Incident Response Budget Template for Small Teams

Most small teams spend nothing on incident response until the incident — then spend everything at once, in a panic, on the wrong things. The honest budget has five lines and one split: fund detection first, second copies second, on-call time third, practice fourth, transfer last. One bad afternoon funds the whole year. This page is the one-page card, the split, the spending ladder, and what not to buy first.

1. The one-page IR budget card

One row per line item. If a row has no owner and no review date, it is a wish, not a budget line:

Line itemWhat it buysAnnual bandOwnerReviewed
Detection — monitors on the things customers notice firstUptime, DNS, SSL/cert expiry, backup-job success, form checks$0–$600Named personQuarterly
Second copies — the provider you fail over toSecond DNS provider, offsite backup storage, zone exports$120–$900Named personQuarterly
On-call time — the hours you are asking someone to giveStipend, time-in-lieu, or a written rotation with comp rules$0–$2,400Owner/ops leadQuarterly
Practice — two tabletops + one restore drill per yearHalf-days of team time, a facilitator, the drill log$0–$1,000Named personQuarterly
Transfer — insurance and legal readinessCyber insurance quote, notification-duty review, retainer review$0–$1,500OwnerAnnually

Total band: roughly $120–$6,400 a year for a team under twenty. The total matters less than the split — teams that skip detection to buy response tools own alerts that never fire and retainers they can't trigger.

2. The 40/30/20/10 split

Divide whatever you decide to spend this way:

The split is the budget. A team that spends 80% on tools and 0% on practice has bought equipment for a fire brigade that has never met.

3. The funding rule: one bad afternoon pays for the year

Don't benchmark against enterprise security budgets — benchmark against your own last incident. Set the annual IR budget at roughly what your last incident cost you (engineering hours × loaded rate, plus refunds, credits, churn, and the emergency invoice), then spend it before instead of after. If you have never measured the cost of an hour down, do that first — the uptime/downtime budget page has the arithmetic.

4. The spending ladder (in order, no skipping)

  1. Detection first ($0–$600). Monitors on the five signals customers hit first. Cheapest line, biggest return, and everything downstream depends on it.
  2. Second copies second ($120–$900). A tested backup and a pre-configured second DNS/backup provider. Untested backups are a wish; the restore-test template makes them evidence.
  3. Practice third (time, not money). Two tabletops and one restore drill a year. This is where the severity labels and runbooks get exercised before they're needed for real.
  4. Tooling last. Buy automation only after two drills found the same gap. A tool bought to fix a gap you haven't drilled is a guess with an invoice.
  5. Transfer when revenue justifies it. Cyber insurance and legal review after lines 1–3 exist — insurers ask what you already do, and "nothing" is the expensive answer.

5. What NOT to buy first

Every dollar of emergency spend during an incident is a budget line that was missing. That is the whole audit.

6. Three metrics

Worked example: twelve-person SaaS, $0 budget to $3,400 and calm

A twelve-person B2B SaaS (payments integrations, nine engineering staff) spent exactly $0 on IR and $2,100 one Saturday — an emergency contractor re-building DNS at 11pm while support answered tickets with a spreadsheet. A quarter later a payment-processor API outage silently broke checkout for six hours before anyone noticed; the churn conversation that followed was pricier than the contractor.

They wrote the one-page card: $3,400/year split 40/30/20/10 — $1,360 detection (uptime + DNS + cert + backup-job monitors), $1,020 on-call (a written rotation with time-in-lieu), $680 second copies (second DNS provider + offsite backups with quarterly restore checks), $340 practice (two half-day tabletops, one restore drill). Transfer deferred until renewal season. The next real incident — the same processor API flaking — was caught by the processor-health monitor in 90 seconds, first customer update out in 48 minutes, emergency spend $0. Same team, same vendors; the difference was $3,400 spent before instead of $2,100 spent after, plus the six silent hours they didn't have.

Takeaways

---

The Ops Starter Kit ($14) turns this card into a fillable plan with the severity matrix and runbooks behind it, Vol. 2 ($27) adds the DR plan and evidence log for the review after, and the Mega Bundle is all five kits at one checkout. Score your current readiness free in two minutes with the IR Readiness Score.