The 3 Questions Your IR Plan Must Answer in the First 30 Minutes
Most incident response plans are written for organisations that already have a
security team. If you're a founder, an office manager, or the one IT person for
1–50 people, yours probably isn't. And that's fine — a small team doesn't need a
40-page plan. It needs to answer three questions fast, in order, when something
goes wrong.
Question 1: What is actually happening?
Before you touch anything, write down what you observed, when, and on which
machine. One incident log file, opened in the first five minutes. This isn't
bureaucracy — it's the record you'll need for the vendor call, the insurance
claim, and the post-mortem. Guessing "it's probably ransomware" and acting on
the guess is how encrypted backups get destroyed.
Question 2: What do we disconnect first?
Containment beats eradication for speed. Your plan should name, in advance:
which machines get pulled off the network, who is authorised to pull them, and
the one shared drive or cloud folder to freeze first. If the answer lives in
someone's head, it isn't a plan.
Question 3: Who says what, to whom?
The first 30 minutes are also a communications problem: staff need a one-line
"what to do right now" message, and anything customer-facing waits until you
have facts. Your plan should hold the message templates already written —
because you will not write well under pressure.
---
That's the whole spine: log it, cut it, say it. Everything else — severity
levels, playbooks, the tabletop exercise that makes it stick — is structure
around those three answers. The templates for all of it (IR plan, severity
matrix, comms templates, containment checklists) are in the Ops Starter Kit.
*This is general guidance, not legal or regulatory advice. Adapt every template
to your own environment.*