One-page incident response plan
Fill it in now, print it, and keep a copy somewhere you can reach without your computer.
Incident response plan:
General guidance, not legal advice. This template reflects UK requirements as of October 2026. Reporting duties can differ by sector and by contract, so check them for your organisation.
Your entries are saved in this browser only. Nothing is sent to us.
1. Who to call
2. In the first hour: do
- Call your incident lead, then your IT support and insurer.
- Disconnect affected devices from the network (unplug or turn off Wi-Fi), but leave them switched on.
- Write down what you see, with times. Photograph ransom notes or error messages.
- Talk by phone, not by email or chat, if those accounts may be compromised.
- Change passwords from a clean device, starting with email and admin accounts.
Don’t
- Switch off or wipe devices. You may destroy the evidence you need.
- Pay a ransom or contact the attackers without specialist and insurer advice.
- Restore from backups until you know how the attackers got in.
- Announce anything publicly before you know the facts.
3. Is personal data involved?
If personal data may have been lost, stolen, altered or exposed, the clock has started. A breach that is likely to put people at risk must be reported to the ICO without undue delay, and within 72 hours of you becoming aware of it where feasible. If the risk to people is high, you must tell them too, without undue delay. If you decide not to report, record why.
4. Who else to tell
| Police (England, Wales, NI) | Report Fraud: 0300 123 2040. If you are under live attack, call straight away. |
|---|---|
| Police (Scotland) | Police Scotland: 101 |
| ICO | Personal data breaches: 0303 123 1113 or online, within 72 hours |
| Your bank | Immediately, for any payment fraud. Speed matters for recovering money. |
| Your insurer | As your policy requires. Late notice can affect your cover. |
| NCSC | For significant incidents, via the NCSC website |
| Customers and suppliers | If their data or payments are affected, once you know the facts |
5. Recover
- Find and close the way in before restoring anything.
- Restore from backups you know are clean.
- Reset passwords and check MFA on every affected account.
- Watch closely for a few weeks. Attackers often try again.
6. Afterwards
- Hold a short review within two weeks: what happened, what worked, what didn’t.
- Update this plan and fix the weaknesses you found.
- Run through the plan once a year, even if nothing has happened.
Incident log
| Date and time | What happened or was found | Action taken | By |
|---|---|---|---|
The printed version includes a blank incident log on a second page.
General guidance only, not legal advice. Check reporting duties and contact details for your organisation. Source: cyberascentconsultancy.com, reviewed October 2026.
Important
This template is provided free as general information for UK organisations. It is not legal, regulatory or insurance advice, and it is not a substitute for professional advice on your circumstances. Laws, contact details and reporting requirements change; check them before relying on them. Your organisation may have additional duties, for example under the NIS Regulations, financial services rules, NHS data security requirements, contracts with customers, or the terms of your insurance policy. To the extent permitted by law, Cyber Ascent Consultancy Limited accepts no liability for any loss arising from use of this template. See our terms of use.