HIVE80lab — Ops notes

Incident Response Plan Template for Small Teams (1–50 People)

Small teams don't need a 40-page incident response policy. They need one page with

three answers written down: who declares an incident, what gets shut down first, and

who talks. This template gives you that page with fill-in-the-blank sections, sized

for 1–50 people with no dedicated security staff.

Section 1 — Declaration

- a system needed for work is inaccessible,

- business or customer data is exposed, moving, or requested by someone you can't verify,

- a ransom note, extortion message, or payment-fraud attempt appears.

The declarer's only job is to say "this is now an incident" and start the page. They

don't need to be the most technical person in the room — they need authority and a

phone.

Section 2 — Containment order

| If you see… | Do this first | Who may pull the plug |

|---|---|---|

| Ransom note / files encrypting | Isolate machines, cut shared drives, protect backups | [name] |

| Fraud / impostor requests money | Freeze money movement; call the bank; keep systems up to investigate | [name] |

| Unknown breach symptoms | Snapshot logs, then follow the fraud or ransom path per evidence | [name] |

The opposite instincts are the trap: ransomware wants you offline fast, payment fraud

wants systems up and money frozen. Decide the order on a calm day, not during the

incident.

Section 3 — Communications

updates land, when the next update comes.

you'll write again. No speculation, no confirmation you can't support yet.

Severity levels (keep it to three)

in 15 minutes; escalate to [name] at 2 hours.

After the incident

One debrief page, same day or next: timeline, what worked, what to change in this

template. Update the template — it's the only artifact that gets better for free.

The full kit version of this template (with the statement drafts, severity table, and

a facilitator script for a 45-minute tabletop exercise) is in our Ops Starter Kit

link goes live when our payout rail unlocks.