Back to blog
7 minKim Ytredal

How to Build an Incident Response Plan That Actually Works

Incident ResponsePlanningPreparedness

Most organizations have an incident response plan in a drawer — written once, never tested, and nobody knows where it is when the alarm goes off. An effective incident response plan must be living, practiced, and accessible.

Key elements of a good plan

1. Define roles and responsibilities

  • Incident Commander — — decision-maker during the incident
  • Technical Lead — — coordinates the technical response
  • Communications Lead — — internal and external communications
  • Legal Advisor — — GDPR notification, insurance, authority reporting

2. Classify incidents

Not all incidents require full mobilization. Define levels:

  • Level 1 — Low — phishing attempts, malware on single machine
  • Level 2 — Medium — compromised user account, data loss
  • Level 3 — High — ransomware, active intrusion, major data breach

3. Establish communication routines

  • Who gets notified first? Establish an escalation chain
  • Use a dedicated communication channel (not one that may be compromised)
  • Have contact lists available offline (not just in email)

4. Document technical procedures

  • Isolation of affected systems
  • Evidence collection and preservation
  • Attack vector analysis
  • Recovery procedures

5. Test and practice

  • Conduct tabletop exercises quarterly
  • Run full-scale simulations annually
  • Update the plan after each exercise and real incident

Common mistakes

  • Plan is too long — — under pressure, nobody reads an 80-page document
  • Nobody knows about the plan — — anchor it across the organization
  • Missing contact info — — have phone numbers, not just email
  • No offline access — — the plan often lives on the systems that are down

ForSec helps develop, implement, and test incident response plans tailored to your organization. We can also serve as your external incident response team.

Need help with cybersecurity?

We help Norwegian organizations protect against digital threats. Contact us for a no-obligation conversation.

Contact us