It is a documented starting point, which is what most applications and audits ask for. Insurers and auditors also look for evidence the plan is tested and maintained.

QDoes the builder store my answers?

No. Everything runs in your browser. Copy or print the outline before closing the tab.

Related reading

The First Four Hours of a Cyber Incident When You Have No CISOFive Security Controls Every Small Organization Should Implement FirstAI Tools Your Team Is Already Using — And Why That’s a Governance Problem

Tool and guide maintained by Ashwameth J Ravilla, CISSP, CISA, CDPSE, CMMC RP (CPN 72949) · Last updated September 2026.

Need a Deeper Analysis?

This tool gives you a starting point. For a comprehensive, professional assessment tailored to your specific environment, schedule a consultation.

Schedule a Scope Call