How to Create an Incident Response Plan for Your Business
By Daniel Agyemang Prempeh, Founder, DefendVistaLast reviewed:
What an SME incident response plan must contain, how to write it in two weeks, and how to make sure it actually works at 03:00 when the TMS is encrypted.
An incident response plan is the difference between a haulier that loses half a day and one that loses a fortnight. Most SMEs do not have one. Most that do have a plan written by someone who has since left, never tested, and dependent on the very email system that the ransomware just encrypted. This guide shows what a working plan looks like and how to build one that survives first contact with a real incident.
What an incident response plan must contain
Six things, in this order: named roles and decision authorities, contact lists kept off network, communication templates for customers and the ICO, technical playbooks for the two or three scenarios most likely to hit you, out of band communications so the plan still works when email is down, and an evidence preservation procedure so the forensic investigation is not compromised by well meaning staff wiping machines. Anything else is supporting material.
Pick the incidents that actually matter
Do not try to write a playbook for every possible attack. Pick the two or three scenarios that would hurt you most. For a haulier or 3PL that is almost always ransomware, business email compromise (fraudulent payment redirection), and serious data loss involving driver or customer personal data. Write a focused playbook for each, then leave the rest as a general response template. A 30 page plan that covers the three scenarios you will actually face beats a 120 page plan that covers none of them well.
Roles and authorities, decided in advance
Decide now who can declare an incident (usually duty manager and above), who speaks to customers, who speaks to the ICO, who authorises emergency spend up to £25,000 without sign off, who can shut down the warehouse if the WMS is suspect, and who calls the insurer at 02:00. The middle of a ransomware incident is the wrong time to discover the answer is ambiguous. We worked a 2024 incident where the response stalled for six hours because no one was willing to authorise the £18,000 forensic retainer without the MD, who was on a flight.
Out of band communications
If Microsoft 365 is down, what do you use? A WhatsApp group on personal phones is the minimum (set it up now, not during the incident). For larger operators a dedicated Signal channel, a printed crisis comms tree, and a pre established conference bridge number kept outside Teams are all standard. Print the senior team contact list and keep a copy in the depot safe and the MD's car. We have seen incidents where the IR team could not even reach the IT manager because the only contact number was in the encrypted Active Directory.
A worked playbook: ransomware in dispatch
Hour zero: duty manager declares incident, isolates affected systems at the switch, does not power them off, opens the written response log. Hour one: response team convened on out of band channel, insurer notified, IR partner activated. Hours two to six: scope assessed, customer holding statement issued, paper run sheets distributed for the next 24 hours of work. Hours six to twelve: recovery path decided based on backup integrity, ICO notification prepared if personal data is in scope. Hours twelve onward: controlled restore into a hardened environment, never back into the compromised one. Every action timestamped. Every decision logged.
Testing the plan
A plan that has never been tested will fail. Run at least one realistic tabletop exercise every 12 months with the actual leadership team in the room, no laptops. Use a scenario from a real UK haulier incident (KNP, Bardin Hill, or the 2024 Knights of Old precursor case all work well). Debrief honestly. Update the plan with what you find. The plan gets sharper with every cycle, and the team gets calmer.
Common gaps we find in SME plans
Contact list lives on the SharePoint that just got encrypted. Insurer policy number is unknown to the people who would call at 02:00. No agreed protocol for paying the IR retainer when finance systems are offline. The named DPO left the business two years ago. The plan references systems that were retired in 2022. Walk through your plan once a quarter and fix what is stale.
Frequently asked questions
How long should the plan be?+
Long enough to be useful, short enough to be read at 02:00. Most SME plans land between 15 and 40 pages, with the operational playbooks kept as separate two to four page documents that can be pulled out quickly.
Who should own the plan?+
A named individual on the leadership team, usually the COO, FD or an operations director. IT can maintain the technical playbooks, but the plan itself needs business ownership because most of the hard decisions in a real incident are business decisions, not technical ones.
How often should we revisit it?+
At least annually, and any time you change a major system (new TMS, new ERP, office move), bring in or lose a senior leader, or change cyber insurer.
Do we need an external IR retainer?+
Strongly recommended above 50 staff or for operators with regulated data. A retainer guarantees response time and pre agreed rates. Without one, you are negotiating commercial terms at the worst possible moment.
Next step
Want to talk this through?
Book a free 30 minute consultation. No sales pitch, just clear answers.
Book free consultation