Incident Response Plan Template for Small Teams (1–50 People)
Small teams don't need a 40-page incident response policy. They need one page with
three answers written down: who declares an incident, what gets shut down first, and
who talks. This template gives you that page with fill-in-the-blank sections, sized
for 1–50 people with no dedicated security staff.
Section 1 — Declaration
- Incident declarer: [name] · Backup: [name]
- What counts as an incident (behavioral, not adjectives):
- a system needed for work is inaccessible,
- business or customer data is exposed, moving, or requested by someone you can't verify,
- a ransom note, extortion message, or payment-fraud attempt appears.
The declarer's only job is to say "this is now an incident" and start the page. They
don't need to be the most technical person in the room — they need authority and a
phone.
Section 2 — Containment order
| If you see… | Do this first | Who may pull the plug |
|---|---|---|
| Ransom note / files encrypting | Isolate machines, cut shared drives, protect backups | [name] |
| Fraud / impostor requests money | Freeze money movement; call the bank; keep systems up to investigate | [name] |
| Unknown breach symptoms | Snapshot logs, then follow the fraud or ransom path per evidence | [name] |
The opposite instincts are the trap: ransomware wants you offline fast, payment fraud
wants systems up and money frozen. Decide the order on a calm day, not during the
incident.
Section 3 — Communications
- Spokesperson: [name] · Backup: [name]
- Staff first message: what's happening in one sentence, what changes now, where
updates land, when the next update comes.
- Customer first message: what you know, what you don't, what you're doing, when
you'll write again. No speculation, no confirmation you can't support yet.
Severity levels (keep it to three)
- S1 — burning: data or money actively leaving, or the business is down. Respond
in 15 minutes; escalate to [name] at 2 hours.
- S2 — limping: degraded, contained, or unconfirmed. Same-day fix; escalate at 3 days.
- S3 — ugly: no active harm. Log it, review weekly.
After the incident
One debrief page, same day or next: timeline, what worked, what to change in this
template. Update the template — it's the only artifact that gets better for free.
The full kit version of this template (with the statement drafts, severity table, and
a facilitator script for a 45-minute tabletop exercise) is in our Ops Starter Kit —
link goes live when our payout rail unlocks.