Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

Cyber Incident Response Plan Generator

An incident response plan built from your answers: roles, severity, playbooks, templates.

Security No upload Free preview, no sign-upIncluded in your pass Premium tool Premium pass: ₹799 for 30 days

Free preview.

  • Free preview: every page with your details, the first part of the wording readable and the rest hidden, marked “MySmartCoPilot preview · not for use”.
  • Locked until you unlock it: download, copy and print.
  • Unlock: Premium pass, ₹799 for 30 days, a one-time payment that never renews.

Ways to unlock shows how to get the full result.

See passes (opens in a new tab)

Printing this result is locked in the free preview.

Plan preview

Your organisation

Plan details and branding

Logo PNG or JPEG, on the cover

Team and contacts

Untick the roles you do not have: their tasks pass to the incident lead and their approvals to the executive.

Incident lead

Runs the response: declares the incident and its severity, calls in the team, assigns tasks, keeps the incident log and sets the times of updates.

Deputy incident lead

Stands in for the incident lead, keeps the timeline and the action list, and takes over long incidents in shifts.

Technical lead

Leads the investigation, containment, eradication and recovery work, and directs IT staff and outside responders.

Executive decision-maker

Approves high-impact decisions: shutting down critical services, outside spending, notifications and public statements.

Communications lead

Writes and sends internal and external messages from one agreed set of facts, and handles questions from the media.

Legal and privacy lead

Advises on notifications, evidence, contracts and insurance, and decides with the executive what must be reported to whom.

HR lead

Handles staff matters: insider cases, messages to staff with the communications lead, and welfare during long incidents.

Finance lead

Stops and recalls fraudulent payments with the bank, works with the insurer and records the costs of the incident.

Customer service lead

Briefs front-line staff, answers customers with approved wording and passes on what customers report.

Who does what

The suggested assignments, one Accountable role (A or A/R) per activity. R does the work, C is consulted, I is informed.

Responsibilities of each role for each activity
Activity LeadDeputyTechExecCommsLegalHRFinCust
Declare an incident and set its severity
Investigate and keep the technical timeline
Contain: isolate systems, disable accounts
Shut down a critical service or take the network offline
Bring in outside responders
Notify the cyber insurer
Preserve evidence and the incident log
Notify regulators and authorities
Notify affected customers and people
Report to law enforcement
Brief staff
Public and media statements
Stop or recall payments
Staff matters in insider cases
Restore systems and confirm normal operation
Close the incident and run the review

Systems and data

Critical systems

The systems the business cannot do without, in any order: the plan sorts them by tier for recovery.

    Services and protection

    Cloud platforms
    Data you hold
    Also true for you decides the reporting rules the plan names

    Outside help and authorities

    The firms and authorities you would call. Check the insurance policy: it may say whom to call first.

      Severity levels

      Suggested criteria and internal response targets: change them to suit you. These are your own targets, not legal deadlines.

      SEV-1 Critical
      SEV-2 High
      SEV-3 Medium
      SEV-4 Low

      Communication

      Message templates

      Playbooks and evidence

      Playbooks

      Checks

        Plan preview

        Next steps

        For general information only, not legal advice. Templates are generic starting points — have a qualified lawyer review anything you rely on.

        About the Cyber Incident Response Plan Generator

        When an incident starts, nobody has time to work out who decides, who calls whom and what to do first. This generator asks about your organisation — its team, systems, suppliers, data and the channels you use — and writes an incident response plan around the answers, built on NIST SP 800-61 Rev. 3 and the Detect, Respond and Recover functions of the NIST Cybersecurity Framework 2.0.

        The plan names your people in every step: a one-page quick start for the first hour, roles with contacts and stand-ins, a RACI matrix of who does what, outside help and the official reporting points of your country, a severity matrix with response times and escalation, communication rules with message templates for staff, customers, authorities, police, partners and the media, evidence handling with a chain of custody form, recovery priorities from your own systems, and playbooks for ransomware, phishing and email compromise, personal data breaches, lost devices, DDoS, insider misuse and cloud account takeover. Tabletop scenarios, a review schedule and readiness actions drawn from your answers keep it alive.

