Cyber Incident Response Plan Generator
An incident response plan built from your answers: roles, severity, playbooks, templates.
Free preview.
- Free preview: every page with your details, the first part of the wording readable and the rest hidden, marked “MySmartCoPilot preview · not for use”.
- Locked until you unlock it: download, copy and print.
- Unlock: Premium pass, ₹799 for 30 days, a one-time payment that never renews.
Ways to unlock shows how to get the full result.
Printing this result is locked in the free preview.
Plan preview
Locked in the free preview. Opens the ways to unlock this result.
Locked in the free preview. Batch runs unlock with a pass.
Locked in the free preview. Query results unlock with a pass.
For general information only, not legal advice. Templates are generic starting points — have a qualified lawyer review anything you rely on.
About the Cyber Incident Response Plan Generator
When an incident starts, nobody has time to work out who decides, who calls whom and what to do first. This generator asks about your organisation — its team, systems, suppliers, data and the channels you use — and writes an incident response plan around the answers, built on NIST SP 800-61 Rev. 3 and the Detect, Respond and Recover functions of the NIST Cybersecurity Framework 2.0.
The plan names your people in every step: a one-page quick start for the first hour, roles with contacts and stand-ins, a RACI matrix of who does what, outside help and the official reporting points of your country, a severity matrix with response times and escalation, communication rules with message templates for staff, customers, authorities, police, partners and the media, evidence handling with a chain of custody form, recovery priorities from your own systems, and playbooks for ransomware, phishing and email compromise, personal data breaches, lost devices, DDoS, insider misuse and cloud account takeover. Tabletop scenarios, a review schedule and readiness actions drawn from your answers keep it alive.
Reporting duties are named with their official sources, and the deadlines come from the Breach Notification Deadline Calculator rather than being fixed in the plan. The free preview shows every page as you build it; the DOCX, PDF and Markdown files need a Premium pass. Nothing you enter is uploaded.
How to use it
- Describe the organisation: its name, country, sector and size. The country sets the official reporting points and the rules the plan points to.
- Name the team: the incident lead, the deputy, the technical lead and the executive who decides, then the roles you have (communications, legal and privacy, HR, finance, customer service), with phone numbers and stand-ins. Adjust Who does what if your assignments differ.
- List the critical systems with owners and recovery targets, say which email, identity, cloud, backup and security tools you use, and tick the kinds of data you hold.
- Add your outside help — IT provider, incident response firm, cyber insurer, bank, internet provider — and press Add the official reporting points for your country.
- Check the severity levels, the channels (including an out-of-band channel for when email cannot be trusted), the playbooks and the templates, and read the Checks for anything missing.
- Read the plan in the preview beside the form. With a Premium pass, download it as DOCX, PDF or Markdown, copy it or print it; without one, the free preview shows every page with the wording partly hidden.
- Use Save answers to keep your answers as a file and open them again at the next review: that works with or without a pass.
Examples
Example plan: nine roles, five systems (two critical), Microsoft 365, AWS, offline backups not confirmed, multi-factor authentication for administrators only
A plan of about 38 pages: quick start, team and RACI, outside contacts, four severity levels, seven playbooks, six templates, seven tabletop scenarios, readiness actions for offline backups and multi-factor authentication, and appendices with the contact sheet and the forms.
Press Example plan on the page; the official reporting points follow the country you choose.
Country India, customer personal data, a team of three (incident lead, technical lead, executive) and an outside IT provider
Section 10 names the CERT-In Directions and the DPDP Rules with their official sources and lists CERT-In’s reporting email, phone and fax and the National Cyber Crime Reporting Portal; the readiness actions include the CERT-In point of contact, 180 days of logs kept in India and clock synchronisation with NIC or NPL time servers.
Common uses
- Writing a first incident response plan for a small or medium organisation.
- Replacing an out-of-date plan with one built on NIST SP 800-61 Rev. 3.
- Meeting a customer’s, insurer’s or auditor’s request for a documented incident response plan.
- Preparing tabletop exercises with scenarios that match your own playbooks.
- Giving the board and the team one agreed answer to “who decides what” before an incident.
What the plan contains
- 1–2. About this plan and a quick start: purpose, scope, approach, authority, and what anyone and the incident lead do in the first hour.
- 3–4. Team and outside help: roles, contacts and stand-ins, what each role does, who does what (RACI), who may take which decision, suppliers and official reporting points.
- 5–7. Severity, detection and response: four levels with criteria, response times and who is told; how incidents are reported and triaged; the incident log, escalation, containment and eradication.
- 8–11. Communication, evidence, reporting and recovery: channels and rules with six message templates; what evidence to keep and how; the reporting rules that may apply; recovery priorities from your systems and when an incident ends.
