10 Ways to Improve Your Incident Response Plan

Written by: Piers Shearman

Categorised: Cyber Resilience

The famous saying “The best laid plans of mice and men” and the boxer Mike Tyson’s quote, “Everyone has a plan until they get punched in the face“, both highlight the same reality: there’s a vast difference between making a plan and putting it into action.

Despite this, boxers, like many a grizzled CISO, know that having a plan is important. The better the plan, the better your chances of avoiding a financial or reputational knockout.

Staying prepared for cyber threats in 2025 starts with a robust Incident Response Plan (IRP)—ensure yours remains strong and effective.

Here are 10 actions you can take to review your existing IRPs:


1. Points of Contact

One of the simplest functions of the IRP is to hold the contact details of those involved. If Teams and Email are offline or potentially compromised, the IRP is vital for holding contact details. This includes:

  • Members of the CMT who are using the IRP
  • The Incident response team (CIRT)
  • Internal support teams such as corporate communications, legal, HR,
  • Current insurance company
  • Third party support organisations such as digital forensics, PR, legal, mutual aid
  • Sector regulators if applicable
  • Data protection Authorities (in all the countries you operate in)

Check that everyone is listed and their details are up to date.


2. Add a checklist

A plan that is over-engineered and overloaded with excessive details can be just as ineffective as having no plan at all. If it’s too lengthy and complex, it’s unlikely to be followed during a high-pressure incident.

Develop a concise, 1-page checklist summarising the key points of your IRP. Keep it easily accessible during discussions so you can quickly reference it and ensure all critical aspects are covered.

Creating a checklist isn’t just about convenience—it’s also a valuable exercise for reviewing and reinforcing familiarity with the IRP, making it far more likely to be effectively utilised in an actual incident.


3. Does it confirm roles and responsibilities?

It is vital that your IRP lists who is on the team and what their roles are.

This needs to be agreed in advance to avoid confusion later. The alternative is to put 50 people into a room with no agreed roles and responsibilities and then look at the CEO to make all the decisions in a caffeine fuelled whack-a-mole until he or she burns out. This doesn’t work for more a couple of hours and is a clear waste of resources. There are a lot of components in responding to a cyber-attack, make sure the responsibilities are shared and people know who is responsible for what.

This should include the responsibilities of the CMT (Gold), who will be using the IRP to manage the incident, and the operational (Silver) team who support them.

Consider role cards – This is an idea from the IRP template of the Australian Signals Directorate,

These cards have three benefits:

  • Useful when devising the IRP and assigning roles.
  • For the individuals – so they are clear on what they are responsible for.
  • For other members -so they can see who they can rely on for support and who they need to inform.

Keep it simple. At a time of high cognitive load, documents need to be simple if you want them to be utilised.


4. Alerting and escalation

Your incident response plan must clearly define what constitutes an incident versus a crisis and outline who needs to be informed at each stage. This clarity ensures you know when to activate the plan and follow the established procedures without hesitation.

If you’re uncertain whether the situation qualifies as an incident, why would you deploy your response plans? Defining these thresholds in advance prevents critical delays during high-pressure situations.

Escalation – Who needs to know and when?

Escalation is about timely communication. Your IRP should specify who needs to be informed and when, closely linking to clearly defined roles and responsibilities. If roles are ambiguous, you risk confusion about who to notify during a critical event.

In a cyber-attack, time is of the essence. Key personnel need to be alerted promptly. If you find yourself wondering, “Should we let head office or group know there might be an issue?”, your escalation process isn’t clearly defined. Delays like this can waste valuable time and create unnecessary stress.

To avoid this, agree in advance who must be contacted for different types of incidents. This proactive approach ensures a swift, coordinated response when it matters most.


5. Where are we going to meet?

Handling a crisis is going to go a lot more smoothly if you can get your key teams into individual rooms to start sorting out this issue. Obviously, that isn’t always practical, but if you can, assign rooms and hope the CFO has decent Wi-Fi on his long-haul flight back from Tahiti.

