Cybersecurity

Incident Response Plan Template: A Practical Guide for Mid-Size Companies

Ethan Vereal, Chief Technology Officer. . Republished: . 11 min read

In short

An incident response plan is only useful if people can follow it under pressure. Built on the NIST phases, this covers preparation through to lessons learned, who holds which role, communication templates, an escalation matrix, and how to run a tabletop exercise that finds real gaps.

Every company will experience a security incident. The question is not whether, but when, and whether your team will respond with a tested plan or with chaos. A 2025 IBM study found that organizations with a tested incident response plan reduced breach costs by an average of $2.66 million compared to those without one. For mid-size companies, that difference can be existential.

Yet most mid-size companies either have no incident response plan, or have a dusty document written three years ago that no one has tested. This guide provides a practical, actionable framework based on NIST 800-61 (Computer Security Incident Handling Guide) that you can implement in your organization this quarter.

The 6 Phases of Incident Response

Phase 1: Preparation

Preparation is everything you do before an incident occurs. It is the phase that determines whether your response will be measured or frantic.

Phase 2: Detection and Analysis

The average time to detect a breach is still 194 days (IBM 2025). Reducing this window is the highest-leverage investment in incident response.

Phase 3: Containment

The goal is to stop the bleeding without destroying evidence or causing additional damage.

Phase 4: Eradication

Remove the threat actor's access and eliminate the root cause:

Phase 5: Recovery

Restore systems to normal operation with confidence that the threat is eliminated:

Phase 6: Post-Incident Review

This is the phase most organizations skip, and it is arguably the most valuable:

Roles and Responsibilities

Role Responsibility Activated At
Incident Commander Overall coordination, decision authority, resource allocation SEV-1 and SEV-2
Technical Lead Forensic investigation, containment execution, eradication All severities
Communications Lead Internal comms, customer notification, media relations SEV-1
Legal Counsel Regulatory notification requirements, privilege, liability SEV-1 and SEV-2
Executive Sponsor Business decisions, budget approval, board communication SEV-1

Communication Templates

Prepare these templates in advance so you are not drafting critical communications during a crisis:

Tabletop Exercise Guide

An untested plan is not a plan, it is a wish. Run tabletop exercises quarterly to validate your IR capability:

  1. Select a realistic scenario (ransomware is the most common first exercise)
  2. Gather the full IR team in a room (or video call) for 2-3 hours
  3. Present the scenario in stages, introducing new information every 20-30 minutes
  4. At each stage, ask: What do we do next? Who makes this decision? What information do we need?
  5. Document gaps discovered, missing contact information, unclear decision authority, untested tools, communication breakdowns
  6. Create action items and track them to completion before the next exercise
Tabletop truth: The first tabletop exercise always reveals significant gaps. That is the point. It is far better to discover that your backup restoration process has never been tested during a tabletop than during an active ransomware incident.

TechCloudPro's cybersecurity practice builds incident response programs for mid-size companies, from plan development and playbook creation to tabletop exercises and IR retainer management. We have responded to over 50 security incidents and know what works under pressure. Schedule an IR readiness assessment and we will evaluate your current plan, identify gaps, and build a program that protects your business when the inevitable incident occurs.

About the author

Ethan Vereal, Chief Technology Officer

Ethan leads the technology direction at TechCloudPro, with a background in cloud architecture, AI and machine learning systems, and enterprise security. He designs the private LLM deployment frameworks and oversees technical delivery on complex ERP programmes, drawing on earlier work in distributed systems, DevOps and cybersecurity.

Related reading

Talk to the team that wrote this

If any of this matches what you are dealing with, a short conversation will get you further than another article.

Book a consultationCybersecurity at TechCloudPro