Home Resources Incident Response Planning
IR planning guide · 2025

Incident Response Planning: what to do before and during a breach.

The organizations that recover fastest from breaches planned before they were breached. Here's how to build the plan — and test it.

Incident response planning guide

The organizations that recover fastest from breaches are the ones that planned before they were breached.

An incident response (IR) plan is a documented set of procedures that defines how your organization detects, contains, eradicates, and recovers from a cybersecurity incident. Without one, every decision during an active breach is made under maximum stress with incomplete information and no clear authority. With one, your team knows exactly who does what in the first 15 minutes — when those minutes matter most.

The six phases of incident response (NIST SP 800-61)

  • Preparation: Establishing the IR team, defining roles and responsibilities, deploying detection tools, maintaining contact lists, and conducting tabletop exercises. Everything that happens before an incident.
  • Detection and analysis: Identifying that an incident has occurred, determining its scope and severity, and validating that it's a real threat rather than a false positive. This is where 24/7 monitoring with human analysts is decisive.
  • Containment: Isolating affected systems to prevent lateral spread. Short-term containment (disconnecting affected endpoints) followed by long-term containment (network segmentation, credential rotation).
  • Eradication: Removing the attacker's presence from the environment — malware, persistence mechanisms, backdoors, compromised accounts. Eradication must be complete before recovery begins.
  • Recovery: Restoring affected systems from clean backups, verifying integrity, and returning to normal operations. Recovery should include hardening the initial access vector to prevent reinfection.
  • Post-incident activity: Root cause analysis, lessons learned, detection improvement, and regulatory notifications if required. The insights from this phase strengthen your defenses for the next incident.

What to do in the first 15 minutes

The decisions made in the first 15 minutes of a confirmed breach have an outsized impact on outcomes. Specifically: do not reboot affected systems (this can destroy volatile memory evidence), do not delete logs or files, do not change passwords on compromised accounts before isolating those systems, and do not notify the attacker that you know they're there by taking visible defensive actions before containment is ready. Call your IR provider — or if you're a SignalPoint client, call our 24/7 emergency line and our analyst will guide you through immediate steps while the response team mobilizes.

Building your IR plan: the minimum viable document

  • Incident classification: what constitutes a Severity 1 (critical) vs. Severity 2 (high) vs. Severity 3 (medium) event
  • Escalation contacts: who gets called for each severity level, including personal mobile numbers and after-hours contacts
  • External contacts: IR provider, legal counsel, cyber insurance carrier, FBI cyber division contact, PR/communications contact
  • System inventory: what systems exist, who owns them, and how to reach them during an incident
  • Containment procedures: how to isolate endpoints, disable accounts, and segment network segments
  • Communication protocols: what gets communicated externally, by whom, when — including customer and regulatory notifications
  • Regulatory notification requirements: HIPAA 60-day notification window, Tennessee breach notification law, PCI-DSS card brand requirements

Tabletop exercises: testing your plan before you need it

A plan that has never been tested will fail under pressure. Tabletop exercises put your leadership team through a simulated incident scenario — working through decisions in real time without touching live systems. SignalPoint facilitates tabletop exercises that test your plan against realistic ransomware, BEC, and insider threat scenarios, producing a written gap analysis and recommended improvements.

Quick answers

Frequently asked questions.

IR plans should be reviewed annually at minimum, and updated after any significant change to your environment (new systems, new personnel, new vendors), after any real incident, and after any tabletop exercise that exposes gaps. Regulatory frameworks including HIPAA and NIST CSF require regular testing and updating of IR procedures.

A tabletop exercise is a facilitated discussion-based simulation where your leadership team works through a hypothetical cyber incident scenario. No systems are touched — the exercise tests decision-making, communication chains, and IR procedures. SignalPoint facilitates custom tabletop exercises built around scenarios relevant to your industry and environment.

Yes. SignalPoint offers incident response retainers that guarantee priority response with a contractual SLA. Retainer clients receive pre-incident preparation including environment documentation and IR planning support, as well as the fastest possible response time during an active incident.

Stop the next attack before it starts.

Free 30-minute consultation — no commitment, no jargon, no sales pressure.

Schedule nowView pricing
Free monthly threat briefing
Chattanooga-specific threat intelligence, delivered to your inbox. No spam, unsubscribe anytime.