Skip to content
בס״ד
Cyber Replay logo CYBER REPLAY
Incident Response 12 min read Published Aug 23, 2026 Updated Aug 23, 2026

Incident Response Plan for Cyber Attacks: Enterprise Playbook and Checklist

Build an enterprise incident response plan for cyber attacks using NIST, CISA, and SANS frameworks. Phase-by-phase playbook, checklist, SLAs, and FAQ.

By CyberReplay Security Team

TL;DR: A defensible incident response plan for cyber attacks has five non-negotiable parts - a signed and leadership-approved policy, named roles with explicit decision authority, phase-based procedures mapped to NIST SP 800-61 and SANS PICERL, a tested contact and escalation tree with out-of-band communications, and a tested cadence of tabletops twice a year plus a live exercise annually plus yearly re-approval. Without all five, your first real incident becomes an unrecoverable audit and disclosure problem.

Table of contents

What you will learn

  • How to build an incident response plan for cyber attacks that satisfies NIST, CISA, and SANS expectations in one document.
  • The exact phase-by-phase procedures, roles, SLAs, and contact tree that hold up under audit, insurer, and regulator scrutiny.
  • A readiness checklist and a minute-by-minute ransomware tabletop inject you can run this quarter.
  • The disclosure clocks (SEC, GDPR) that start at awareness, not at containment, and how to map them before an incident.
  • How to decide what to keep in-house versus what to hand to an MDR or external IR provider.

Quick answer

An enterprise incident response plan for cyber attacks is a written, leadership-approved document that defines roles, decision authority, phase-based procedures mapped to NIST SP 800-61 and SANS PICERL, a contact and escalation tree, out-of-band communications, SLAs for detection and recovery, and a tested exercise cadence. It is the single artifact an auditor, insurer, or regulator will ask for first, and the one most enterprises cannot produce on demand. If you are not sure whether your current plan would hold up, book a free security assessment to benchmark it against NIST and CISA expectations before an incident forces the question.

When this matters

This matters the moment an incident is declared in writing. Before that moment, the plan is a project. After that moment, the plan is your defense. IBM’s 2024 Cost of a Data Breach Report puts the global average breach cost at USD 4.88 million, and organizations with high security staffing shortages face costs USD 1.76 million higher than low-shortage peers. Verizon’s 2024 DBIR shows the median time to identify a breach remains around 50 days. A plan that cuts dwell time by even one hour compounds across detection, containment, disclosure, and recovery.

The cost of inaction is not theoretical. Without a written plan, you lose evidence, miss disclosure deadlines, breach insurance conditions, and turn a containable incident into a board-level crisis. With a tested plan, you preserve options.

Definitions

  • Incident response plan (IRP): A written, approved document that defines how an organization prepares for, detects, responds to, and recovers from cyber incidents.
  • NIST SP 800-61: The U.S. National Institute of Standards and Technology lifecycle framework: Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity.
  • SANS PICERL: The operational six-stage runbook: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned.
  • MTTD / MTTR: Mean time to detect and mean time to respond. The two metrics that most directly predict breach cost.
  • Materiality: The legal threshold that triggers SEC Item 1.05 disclosure for U.S. registrants, determined without unreasonable delay.
  • Out-of-band communications: A response channel that does not rely on the compromised corporate email or chat infrastructure.

The complete guide to an incident response plan for cyber attacks

A complete incident response plan for cyber attacks is not a long document. It is a short, signed, tested document. The goal is a plan that an incident manager can execute at 02:00 on a holiday without calling a meeting. Every section below maps to a NIST or SANS phase so you can defend each choice.

Phase 1: Preparation

Preparation is where most incidents are won or lost before they start. NIST SP 800-61 treats preparation as the foundation, and CISA’s IRP Basics requires the plan to be written and leadership-approved.

Required artifacts:

  • A signed policy with senior leadership approval and a named plan owner.
  • A role matrix with explicit decision authority: incident manager, exec sponsor, legal counsel, communications lead, IR lead.
  • A contact and escalation tree with primary and alternate contacts, tested in the last 90 days.
  • An out-of-band communications channel pre-staged and documented.
  • An external IR retainer signed and reachable after hours.
  • Top-scenario runbooks for your six most likely incidents (ransomware, business email compromise, cloud account takeover, data exfiltration, insider misuse, third-party breach).
  • Tooling baseline: EDR, SIEM, identity logs, and cloud audit logs centralized and retained for at least 90 days.
Role: Incident Manager
Decision authority: declare incident, isolate hosts, disable accounts, engage external IR
Escalates to: Exec Sponsor (sev-1), CISO (sev-2+)
Does NOT decide: public disclosure, regulatory filing, ransom payment

Phase 2: Identification and analysis

Identification is where false positives and missed detections both cost you. Require a second independent source before declaring an incident, and a second before closing one.