- 12–14. Playbooks, lessons and readiness: the playbooks you chose, the after-incident review, readiness actions, tabletop scenarios, reviews and versions.
- Appendices: a one-page contact sheet, an incident log, an incident report form, a chain of custody form, an after-action report and a glossary with the sources.
How your answers shape it
The plan is written about your organisation, not in general terms. Steps name the people who take them (“Call the incident lead (Sam Patel)”), the bank, insurer and providers you listed, and the email, identity and cloud services you use. Roles you do not have are left out and their tasks pass to the incident lead, and the RACI matrix is adjusted so that every activity still has one accountable role.
Gaps in the answers become readiness actions: no offline backups, untested restores, multi-factor authentication not for everyone, no central logs, no out-of-band channel. The kinds of data you hold, your country and a few questions (personal data of people in the EU or UK, essential services, HIPAA, SEC reporting) decide which reporting rules the plan names.
Built on NIST SP 800-61 Rev. 3
NIST’s incident response guidance organises the work by the functions of the Cybersecurity Framework 2.0: Detect (continuous monitoring and adverse event analysis), Respond (incident management, analysis, reporting and communication, mitigation) and Recover (recovery plan execution and communication), with lessons learned feeding improvement and Govern, Identify and Protect preparing for all of it. The plan follows that structure and its recommendations: an incident lead for each incident, incidents handled by priority rather than in order of arrival, risk factors for severity, protected incident records, evidence integrity, verified backups before restoring, and an after-action report.
The ransomware steps follow the response checklist of the #StopRansomware Guide by CISA, the NSA, the FBI and MS-ISAC; the payment-fraud steps follow the FBI’s advice on business email compromise.
Reporting rules and deadlines
Which authorities must be told, and how fast, depends on where you operate, whose data is involved, your sector and your contracts — and the rules change. So the plan names the rules your answers point to with their official sources — for example the directions of CERT-In and the DPDP Rules in India, the GDPR and the NIS2 Directive in the EU, the UK GDPR, HIPAA and SEC Form 8-K in the US, the Notifiable Data Breaches scheme in Australia and PIPEDA in Canada — and sends the deadlines to the Breach Notification Deadline Calculator, which works them out from the moment you became aware. Your legal adviser confirms which apply.
Limitations
- It is a template filled in from your answers, not legal advice: it does not decide which laws apply to you. Have it reviewed by a qualified legal adviser.
- The playbooks describe common incidents in general terms; adapt the technical steps to your own systems and tools.
- The plan is only as current as its contacts: check them every quarter.
- The plan is written in English. The PDF uses Noto Sans for Latin, Greek and Cyrillic text; names in scripts that need shaping (such as Devanagari or Arabic) show as “?” in the PDF and in the free preview’s pages — use the DOCX for them.
Privacy
Your answers — names, phone numbers, suppliers and systems — stay in this browser and are never uploaded. Keep these answers in this browser is off unless you switch it on, so a plan is not left on a shared computer; Save answers gives you a file to keep instead.
Frequently asked questions
What do I get without a pass?
Without a pass, Cyber Incident Response Plan Generator shows every page with your details, the first part of the wording readable and the rest hidden, marked “MySmartCoPilot preview · not for use”. Until you unlock it, the result can’t be downloaded, copied or printed. A Premium pass, a one-time payment that never renews, unlocks the full result. The pricing page lists the passes and their prices.
Why does the plan not list the reporting deadlines?
Because they depend on the facts of each incident — the country, the data, the sector, when you became aware — and on rules that change. The plan names the rules that may apply and their sources, and the Breach Notification Deadline Calculator works out the actual deadlines when an incident happens.
Does this make us compliant with a law or standard?
No tool can promise that. A documented, tested incident response plan is something many laws, standards and insurers expect, and this one follows NIST SP 800-61 Rev. 3, but whether it meets a particular duty is for your legal adviser or auditor to judge.
We are a small company. Do we need all these roles?
No. Untick the roles you do not have: the incident lead takes on their tasks and the executive their approvals, and the RACI matrix is adjusted. Many small companies run with an incident lead, a technical lead (often the IT provider) and the owner as the executive.
Can I edit the plan after downloading it?
Yes: the DOCX opens in Word and other word processors, and the Markdown in any editor or wiki. For the next review it is usually quicker to open your saved answers here, change them and download the plan again.
How often should we test the plan?
Choose how often in the plan details: every three months, twice a year or once a year. The plan includes a tabletop scenario for each playbook you chose, with updates to read out during the exercise and questions to discuss.
Where are my answers kept?
Only in this page while it is open, unless you switch on Keep these answers in this browser or save the answers file. Nothing is sent to a server.