Resources

One-page incident response plan

Fill it in now, print it, and keep a copy somewhere you can reach without your computer.

By Jason Kelly, Certified ISO/IEC 27001 Lead Implementer. Last reviewed October 2026.

General guidance, not legal advice. This template reflects UK requirements as of October 2026. Reporting duties can differ by sector and by contract, so check them for your organisation.

Your entries are saved in this browser only. Nothing is sent to us.

1. Who to call

Incident leadThe person who makes decisions
DeputyIf the lead is unavailable
IT support or MSPInclude out-of-hours
Cyber insurerMany require you to call them first
Bank fraud lineFor payment fraud or diversion
Data protection leadOwns the 72-hour call

2. In the first hour: do

  • Call your incident lead, then your IT support and insurer.
  • Disconnect affected devices from the network (unplug or turn off Wi-Fi), but leave them switched on.
  • Write down what you see, with times. Photograph ransom notes or error messages.
  • Talk by phone, not by email or chat, if those accounts may be compromised.
  • Change passwords from a clean device, starting with email and admin accounts.

Don’t

  • Switch off or wipe devices. You may destroy the evidence you need.
  • Pay a ransom or contact the attackers without specialist and insurer advice.
  • Restore from backups until you know how the attackers got in.
  • Announce anything publicly before you know the facts.

3. Is personal data involved?

If personal data may have been lost, stolen, altered or exposed, the clock has started. A breach that is likely to put people at risk must be reported to the ICO without undue delay, and within 72 hours of you becoming aware of it where feasible. If the risk to people is high, you must tell them too, without undue delay. If you decide not to report, record why.

4. Who else to tell

Police (England, Wales, NI)Report Fraud: 0300 123 2040. If you are under live attack, call straight away.
Police (Scotland)Police Scotland: 101
ICOPersonal data breaches: 0303 123 1113 or online, within 72 hours
Your bankImmediately, for any payment fraud. Speed matters for recovering money.
Your insurerAs your policy requires. Late notice can affect your cover.
NCSCFor significant incidents, via the NCSC website
Customers and suppliersIf their data or payments are affected, once you know the facts

5. Recover

  • Find and close the way in before restoring anything.
  • Restore from backups you know are clean.
  • Reset passwords and check MFA on every affected account.
  • Watch closely for a few weeks. Attackers often try again.

6. Afterwards

  • Hold a short review within two weeks: what happened, what worked, what didn’t.
  • Update this plan and fix the weaknesses you found.
  • Run through the plan once a year, even if nothing has happened.
Get help preparing for incidents

The printed version includes a blank incident log on a second page.

Important

This template is provided free as general information for UK organisations. It is not legal, regulatory or insurance advice, and it is not a substitute for professional advice on your circumstances. Laws, contact details and reporting requirements change; check them before relying on them. Your organisation may have additional duties, for example under the NIS Regulations, financial services rules, NHS data security requirements, contracts with customers, or the terms of your insurance policy. To the extent permitted by law, Cyber Ascent Consultancy Limited accepts no liability for any loss arising from use of this template. See our terms of use.