An incident response plan is a written, tested playbook for what your business does when a cyberattack or data breach happens. Most small businesses don't have one, and many regulators, auditors and insurers expect it.
GLBA, SEC Regulation S-P, HIPAA, PCI DSS and SOC 2 all expect a documented way to respond to security incidents, and cyber insurance carriers ask about it on applications and renewals. Yet for many small and midsize businesses, the plan is missing or is a generic template nobody has read, tested or adapted to the actual environment. Here's what a plan is, what it should contain and which notification deadlines it needs to cover.
An incident response plan (IRP) is a documented set of procedures for how your organization will detect, contain, investigate, recover from and report a cybersecurity incident. It answers the questions nobody can think through clearly under pressure: Who do we call first? Who has authority to take systems offline? When do we notify clients, regulators and our insurer? Where are the backups and who can reach them? Who speaks for the company? Think of it as a fire drill for your network: you want the exits memorized before the alarm goes off.
FTC Safeguards Rule (GLBA). Non-bank financial institutions such as tax preparers, mortgage brokers and some CPAs and financial planners must have a written incident response plan covering its goals, internal response processes, roles and responsibilities, communications, documentation, remediation and post-incident review. The amended rule took effect in June 2023.
SEC Regulation S-P (registered investment advisers and broker-dealers). The 2024 amendments require a written incident response program to detect, respond to and recover from unauthorized access to customer information, plus customer notification and service-provider oversight. Compliance dates were December 3, 2025 for larger firms and June 3, 2026 for smaller firms. For the details, see what Regulation S-P requires of advisers and broker-dealers. (The SEC's separate 2023 cybersecurity disclosure rule, Form 8-K Item 1.05, applies to public companies, and the SEC's proposed cybersecurity rule for advisers was withdrawn in 2025.)
HIPAA. The Security Rule requires security incident procedures: identifying and responding to suspected or known incidents, reducing harmful effects and documenting incidents and outcomes. It also requires a contingency plan covering data backup, disaster recovery, emergency-mode operations and testing.
PCI DSS v4.0.1. Requires an incident response plan that is ready to activate immediately, with defined roles, communication and contact procedures, and annual testing.
SOC 2. Auditors look for documented incident management procedures under the Trust Services Criteria, and evidence that they are used and tested.
Cyber insurance. Carriers commonly ask whether you have a written plan, and some ask whether it has been tested. See What does your cyber insurance policy require?
A functional plan covers six phases.
Preparation. Who is on the response team, what their roles are, and what tools and contacts they need. It also defines what "normal" looks like so you can recognize "abnormal." This work happens before any incident.
Identification. What alerts, behaviors or reports trigger the plan, where the line sits between a minor security event and a declared incident, and who makes that call.
Containment. Short-term steps (isolate the affected system, cut off the attacker's access) and longer-term steps (stabilize the environment while you investigate), plus who has authority to take systems offline.
Eradication. Remove the attacker and any malware, identify the root cause and close the weakness that was exploited.
Recovery. Restore from clean, verified backups, check integrity before bringing systems back, and watch for signs of reinfection. This is where tested backup and disaster recovery matters. See also what happens during an IT emergency.
Post-incident review. What happened, what worked, what needs to change, and what documentation regulators, insurers or clients will need.
An incident at a regulated business can trigger notice requirements with fixed clocks. Common ones:
Missing a deadline while scrambling to understand what happened can create a second problem on top of the first. Having the requirements, contacts and decision criteria written down in advance is what prevents that. For investment advisers, our IT for financial advisers and wealth managers page covers how this fits Reg S-P.
An untested plan is mostly a hopeful document. Plans should be tested at least annually, usually through a tabletop exercise where the team talks through a simulated incident, finds the gaps and updates the plan. Many frameworks expect evidence of testing, not just a plan on file.
Tabletop exercises surface the practical problems that look fine on paper: the primary contact left the company last year, the backup credentials are stored on the system that just got encrypted, or the legal counsel number is out of date.
We help managed IT clients document an incident response plan that fits their environment and regulatory obligations, walk through it with the team, and update it when systems or staff change. On the technical side, our monitoring, endpoint detection and response (EDR) and backups give the plan something real to rely on. A plan works best on top of a current risk picture, so see What is a compliance risk assessment?
NerdSquad is not a law firm; confirm your obligations with your compliance counsel.
Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.
Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.