Cyber Incident Response Plan: A Practical Guide
It's 7pm on a Friday, and someone in your finance team just clicked a link they shouldn't have. Without a cyber incident response plan, "now what?" is a question you're answering on the fly. Here's what an actual, usable plan looks like — and how to build one without hiring a full security team.
The Core Stages of Response
The six stages every solid cyber incident response plan follows, from preparation to review.
Read SectionWho Should Be Involved
The roles you actually need on a response team — and it's not as many people as you'd think.
Read SectionNotification Duties
What the Notifiable Data Breaches scheme actually requires once you confirm a breach.
Read SectionIf the honest answer is "I don't know" or "we'd figure it out," you're not alone. Most small and mid-sized businesses in Australia don't have one written down. They plan to deal with a cyber incident the same way they'd deal with a burst pipe — react, scramble, hope for the best.
The problem is that cyber incidents don't wait for a good time. Without a plan, confusion eats up the first few hours — the ones that matter most — instead of action.
What Is a Cyber Incident Response Plan?
A cyber incident response plan is a written document that tells your team what to do when something goes wrong — a ransomware attack, a phishing breach, a hacked email account, or stolen data.
It's not a security policy. A policy says what you should do in general. A response plan says who does what, in what order, the moment you confirm an incident. Specifically, good plans usually cover:
- Who's on the response team and how to reach them, day or night
- How to tell a real incident from a false alarm
- The exact steps to contain the problem before it spreads
- Who needs to be told, and when (customers, regulators, the board)
- How to get systems back up safely
- What to review once the dust settles
Why Most Businesses Skip This — And Why That's a Mistake
Building a response plan feels like one of those "important but not urgent" tasks. Until it's suddenly the most urgent thing in the building. A few reasons businesses put it off:
- It seems like something only big companies need
- Nobody's sure who should own the project
- There's a belief that antivirus software is enough protection
None of these hold up once you look at the numbers. In fact, the Australian Cyber Security Centre receives a cybercrime report every few minutes, and small businesses get targeted just as often as large ones — often more, because attackers know they're less prepared. Without a plan, response time stretches from hours to days, and every extra hour in a data breach usually means more data exposed and a bigger bill to fix it.
The Core Stages of Incident Response
Most solid plans follow the same basic shape, even if the details differ by business.
- Preparation — Build the team, write the plan, set up monitoring, and make sure everyone knows their role.
- Detection and analysis — Confirm whether it's a real incident, figure out what's affected, and how serious it is.
- Containment — Stop the bleeding. Isolate a device, disable a compromised account, or shut down a system temporarily.
- Eradication — Remove the cause. Delete the malware, close the vulnerability, reset the credentials.
- Recovery — Bring systems back online carefully, watching closely for the problem to return.
- Post-incident review — Look at what happened and what needs to change so it doesn't happen the same way twice.
Skipping any of these stages tends to cause trouble. As a result, businesses that jump from "we found the problem" straight to "we're back online" without proper containment often get hit again within weeks.
Who Should Be on Your Response Team
You don't need a huge team. You need the right people who know their job the moment the phone rings:
- An incident lead who makes the final calls and keeps everyone coordinated
- IT or a managed service provider who can get into the systems and fix things
- Someone from leadership who can approve decisions like taking a system offline
- Legal or compliance support for regulatory notification requirements
Small businesses often outsource some of these roles, and that's fine. What matters is that everyone named in your cyber incident response plan knows who to call, and that number is written down somewhere other than one person's phone.
Notification Obligations You Can't Ignore
If the Notifiable Data Breaches scheme covers your business, you have legal obligations once you confirm a breach involving personal information. The Office of the Australian Information Commissioner expects notification within a set timeframe once you know — or should reasonably have known — that a breach is likely to cause serious harm. Specifically, your plan should spell out:
- Who decides whether a breach meets the notification threshold
- The exact process for notifying OAIC
- How and when affected individuals get told
Getting this wrong doesn't just cause reputational damage. It can bring regulatory penalties on top of whatever the incident already cost you.
Testing Your Cyber Incident Response Plan Before You Need It
A plan that's never been tested is just a guess written on paper. Run a tabletop exercise at least once a year — walk your team through a fake scenario and see where the gaps show up. Common gaps found during testing:
- Contact details that are out of date
- Confusion over who has authority to shut down a system
- No backup way to communicate if email itself is compromised
Afterward, fix what you find, update the plan, and test again next year. In short, treat it like a fire drill, not a one-time project.
Not sure your business could handle a real incident today? A cyber compliance assessment from Cyber Compliance Pro gives you a clear baseline before you build or test a plan.
Getting Help If You're Starting From Zero
If your business doesn't have a cyber incident response plan yet, you're better off building one properly instead of patching together a generic template. As a result, a template tends to miss the specific systems, vendors, and risks that apply to your actual business.
Working with a compliance and cyber consultant means the plan reflects how your business really operates. It also means someone's already thought through the tricky parts, like notification timing and evidence handling, before you're under pressure to figure it out yourself.
Once the plan is written, a tested cyber incident response procedure turns it into step-by-step actions. Our service aligns to ACSC incident response plan guidance and covers every common cyber attack incident response plan scenario.
You can also use our cyber incident response plan template guide to structure the document.
For breaches involving personal information, pair this with a data breach response plan.
Ready to build a cyber incident response plan that actually works?
Get in TouchFrequently Asked Questions
An incident response plan focuses on detecting and containing a cyber incident. A disaster recovery plan focuses on restoring systems and data afterward — they work together but aren't the same document.
Review it at least once a year, and update it any time you change systems, vendors, or staff in key response roles.
Yes. Attackers often target smaller businesses specifically because they expect weaker defences and no formal response process.
Usually a senior IT or operations person, supported by outside specialists or a managed provider for technical response.
Not for every business, but if you handle personal information and fall under the Notifiable Data Breaches scheme, you have real obligations around breach response and reporting.
With the right support, most businesses can have a working plan in place within a few weeks, including a first tabletop test.