Most small teams spend nothing on incident response until the incident — then spend everything at once, in a panic, on the wrong things. The honest budget has five lines and one split: fund detection first, second copies second, on-call time third, practice fourth, transfer last. One bad afternoon funds the whole year. This page is the one-page card, the split, the spending ladder, and what not to buy first.
One row per line item. If a row has no owner and no review date, it is a wish, not a budget line:
| Line item | What it buys | Annual band | Owner | Reviewed |
|---|---|---|---|---|
| Detection — monitors on the things customers notice first | Uptime, DNS, SSL/cert expiry, backup-job success, form checks | $0–$600 | Named person | Quarterly |
| Second copies — the provider you fail over to | Second DNS provider, offsite backup storage, zone exports | $120–$900 | Named person | Quarterly |
| On-call time — the hours you are asking someone to give | Stipend, time-in-lieu, or a written rotation with comp rules | $0–$2,400 | Owner/ops lead | Quarterly |
| Practice — two tabletops + one restore drill per year | Half-days of team time, a facilitator, the drill log | $0–$1,000 | Named person | Quarterly |
| Transfer — insurance and legal readiness | Cyber insurance quote, notification-duty review, retainer review | $0–$1,500 | Owner | Annually |
Total band: roughly $120–$6,400 a year for a team under twenty. The total matters less than the split — teams that skip detection to buy response tools own alerts that never fire and retainers they can't trigger.
Divide whatever you decide to spend this way:
The split is the budget. A team that spends 80% on tools and 0% on practice has bought equipment for a fire brigade that has never met.
Don't benchmark against enterprise security budgets — benchmark against your own last incident. Set the annual IR budget at roughly what your last incident cost you (engineering hours × loaded rate, plus refunds, credits, churn, and the emergency invoice), then spend it before instead of after. If you have never measured the cost of an hour down, do that first — the uptime/downtime budget page has the arithmetic.
Every dollar of emergency spend during an incident is a budget line that was missing. That is the whole audit.
A twelve-person B2B SaaS (payments integrations, nine engineering staff) spent exactly $0 on IR and $2,100 one Saturday — an emergency contractor re-building DNS at 11pm while support answered tickets with a spreadsheet. A quarter later a payment-processor API outage silently broke checkout for six hours before anyone noticed; the churn conversation that followed was pricier than the contractor.
They wrote the one-page card: $3,400/year split 40/30/20/10 — $1,360 detection (uptime + DNS + cert + backup-job monitors), $1,020 on-call (a written rotation with time-in-lieu), $680 second copies (second DNS provider + offsite backups with quarterly restore checks), $340 practice (two half-day tabletops, one restore drill). Transfer deferred until renewal season. The next real incident — the same processor API flaking — was caught by the processor-health monitor in 90 seconds, first customer update out in 48 minutes, emergency spend $0. Same team, same vendors; the difference was $3,400 spent before instead of $2,100 spent after, plus the six silent hours they didn't have.
---
The Ops Starter Kit ($14) turns this card into a fillable plan with the severity matrix and runbooks behind it, Vol. 2 ($27) adds the DR plan and evidence log for the review after, and the Mega Bundle is all five kits at one checkout. Score your current readiness free in two minutes with the IR Readiness Score.