        Reporting duties are named with their official sources, and the deadlines come from the Breach Notification Deadline Calculator rather than being fixed in the plan. The free preview shows every page as you build it; the DOCX, PDF and Markdown files need a Premium pass. Nothing you enter is uploaded.

        How to use it

        1. Describe the organisation: its name, country, sector and size. The country sets the official reporting points and the rules the plan points to.
        2. Name the team: the incident lead, the deputy, the technical lead and the executive who decides, then the roles you have (communications, legal and privacy, HR, finance, customer service), with phone numbers and stand-ins. Adjust Who does what if your assignments differ.
        3. List the critical systems with owners and recovery targets, say which email, identity, cloud, backup and security tools you use, and tick the kinds of data you hold.
        4. Add your outside help — IT provider, incident response firm, cyber insurer, bank, internet provider — and press Add the official reporting points for your country.
        5. Check the severity levels, the channels (including an out-of-band channel for when email cannot be trusted), the playbooks and the templates, and read the Checks for anything missing.
        6. Read the plan in the preview beside the form. With a Premium pass, download it as DOCX, PDF or Markdown, copy it or print it; without one, the free preview shows every page with the wording partly hidden.
        7. Use Save answers to keep your answers as a file and open them again at the next review: that works with or without a pass.

        Examples

        A freight company of 120 people
        Input
        Example plan: nine roles, five systems (two critical), Microsoft 365, AWS, offline backups not confirmed, multi-factor authentication for administrators only
        Result
        A plan of about 38 pages: quick start, team and RACI, outside contacts, four severity levels, seven playbooks, six templates, seven tabletop scenarios, readiness actions for offline backups and multi-factor authentication, and appendices with the contact sheet and the forms.

        Press Example plan on the page; the official reporting points follow the country you choose.

        A small company in India
        Input
        Country India, customer personal data, a team of three (incident lead, technical lead, executive) and an outside IT provider
        Result
        Section 10 names the CERT-In Directions and the DPDP Rules with their official sources and lists CERT-In’s reporting email, phone and fax and the National Cyber Crime Reporting Portal; the readiness actions include the CERT-In point of contact, 180 days of logs kept in India and clock synchronisation with NIC or NPL time servers.

        Common uses

        • Writing a first incident response plan for a small or medium organisation.
        • Replacing an out-of-date plan with one built on NIST SP 800-61 Rev. 3.
        • Meeting a customer’s, insurer’s or auditor’s request for a documented incident response plan.
        • Preparing tabletop exercises with scenarios that match your own playbooks.
        • Giving the board and the team one agreed answer to “who decides what” before an incident.

        What the plan contains

        • 1–2. About this plan and a quick start: purpose, scope, approach, authority, and what anyone and the incident lead do in the first hour.
        • 3–4. Team and outside help: roles, contacts and stand-ins, what each role does, who does what (RACI), who may take which decision, suppliers and official reporting points.
        • 5–7. Severity, detection and response: four levels with criteria, response times and who is told; how incidents are reported and triaged; the incident log, escalation, containment and eradication.
        • 8–11. Communication, evidence, reporting and recovery: channels and rules with six message templates; what evidence to keep and how; the reporting rules that may apply; recovery priorities from your systems and when an incident ends.
        • 12–14. Playbooks, lessons and readiness: the playbooks you chose, the after-incident review, readiness actions, tabletop scenarios, reviews and versions.
        • Appendices: a one-page contact sheet, an incident log, an incident report form, a chain of custody form, an after-action report and a glossary with the sources.

        How your answers shape it

        The plan is written about your organisation, not in general terms. Steps name the people who take them (“Call the incident lead (Sam Patel)”), the bank, insurer and providers you listed, and the email, identity and cloud services you use. Roles you do not have are left out and their tasks pass to the incident lead, and the RACI matrix is adjusted so that every activity still has one accountable role.

