Build your breach response plan before you need it
This app-style planner helps your team think through the first 72 hours of a cyber incident, assign ownership, track response phases, and export a practical response summary for leadership.
Current phase
Immediate Response
0–6 Hours
Progress
0 / 20 completed
Emergency Contacts for the Response Team
Keep this information current and accessible
During an incident, nobody should be hunting through inboxes or old documents for the right phone number. Review and update these contacts regularly.
Incident Commander
CEO, President, or whoever is going to take charge
Name
24/7 Phone
Backup Contact
Technical Lead
IT Manager, internal IT lead, or IT service provider
Name
24/7 Phone
Backup Contact
Immediate Response
This phase is about establishing control. Confirm what looks affected, stop improvisation, and preserve the information you will need later.
Primary objective
Stabilize the situation, preserve evidence, and establish a single response lead.
Key stakeholders
Executive lead, IT lead, legal counsel, cyber insurance contact
Checklist
- Activate the response team and assign one decision-maker.
- Identify affected systems, identities, mailboxes, endpoints, or cloud workloads.
- Preserve logs, screenshots, alerts, and system state before broad cleanup.
- Review insurance requirements and determine whether forensics or legal must be engaged immediately.
Communication notes
Limit messaging to a small approved group. No all-staff or client updates until the scope is clearer.
Documentation focus
Document initial symptoms, timestamps, affected systems, who discovered the issue, and who approved each major action.