Free Tool
Incident Response Plan
Answer key questions about your organization to generate a customized IR plan outline you can build upon.
This tool provides general guidance based on the information you provide. It is an initial starting point, not a substitute for professional assessment. Every organization's environment is unique — results should be reviewed with a qualified advisor before making compliance or security decisions.
Who this tool is for
This builder is for organizations that know they need an incident response plan and do not have one — or have one that nobody has read since it was written. That includes companies where IT handles everything, nonprofits where the executive director is also the crisis lead, professional firms with client confidentiality obligations, and any organization whose cyber insurance application or customer contract asks "do you have a documented IR plan?" It is also useful for larger teams with a mature plan who want a quick check on whether roles, communication paths, and testing cadence are still current.
What it measures — and what “in scope” means
The questions establish where your program stands today: whether a plan exists and how complete it is, whether there is a designated response team or point of contact, whether incident categories and severity levels are defined, whether there is a communication plan for notifying leadership, customers, and regulators, and whether the plan has been tested through tabletop exercises and reviewed after real incidents. From those answers the tool generates a plan outline that follows the NIST SP 800-61 lifecycle — preparation, detection and analysis, containment, eradication and recovery, and post-incident review — with sections sized to your current maturity. "In scope" means the plan covers cybersecurity incidents affecting your systems and data; physical security and business continuity are related but separate documents.
What your result is not
The output is an outline, not a finished plan. It does not know your systems, your vendors, your regulators, your insurer's notification requirements, or your legal obligations, and it cannot tell you who to call at 2 a.m. Those details are the plan; the outline is the scaffolding. It is also not a playbook for an incident in progress — if you are responding to something right now, involve counsel, your insurer, and an incident response firm before taking action that could destroy evidence.
Frequently asked questions
QWhat should an incident response plan include?
At minimum: who declares an incident and who leads it, how incidents are categorized by severity, containment steps for common scenarios, an internal and external communication plan, notification triggers for regulators and customers, and a post-incident review process.
QHow often should we test the plan?
A tabletop exercise at least annually, and after any significant change to systems, staff, or vendors. Plans that are never tested fail in predictable ways the first time they are used.
QWe have no security staff. Who should own incident response?
Someone with authority to make decisions, not necessarily someone technical. The related article on the first four hours without a CISO explains how to structure that role.
QIs this plan enough for cyber insurance or SOC 2?
It is a documented starting point, which is what most applications and audits ask for. Insurers and auditors also look for evidence the plan is tested and maintained.
QDoes the builder store my answers?
No. Everything runs in your browser. Copy or print the outline before closing the tab.
Related reading
Tool and guide maintained by Ashwameth J Ravilla, CISSP, CISA, CDPSE, CMMC RP (CPN 72949) · Last updated September 2026.
Need a Deeper Analysis?
This tool gives you a starting point. For a comprehensive, professional assessment tailored to your specific environment, schedule a consultation.
Schedule a Scope Call