Required procedures:

  • A written declaration criteria with severity tiers (sev-1 through sev-4) and examples for each.
  • A two-source confirmation rule for declaration and for closure.
  • An incident channel opened in writing at declaration, with a named scribe.
  • MTTD tracked per scenario and trending down quarter over quarter.
  • A blast-radius assessment template completed within the first hour.

If your SIEM and EDR both fire on the same host within the same window, that is your second source. If only one fires, hunt before you declare.

Phase 3: Containment

Containment is the phase where speed and evidence preservation collide. The rule is simple: preserve first, contain second, eradicate third.

Required procedures:

  • Network isolation via EDR or segmentation, documented and reversible.
  • Account disablement for compromised credentials, with a re-enablement validation step.
  • Memory and disk imaging before any rebuild, with chain-of-custody logged.
  • C2 domain and IP blocking at DNS, proxy, and firewall, with a rollback procedure.
  • Short-term and long-term containment options documented per scenario.

Rebuilding before imaging is the most expensive mistake in this phase. It destroys the evidence you need for disclosure, insurance, and law enforcement.

Phase 4: Eradication

Eradication removes the root cause so the incident does not recur. CISA KEV data shows about 55 days to remediate half of critical vulnerabilities post-patch, which is why recurrence is common.

Required procedures:

  • Root-cause hypothesis documented and validated before eradication begins.
  • Patching and rebuild from known-good images, not in-place cleanup.
  • Credential rotation for every account in the blast radius, including service accounts.
  • Persistence mechanism sweep across the blast radius, not just the initially affected host.
  • Eradication sign-off by the IR lead before recovery starts.

Phase 5: Recovery

Recovery is where untested backups become a second incident. Define recovery SLAs before you need them, and validate reconnection under monitoring.

Required procedures:

  • Clean, offline, and tested backups for all tier-1 systems.
  • Recovery point objectives and recovery time objectives signed off by system owners.
  • Phased reconnection with monitoring windows between each phase.
  • A reconnection validation procedure that confirms integrity before traffic returns.
  • MTTR tracked per scenario and trending down quarter over quarter.

Phase 6: Post-incident activity

Post-incident activity is where the plan improves. Without it, you will have the same incident next quarter.

Required procedures:

  • An after-action review completed for every severity-1 incident, within 10 business days.
  • A lessons-learned register with owners and due dates for every action item.
  • Plan updates triggered by every after-action review and by major infrastructure or leadership changes.
  • Metrics reported to the board: MTTD, MTTR, incident count by severity, and open action items.
  • A yearly plan re-approval with leadership sign-off.

Readiness checklist

Use this as a quarterly self-assessment. If you cannot check a box, it is a gap. For a scored, independent review of these controls, schedule your assessment and we will map each unchecked item to a prioritized 30-day remediation plan.

Preparation

  • Written, leadership-approved plan with a named owner.
  • Role matrix with explicit decision authority.
  • Contact tree tested in the last 90 days, including out-of-band channel.
  • External IR retainer active and reachable after hours.
  • Top six scenario runbooks documented.

Detection

  • EDR, SIEM, identity, and cloud logs centralized and retained for at least 90 days.
  • Use-case coverage for the top six scenarios with tested alerting.
  • MTTD and MTTR tracked and trending down quarter over quarter.

Response

  • Contact tree tested in the last 90 days, including out-of-band channel.
  • External IR retainer active and reachable after hours.
  • Evidence preservation procedure documented and rehearsed.

Recovery

  • Clean, offline, and tested backups for all tier-1 systems.
  • Recovery SLAs defined and signed off by system owners.
  • Reconnection validation procedure documented.

Improvement

  • After-action review completed for every severity-1 incident.
  • Tabletop run at least twice in the last 12 months.
  • Live exercise run in the last 12 months.

Minute-by-minute ransomware scenario

Use this as a tabletop inject. Times are elapsed from first detection.