        Gaps in the answers become readiness actions: no offline backups, untested restores, multi-factor authentication not for everyone, no central logs, no out-of-band channel. The kinds of data you hold, your country and a few questions (personal data of people in the EU or UK, essential services, HIPAA, SEC reporting) decide which reporting rules the plan names.

        Built on NIST SP 800-61 Rev. 3

        NIST’s incident response guidance organises the work by the functions of the Cybersecurity Framework 2.0: Detect (continuous monitoring and adverse event analysis), Respond (incident management, analysis, reporting and communication, mitigation) and Recover (recovery plan execution and communication), with lessons learned feeding improvement and Govern, Identify and Protect preparing for all of it. The plan follows that structure and its recommendations: an incident lead for each incident, incidents handled by priority rather than in order of arrival, risk factors for severity, protected incident records, evidence integrity, verified backups before restoring, and an after-action report.

        The ransomware steps follow the response checklist of the #StopRansomware Guide by CISA, the NSA, the FBI and MS-ISAC; the payment-fraud steps follow the FBI’s advice on business email compromise.

        Reporting rules and deadlines

        Which authorities must be told, and how fast, depends on where you operate, whose data is involved, your sector and your contracts — and the rules change. So the plan names the rules your answers point to with their official sources — for example the directions of CERT-In and the DPDP Rules in India, the GDPR and the NIS2 Directive in the EU, the UK GDPR, HIPAA and SEC Form 8-K in the US, the Notifiable Data Breaches scheme in Australia and PIPEDA in Canada — and sends the deadlines to the Breach Notification Deadline Calculator, which works them out from the moment you became aware. Your legal adviser confirms which apply.

        Limitations

        • It is a template filled in from your answers, not legal advice: it does not decide which laws apply to you. Have it reviewed by a qualified legal adviser.
        • The playbooks describe common incidents in general terms; adapt the technical steps to your own systems and tools.
        • The plan is only as current as its contacts: check them every quarter.
        • The plan is written in English. The PDF uses Noto Sans for Latin, Greek and Cyrillic text; names in scripts that need shaping (such as Devanagari or Arabic) show as “?” in the PDF and in the free preview’s pages — use the DOCX for them.

        Privacy

        Your answers — names, phone numbers, suppliers and systems — stay in this browser and are never uploaded. Keep these answers in this browser is off unless you switch it on, so a plan is not left on a shared computer; Save answers gives you a file to keep instead.

        Frequently asked questions

        What do I get without a pass?

        Without a pass, Cyber Incident Response Plan Generator shows every page with your details, the first part of the wording readable and the rest hidden, marked “MySmartCoPilot preview · not for use”. Until you unlock it, the result can’t be downloaded, copied or printed. A Premium pass, a one-time payment that never renews, unlocks the full result. The pricing page lists the passes and their prices.

        Why does the plan not list the reporting deadlines?

        Because they depend on the facts of each incident — the country, the data, the sector, when you became aware — and on rules that change. The plan names the rules that may apply and their sources, and the Breach Notification Deadline Calculator works out the actual deadlines when an incident happens.

        Does this make us compliant with a law or standard?

        No tool can promise that. A documented, tested incident response plan is something many laws, standards and insurers expect, and this one follows NIST SP 800-61 Rev. 3, but whether it meets a particular duty is for your legal adviser or auditor to judge.

        We are a small company. Do we need all these roles?

        No. Untick the roles you do not have: the incident lead takes on their tasks and the executive their approvals, and the RACI matrix is adjusted. Many small companies run with an incident lead, a technical lead (often the IT provider) and the owner as the executive.

        Can I edit the plan after downloading it?

        Yes: the DOCX opens in Word and other word processors, and the Markdown in any editor or wiki. For the next review it is usually quicker to open your saved answers here, change them and download the plan again.

        How often should we test the plan?

        Choose how often in the plan details: every three months, twice a year or once a year. The plan includes a tabletop scenario for each playbook you chose, with updates to read out during the exercise and questions to discuss.

        Where are my answers kept?

        Only in this page while it is open, unless you switch on Keep these answers in this browser or save the answers file. Nothing is sent to a server.

        Quick answers and tool search

        Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.