What an incident response plan should contain

An incident response plan should say who is in charge, how severity is judged, who may take disruptive decisions without waiting, who communicates with whom, how facts reach counsel for notification decisions, what to do first in the incidents you are likeliest to face, and how to reach everyone when email is down. It should also record when it was last tested. A short plan that has been rehearsed beats a long one nobody has read.

What should an incident response plan contain?

SectionWhat it must answer
RolesWho leads, who decides for the business, who keeps the log, and each one’s deputy
SeverityWhat turns an event into an incident, and what each level sets in motion
Decision authorityWho may isolate systems, take a service offline or engage outside help, and at what threshold
CommunicationsWho speaks to staff, customers and regulators, and over which channel
NotificationHow facts reach counsel, and who keeps the breach record
PlaybooksFirst steps for the incidents you are likeliest to face
ContactsCounsel, insurer, key providers, and a way to reach them outside your own systems
TestingWhen the plan was last exercised and what changed as a result

Which section do most plans skip?

Roles are easy to list. The hard part is writing down, in advance, who may disconnect the finance system at two in the morning without a meeting. Nobody wants to make that call in the moment, and the delay is where damage grows. Name the decision by role, name a deputy, and set the threshold: for example, confirmed ransomware on any server means isolate first, explain afterwards.

How should the plan handle breach notification?

The plan builds the path to counsel, not the decision. As of September 2026, where PIPEDA applies, section 10.1 requires an organization to report to the federal Privacy Commissioner any breach of security safeguards involving personal information under its control where it is reasonable to believe the breach creates a real risk of significant harm, as soon as feasible after it determines the breach occurred, and, unless the law prohibits it, to notify affected individuals on the same test. Section 10.3 requires a record of every breach of security safeguards involving personal information under its control, reportable or not, and the Breach of Security Safeguards Regulations require that record be kept for 24 months after the day the organization determines the breach occurred.

Should the plan decide when you notify? No. The plan should get facts to counsel quickly and keep the breach record. Whether a notification duty is engaged is a legal determination that counsel makes on the facts. Provincial and sector rules may apply instead or as well, which is another reason counsel belongs in the first hour. The BC position is set out in reporting a breach in BC.

Which playbooks should the plan include?

Write one page each for the four or five incidents you are likeliest to face: ransomware, a compromised mailbox or payment fraud, a lost device, a breach at a key provider. Each should say the first three actions, who to call, and what not to do. Where forensic investigation is needed, the playbook should say how it is engaged, usually through counsel; that work is delivered with appropriately licensed partners where the law requires it.

NIST’s current guidance as of September 2026, SP 800-61 Rev. 3 (April 2025), superseded Rev. 2 and places incident response inside an organization’s wider cybersecurity risk management under CSF 2.0. The practical lesson: the plan should draw on the asset lists, backups and supplier contacts you already keep.

How do you reach people when your systems are down?

Keep a printed or offline copy with personal phone numbers, counsel, your insurer’s claims line and policy number, and your key providers. If you hold cyber insurance, read its notice clause and any rules on which responders you may use, and make the plan follow the policy rather than contradict it.

How often should you test the plan?

We suggest at least once a year, and after any significant change to people, systems or providers. An exercise that changes nothing in the plan was probably not realistic enough. A tabletop exercise is the cheapest way to find the missing phone number and the decision nobody owns; how to run a tabletop exercise sets out the method, and the first 24 hours of an incident shows the plan in use. Writing and rehearsing the plan is our incident response readiness work.

How the work is bounded

The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.

Investigation and forensic work is delivered with appropriately licensed partners where the law requires it.

SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.

Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.

Questions we are asked

How long should an incident response plan be?

Short enough to be read under pressure: a few pages of roles, decisions and contacts, with a one-page playbook for each likely scenario. Length is not a measure of readiness; rehearsal is.

Should the plan decide when we notify?

No. The plan should get facts to counsel quickly and keep the breach record. Whether a notification duty is engaged is a legal determination that counsel makes on the facts.

How often should we test it?

We suggest at least once a year, and after any significant change to people, systems or providers. An exercise that changes nothing in the plan was probably not realistic enough.

Can we use a template?

A template is a fair start for structure, but the value is in what no template knows: your names, your decision thresholds, your insurer’s process and your systems. Fill those in, then rehearse.

Checking your plan

Send us the plan you have, however rough. The reply says which sections are missing and which decisions nobody owns yet. More of our writing is indexed at writing.

Discuss a scope