T+0:00  EDR alerts on mass file encryption on a file server.
T+0:05  SOC confirms via second source (SIEM + EDR correlation).
T+0:10  Incident declared in writing; incident channel opened.
T+0:15  Incident manager paged; exec sponsor and outside counsel notified.
T+0:20  Affected host network-isolated via EDR; compromised service account disabled.
T+0:30  Memory and disk images captured; C2 domain blocked at DNS and proxy.
T+1:00  Blast-radius assessment complete; additional hosts isolated.
T+2:00  External IR firm on call; forensic preservation in progress.
T+4:00  Initial containment confirmed; eradication plan drafted.
T+24:00  Eradication across blast radius; rebuild from known-good images.
T+72:00  Recovery validation; phased reconnection under monitoring.
T+96:00  Materiality assessment with counsel; SEC 8-K clock evaluated.

The goal is not perfection. The goal is a documented, defensible sequence that an auditor, insurer, or regulator can follow.

Common mistakes

  • No written plan. A tribal-knowledge response fails under stress and fails audits. CISA’s IRP Basics is explicit: the plan must be written and leadership-approved.
  • Rebuilding before imaging. Destroying evidence breaks disclosure, insurance, and law enforcement timelines. Always preserve first.
  • Single-source detection. One alert source is a false-positive risk. Require a second independent source before declaring, and a second before closing.
  • No out-of-band channel. If attackers own your email and chat, your response is blind. Pre-stage a separate channel and a printed contact list.
  • Untested plan. A plan that has never been tabletopped will fail in the first hour. Test at least twice a year.
  • Slow patching. CISA KEV data shows about 55 days to remediate half of critical vulnerabilities post-patch. Slow eradication invites recurrence.
  • Ignoring disclosure clocks. The SEC four-business-day rule and GDPR 72-hour rule start at awareness, not at containment. Map deadlines before the incident.

FAQ

How do we write an incident response plan for cyber attacks from scratch?

Start with CISA’s Incident Response Plan Basics as a template skeleton, then layer NIST SP 800-61 lifecycle phases over it. Get senior leadership sign-off, name roles and decision authority, write phase-based procedures for top scenarios, build the contact tree, define SLAs, establish out-of-band communications, sign an external IR retainer, and schedule the first tabletop within 90 days.

What is the difference between NIST SP 800-61 and SANS PICERL?

NIST SP 800-61 groups the lifecycle into four phases: Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity. SANS PICERL separates the same work into six stages: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned. Use NIST as the governance framework and SANS as the operational runbook step list.

How fast must we disclose a material cyber incident?

For U.S. SEC registrants, an Item 1.05 Form 8-K is generally due within four business days of determining an incident is material, with materiality determined without unreasonable delay. EU GDPR requires personal data breach notification to the supervisory authority within 72 hours of awareness. Map every applicable deadline into your plan before the incident, and assign a disclosure owner.

Should we run incident response in-house or use an MDR provider?

Most enterprises should do both. Keep incident command and decision authority in-house, and use an MDR or external IR provider for 24/7 detection coverage, surge forensic capacity, and specialized tooling. IBM’s 2024 data shows organizations with high security staffing shortages face breach costs USD 1.76 million higher than low-shortage peers, which is the clearest argument for supplementing internal teams rather than relying on hiring alone.

How often should we test the plan?

Run a tabletop at least twice a year and a full live exercise annually. Re-approve the written plan at least once a year, and after any major change to infrastructure, leadership, or regulatory obligations. Test after every severity-1 incident using the after-action review, because real incidents are the highest-fidelity test you will ever get.

Get your free security assessment

If this incident response plan for cyber attacks is a live priority for your team, schedule your assessment for a focused review. We will map the biggest gaps, assign the first actions, and turn the article into a practical 30-day plan.

Next step: get an independent readiness assessment

If you have read this far, the highest-leverage next step is an independent readiness assessment that scores your current plan against NIST SP 800-61 and CISA guidance, identifies the gaps that would cost you the most in the first hour of a real incident, and gives you a prioritized remediation roadmap. A qualified MSSP or MDR partner can run this in days, not months, and the findings usually pay for themselves in the first avoided hour of dwell time.

If you want a structured starting point, CyberReplay’s managed security services cover readiness assessments, MDR, and incident response retainers, and the help center walks through what to do if you are already in an active incident. If you are mid-incident right now, use the incident help path before you do anything else.

References