An incident response plan you can fill in today.

This incident response plan template is for a small business with no security team: who to call, in what order, a first hour checklist, and how to contain and recover. Fill in the names and numbers and keep it somewhere everyone can find it, not only on the computer that might be the problem.

What is in the plan.

Contacts, what counts as an incident, the first hour, containment, who to call, and recovery.

Incident Response PlanOne page, fill in the blanks

1. Roles and contacts

  • Incident lead: Phone:
  • IT or systems support: Phone:
  • Insurance carrier: Policy #: Phone:
  • Bank or payments provider: Phone:
  • Legal counsel: Phone:
  • Local law enforcement, non-emergency line:

2. What counts as an incident

  • A system that is locked, encrypted or held for ransom
  • A lost or stolen device that had company data on it
  • A payment sent to the wrong account after a suspicious email
  • A login alert from a device or location nobody recognizes
  • A customer or vendor reporting their data showed up somewhere it should not
  • Anything that looks like a breach, even if you are not sure

3. First hour checklist

  1. Confirm it is real, not a false alarm.
  2. Disconnect the affected device from the network. Do not turn it off.
  3. Tell the incident lead.
  4. Write down what happened and when, while it is fresh.
  5. Do not pay anything or reply to the sender yet.

4. Containment

  • Change passwords for any account that may be compromised, starting with email and banking
  • Turn on two factor authentication everywhere it is not already on
  • Revoke access for any device or account you are not sure about

5. Who to call, and in what order

  1. IT or systems support, to contain it
  2. Insurance carrier. Many policies require notice within a set number of days
  3. Bank or payments provider, if money moved
  4. Legal counsel, if customer or employee data may be involved
  5. Law enforcement, if a crime occurred

6. Communication

is the single point of contact for anything said to customers, employees or the press. Nobody else speaks on the record about the incident until legal counsel has weighed in.

7. Recovery

Restore from backup, and confirm the system is clean before reconnecting it. Reset credentials for every account that was touched, and check financial accounts for unfamiliar activity before closing this out.

8. After-action review

Within days of any incident, meet to review what happened, what worked, and what changes in this plan as a result.

9. Sign-off

Reviewed by: Date:

Questions about the plan.

What should an incident response plan include?

Who is in charge, who to call and in what order, what to do in the first hour, how to contain the problem, and how you review it afterward. This template covers all five on one page.

Who should have a copy?

The incident lead and at least one backup, printed or saved somewhere that does not depend on the systems that might be the problem. A plan that only lives on a locked computer does not help.

Why does ransomware matter for a small business?

“Ransomware appeared in 88% of breaches at small and mid-sized businesses, against 39% at large ones.” Verizon 2025 DBIR. A written plan is what turns a locked system into a bad afternoon instead of a bad year.

Start with a two-week review.

Fixed fee. You finish with a ranked plan of what to fix first, what it saves and what it protects.

Prefer email? Write to hello@satsumahq.com

One line is plenty. We will ask the rest on the call.