Once the spaces are designated, print up to date copies of the IRP onsite for use in an emergency or exercise. Think about backup communications at those locations in case connectivity is an issue.


Would you trust your life to your IRP?

In a crisis, like a fire, you reach for a fire extinguisher because it’s simple, reliable, and easy to use under pressure. Now imagine if that extinguisher were outdated, custom-built, and came with a 20-page manual written by someone who left the company five years ago—you’d probably ignore it and try to improvise instead, risking greater harm.


6. Review the list of critical systems

Regularly reviewing your list of critical systems ensures your incident response plan stays relevant. Technologies and business priorities change, so systems that were once critical may no longer be, while new systems may need to be included. Keeping the list up to date helps you focus on the most important assets during an incident.

As systems evolve through updates, mergers, or acquisitions, it’s vital to assess their current role and potential risks. This review ensures your response is aligned with the latest organisational needs and technological landscape.


7. Does the plan refer to all stages of the technical response?

Your IRP should comprehensively outline the actions required at each stage of the incident lifecycle. An effective response plan is typically divided into the following stages:

Detection and Analysis (and Activation): Clearly define how incidents are identified, initial analysis steps, and the criteria for formally activating the response plan.

Containment, Eradication, and Recovery: Specify methods for limiting damage, removing threats from the environment, and restoring systems to normal operations while minimising downtime.

Post-Incident Activity: Detail the process for conducting lessons learned reviews, capturing insights, and implementing improvements based on findings.

These stages ensure a structured and phased approach to handling incidents. Since complexity often increases as an incident progresses, starting with a strong foundation in detection and analysis is critical. Ensure the IRP provides clear steps for each phase, supporting both technical teams and decision-makers throughout the process.


8. Communications and stakeholder engagement

For the crisis management team operating at a strategic level communications are one of the most important aspects of an incident. While some of the detail of your communications strategy may be in a separate Communications Plan, start by checking for the following:

  • Does the plan include the comms response?
  • Is it clear how the various response teams will communicate with each other?
  • Are primary external and internal comms channels clearly identified?
  • Is there a complete list of stakeholders/groups, who will need to be informed and managed?
  • Are the contact details of all relevant external and internal stakeholders included?

9. Playbooks or SOPs

Your IRP should reference any playbooks you have created to deal with likely cyber scenarios you might need to respond to. Consider detailed step-by-step playbooks for common IT scenarios such as ransomware, DOS, data loss, Business Email Compromise or supply chain attack.

Check that you have the playbooks you need, they are up to date and stored securely alongside the incident response plan so they are accessible during an incident.


10. Run regular table top exercises

Dusting off your plans and playbooks and running a table top exercise is the most effective way check your IRP is effective and quickly make improvements.

  • Tabletop exercises help reveal gaps or unclear areas in the IRP, allowing them to be addressed before a real incident occurs.
  • Regular practice ensures all stakeholders understand their roles and responsibilities, improving coordination and decision-making during a crisis.
  • Tabletop exercises provide a safe environment to test the IRP under realistic conditions, stress-testing processes without operational impact.

For more information on running a table top exercise, see our updated complete guide:

Or get in touch to see how Red Goat can assist you in developing an exercise to test your IRPs.


Tabletop Exercise Guide 2026

Our Complete Guide to Running a Cyber Security Tabletop Exercise gives you the tools to test and strengthen your organisation’s incident response capabilities. This expert resource walks you step by step through creating realistic cyber crisis simulations that help your team:

✅ Identify gaps in your incident response plans

✅ Improve decision-making under pressure

✅ Strengthen cross-departmental communication

✅ Build management buy-in for security improvements

✅ Boost overall cyber resilience

What’s Inside the Guide?

✅ The 10-step checklist for delivering effective tabletop exercises

✅ Key elements for designing realistic scenarios

✅ How to engage your crisis management team for maximum impact

✅ Proven strategies for post-exercise debriefing and improvement

 

Brought to you by Red Goat Cyber Security, experts in cyber crisis simulation and resilience training.

 
Download File
Tabletop Exercise Guide 2026

Related Content

Menu