Cybersecurity Incident Response Plan
1. Purpose and Document Structure
This Incident Response Plan (IRP) contains detailed technical and organisational procedures for the Response Team. It supplements DOC-005 (policy) and DOC-006 (reporting procedures). It covers:
- General response procedure (6 PICERL phases),
- Playbooks for the most common incident scenarios,
- Operational checklists,
- Crisis communication procedures.
Offline copy stored at: ▸ [e.g. CISO safe, main reception, each administrator has a printout]
Date of last offline copy update: ▸ DD/MM/YYYY
2. General Response Procedure – 6 PICERL Phases
| Phase | Name | Key actions | Responsible |
|---|---|---|---|
| P | Preparation | Maintain tools, training, plans; tests; CSIRT contacts up to date | ▸ CISO (ongoing) |
| I | Identification | Alert detection, initial analysis, P1–P4 classification, internal report | ▸ CISO / IT Admin |
| C | Containment | Short-term (isolation) + long-term (patch, hardening) | ▸ IT Admin / CISO |
| E | Eradication | Remove malware, close attack vector, verify | ▸ IT Admin |
| R | Recovery | Restore systems, verify, post-recovery monitoring | ▸ IT Admin / System Owner |
| L | Lessons Learned | PIR, update documentation, CSIRT report, Board communication | ▸ CISO |
3. Playbooks – Incident Scenarios
Playbooks for the most frequent and most serious incident types. The organisation may add sector-specific scenarios.
Category: MAL | Priority: P1 | Response time: immediate
PHASE: Identification
- File encryption or ransom demand confirmed?
- Affected systems identified (IP list / names)?
- Estimated infection time established (when were last good files)?
- Is backup available and unaffected?
PHASE: Containment (perform IMMEDIATELY)
PHASE: Eradication
PHASE: Recovery
Reporting
External IR (forensics): ▸ [company name, telephone]
Cyber insurer: ▸ [policy number, telephone]
Category: ACC | Priority: P1 (privileged account) / P2 (regular account)
PHASE: Identification
- What triggered the alert – SIEM, MFA alert, user report, anomaly detection?
- Which account was compromised (privileged / standard)?
- What resources did it have access to?
- Is the account still active?
PHASE: Containment
Disable-ADAccount -Identity [user]PHASE: Eradication and investigation
Category: DAT | Priority: P1 (personal data / confidential) / P2 (internal data)
Special attention: GDPR
If the breach may result in high risk to individuals' rights → notify the affected persons (GDPR Art. 34).
- What data was leaked (category, number of records, personal data?)?
- Which individuals are affected?
- Where did the breach originate (source system)?
- Did data reach an unauthorised party?
- Is the data encrypted / pseudonymised?
PHASE: Containment
PHASE: Legal assessment and reporting
Category: NET | Priority: P1 (key services) / P2 (others)
- Which service / system is unavailable?
- What type of DDoS attack (volumetric, protocol, application layer)?
- Has the telecom operator been contacted?
- Is anti-DDoS protection available from the supplier?
Actions
Anti-DDoS provider: ▸ [name, 24/7 contact number]
Telecom operators (for upstream blocking): ▸ [name, telephone]
Example additional playbooks to prepare:
PB-005: Phishing / Business Email Compromise (BEC)
PB-006: OT/SCADA system attack (if applicable)
PB-007: Supply chain system compromise
PB-008: Unauthorised physical access to IT infrastructure
4. Crisis Communications
4.1 Internal communications
| Recipient | Message content | Deadline | Channel |
|---|---|---|---|
| IR Team | Full technical information | Immediately | ▸ [e.g. Teams / Signal / telephone] |
| Board | Summary: what happened, impact, actions | Within 2h (P1) | ▸ [e.g. encrypted email / telephone] |
| Employees (if relevant) | Instructions: what to do / what not to do | As soon as possible | ▸ [e.g. group email / internal announcement] |
4.2 External communications
| Recipient | Content | Responsible |
|---|---|---|
| CSIRT | Notification form (DOC-006 Annex B/C) | ▸ CISO |
| DPA (if personal data breach) | DPA notification form within 72h | ▸ CISO / DPO |
| Clients / users (if required by GDPR) | ▸ [notification template to be prepared] | ▸ Board / Legal |
| Media | Official press statement | ▸ Board / Press Officer |
| Suppliers affected by incident | Information on incident (if applicable) | ▸ CISO / Board |
5. IR Team Equipment and Tools
| Category | Tool (organisation fills in) | Location / access |
|---|---|---|
| SIEM | ▸ [e.g. Splunk / Microsoft Sentinel / OSSIM] | ▸ |
| EDR / Antivirus | ▸ [e.g. CrowdStrike / Defender / Sophos] | ▸ |
| Forensics – disk imaging | ▸ [e.g. FTK Imager / DD] | ▸ |
| Forensics – memory analysis | ▸ [e.g. Volatility / Magnet RAM] | ▸ |
| Network traffic analysis | ▸ [e.g. Wireshark / NetworkMiner] | ▸ |
| Incident management | ▸ [e.g. TheHive / Jira / ServiceNow] | ▸ |
| Emergency communication (out-of-band) | ▸ [e.g. mobile phones, Signal] | ▸ |
| Secure evidence storage | ▸ [e.g. dedicated offline drive in safe] | ▸ [location] |
6. Change History and Plan Tests
| Version | Date | Author | Description | Approved by |
|---|---|---|---|---|
| ▸ 1.0 | ▸ DD/MM/YYYY | ▸ | ▸ Initial release | ▸ Board |
Plan test history
| Test date | Test type | Scenario | Result | Corrective actions |
|---|---|---|---|---|
| ▸ DD/MM/YYYY | ▸ [Tabletop / Live drill] | ▸ [e.g. Ransomware P1] | ▸ [Pass / Partial / Unsatisfactory] | ▸ |