Cybersecurity Incident Response Plan: What It Must Cover

What Is a Cybersecurity Incident Response Plan, and Does Your Business Have One?

An incident response plan is a written, tested playbook for what your business does when a cyberattack or data breach happens. Most small businesses don't have one, and many regulators, auditors and insurers expect it.

GLBA, SEC Regulation S-P, HIPAA, PCI DSS and SOC 2 all expect a documented way to respond to security incidents, and cyber insurance carriers ask about it on applications and renewals. Yet for many small and midsize businesses, the plan is missing or is a generic template nobody has read, tested or adapted to the actual environment. Here's what a plan is, what it should contain and which notification deadlines it needs to cover.

What an incident response plan is

An incident response plan (IRP) is a documented set of procedures for how your organization will detect, contain, investigate, recover from and report a cybersecurity incident. It answers the questions nobody can think through clearly under pressure: Who do we call first? Who has authority to take systems offline? When do we notify clients, regulators and our insurer? Where are the backups and who can reach them? Who speaks for the company? Think of it as a fire drill for your network: you want the exits memorized before the alarm goes off.

Which frameworks require it

FTC Safeguards Rule (GLBA). Non-bank financial institutions such as tax preparers, mortgage brokers and some CPAs and financial planners must have a written incident response plan covering its goals, internal response processes, roles and responsibilities, communications, documentation, remediation and post-incident review. The amended rule took effect in June 2023.

SEC Regulation S-P (registered investment advisers and broker-dealers). The 2024 amendments require a written incident response program to detect, respond to and recover from unauthorized access to customer information, plus customer notification and service-provider oversight. Compliance dates were December 3, 2025 for larger firms and June 3, 2026 for smaller firms. For the details, see what Regulation S-P requires of advisers and broker-dealers. (The SEC's separate 2023 cybersecurity disclosure rule, Form 8-K Item 1.05, applies to public companies, and the SEC's proposed cybersecurity rule for advisers was withdrawn in 2025.)

HIPAA. The Security Rule requires security incident procedures: identifying and responding to suspected or known incidents, reducing harmful effects and documenting incidents and outcomes. It also requires a contingency plan covering data backup, disaster recovery, emergency-mode operations and testing.

PCI DSS v4.0.1. Requires an incident response plan that is ready to activate immediately, with defined roles, communication and contact procedures, and annual testing.

SOC 2. Auditors look for documented incident management procedures under the Trust Services Criteria, and evidence that they are used and tested.

Cyber insurance. Carriers commonly ask whether you have a written plan, and some ask whether it has been tested. See What does your cyber insurance policy require?

What it needs to contain

A functional plan covers six phases.

Preparation. Who is on the response team, what their roles are, and what tools and contacts they need. It also defines what "normal" looks like so you can recognize "abnormal." This work happens before any incident.

Identification. What alerts, behaviors or reports trigger the plan, where the line sits between a minor security event and a declared incident, and who makes that call.

Containment. Short-term steps (isolate the affected system, cut off the attacker's access) and longer-term steps (stabilize the environment while you investigate), plus who has authority to take systems offline.

Eradication. Remove the attacker and any malware, identify the root cause and close the weakness that was exploited.

Recovery. Restore from clean, verified backups, check integrity before bringing systems back, and watch for signs of reinfection. This is where tested backup and disaster recovery matters. See also what happens during an IT emergency.

Post-incident review. What happened, what worked, what needs to change, and what documentation regulators, insurers or clients will need.

Notification deadlines to build into the plan

An incident at a regulated business can trigger notice requirements with fixed clocks. Common ones:

  • HIPAA: covered entities notify affected individuals without unreasonable delay and no later than 60 days after discovering a breach, and also notify HHS (and the media when 500 or more residents of a state are affected). Business associates notify the covered entity, not the other way around, within 60 days or sooner if the BAA requires.
  • SEC Regulation S-P: advisers and broker-dealers notify affected customers as soon as practicable and no later than 30 days after becoming aware that sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization.
  • FTC Safeguards Rule: non-bank financial institutions notify the FTC within 30 days of discovering an event involving unencrypted information of 500 or more consumers.
  • SEC public company rule: public companies disclose material cybersecurity incidents on Form 8-K within four business days of determining materiality.
  • Florida (FIPA, s. 501.171): notify affected individuals within 30 days, and the Florida Department of Legal Affairs when 500 or more Floridians are affected.
  • PCI DSS: follow your acquiring bank's and the card brands' notification requirements, which typically call for prompt notice.
  • Your cyber insurance policy: most policies require prompt notice, often through the carrier's breach hotline.

Missing a deadline while scrambling to understand what happened can create a second problem on top of the first. Having the requirements, contacts and decision criteria written down in advance is what prevents that. For investment advisers, our IT for financial advisers and wealth managers page covers how this fits Reg S-P.

Testing: the part everyone skips

An untested plan is mostly a hopeful document. Plans should be tested at least annually, usually through a tabletop exercise where the team talks through a simulated incident, finds the gaps and updates the plan. Many frameworks expect evidence of testing, not just a plan on file.

Tabletop exercises surface the practical problems that look fine on paper: the primary contact left the company last year, the backup credentials are stored on the system that just got encrypted, or the legal counsel number is out of date.

How NerdSquad helps

We help managed IT clients document an incident response plan that fits their environment and regulatory obligations, walk through it with the team, and update it when systems or staff change. On the technical side, our monitoring, endpoint detection and response (EDR) and backups give the plan something real to rely on. A plan works best on top of a current risk picture, so see What is a compliance risk assessment?

NerdSquad is not a law firm; confirm your obligations with your compliance counsel.


Talk to NerdSquad

Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.

Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.

Related: Cybersecurity services for businesses