Cyber Incident Response Plan: SME Template Guide
Why Every SME Needs an Incident Response Plan
When a cyber incident strikes, the difference between a manageable disruption and a business-ending catastrophe often comes down to one thing: preparation. Yet according to the Australian Cyber Security Centre (ACSC), fewer than 30% of Australian small businesses have a documented incident response plan (IRP).
The reality is stark. The average cost of a cyber attack on an Australian small business now exceeds $49,600 -- and much of that cost comes not from the attack itself, but from the chaotic, delayed, and uncoordinated response that follows. An IRP does not need to be a 50-page corporate document. For most SMEs, a clear, practical plan of 5-10 pages is more than sufficient.
The 6 Phases of Incident Response
The globally recognised incident response framework (based on NIST SP 800-61) consists of six phases. Here is how each phase applies to an Australian SME:
Phase 1: Preparation
This is everything you do before an incident occurs. It is the most important phase because it determines how effectively you can execute the remaining five.
- Asset inventory: Know what systems, data, and accounts your business relies on. You cannot protect what you do not know about.
- Contact list: Maintain an up-to-date list of key contacts (see template section below).
- Security controls: Implement baseline protections -- MFA, backups, endpoint protection, email filtering.
- Training: Ensure staff know how to recognise and report suspicious activity.
- Insurance: Have your cyber insurance policy details readily accessible, including the claims hotline number.
Phase 2: Identification
Detecting that an incident has occurred -- and understanding its scope -- is often the hardest part. Common indicators include:
- Unusual login activity or failed login attempts
- Unexpected system slowdowns or crashes
- Ransomware notes or encrypted files
- Reports from staff about phishing emails or suspicious messages
- Alerts from your antivirus, EDR, or email security tools
- Notification from a third party (customer, supplier, or the ACSC) that your data has been compromised
The key question at this stage: Is this a real incident, and how severe is it? Not every alert is an incident, but every alert deserves triage.
Phase 3: Containment
Once you have confirmed an incident, the priority is to stop it from spreading. Containment strategies depend on the type of incident:
- Compromised account: Reset passwords immediately, revoke active sessions, enable MFA if not already active.
- Malware/ransomware: Disconnect affected devices from the network (do NOT power them off -- this can destroy forensic evidence).
- Data breach: Identify the source of unauthorised access and close it. Preserve logs.
- BEC/invoice fraud: Contact your bank immediately to attempt to recall fraudulent transfers.
Critical: Do not wipe or rebuild systems at this stage. You need the evidence for investigation, insurance claims, and potentially law enforcement.
Phase 4: Eradication
With the threat contained, remove it entirely. This may involve:
- Removing malware from affected systems
- Closing exploited vulnerabilities (patching, configuration changes)
- Revoking compromised credentials across all systems
- Scanning other systems for indicators of compromise (IOCs)
Phase 5: Recovery
Restore normal business operations. This is where your backups prove their worth:
- Restore data from clean, verified backups
- Rebuild compromised systems from known-good images
- Monitor restored systems closely for signs of re-infection
- Gradually bring systems back online, starting with the most critical
- Communicate with affected customers, suppliers, and staff
Phase 6: Lessons Learned
Within two weeks of recovery, conduct a post-incident review. Document:
- What happened and when (detailed timeline)
- What worked well in the response
- What did not work or could be improved
- Specific actions to prevent recurrence
- Updates needed to the IRP itself
Incident response planning is fundamentally a governance discipline. In the IDIA framework, it sits squarely within the Assurance pillar -- the pillar responsible for governance, risk management, compliance, and continuous improvement. A well-maintained IRP is not just a document; it is evidence that your business takes a structured, repeatable approach to managing cyber risk. That same Assurance pillar also covers the lessons-learned reviews and plan updates that keep your IRP effective over time, rather than gathering dust in a drawer.
IRP Template: Essential Elements for SMEs
Your incident response plan should include these practical components:
1. Contact List
Maintain a printed and digital copy with:
- Internal: Business owner/CEO, IT manager or MSP, key staff members
- External: Cyber insurance provider (policy number + claims hotline), IT forensics firm, legal advisor, PR/communications advisor
- Government: ACSC (1300 CYBER1 / 1300 292 371), ReportCyber (cyber.gov.au), OAIC (for notifiable data breaches), relevant state police cybercrime unit
2. Escalation Procedures
Define clear severity levels and who needs to be notified at each level:
| Severity | Example | Notify | Timeframe |
|---|---|---|---|
| Low | Single phishing email received | IT / MSP | Same business day |
| Medium | Staff clicked phishing link, credentials potentially compromised | IT / MSP + Business owner | Within 2 hours |
| High | Confirmed data breach, ransomware, or financial loss | All contacts (internal + external) | Within 1 hour |
| Critical | Widespread ransomware, major customer data breach | All contacts + insurance + legal + ACSC | Immediately |
3. Communication Plan
Decide in advance:
- Who is the spokesperson? (Typically the business owner for SMEs)
- What channels will you use to communicate? (Email may be compromised -- have backup channels ready such as phone or SMS)
- Draft holding statements for customers, suppliers, and staff
- Social media monitoring and response protocol
4. Evidence Preservation Checklist
- Do NOT power off or wipe affected systems
- Screenshot error messages, ransom notes, and suspicious emails
- Export and preserve system logs, email logs, and access logs
- Record a timeline of events with timestamps
- Store evidence securely -- your insurer and law enforcement will need it
Legal Obligations: Mandatory Reporting
Australian businesses have specific legal obligations when a cyber incident involves personal data:
- Notifiable Data Breaches (NDB) scheme: If a breach is likely to result in serious harm to affected individuals, you must notify the OAIC and affected individuals as soon as practicable. Penalties for failure to comply can reach $50 million for serious or repeated breaches.
- Mandatory ransomware reporting: Under the Cyber Security Act 2024, businesses with annual turnover above $3 million must report ransomware payments to the Australian Signals Directorate within 72 hours. This is separate from the NDB scheme.
- Critical infrastructure: If your business falls under the Security of Critical Infrastructure Act 2018 (SOCI), you have additional 12-hour and 72-hour reporting obligations to the ACSC.
For a full breakdown of what to do in the first 24 hours after discovering a breach, see our guide on what to do when your business has been hacked.
Test Your Plan Before You Need It
An untested plan is barely better than no plan at all. At minimum:
- Annual tabletop exercise: Walk through a realistic scenario (e.g., ransomware attack on a Friday afternoon) with your key staff. Talk through each decision point.
- Quarterly contact list review: Verify phone numbers, email addresses, and policy details are current.
- Backup recovery test: Actually restore from backup at least once a year to verify it works.
Start With a Baseline Assessment
Building an effective incident response plan starts with understanding your current security posture. Platforms like How's My Cyber use the IDIA framework (Identity, Data, Infrastructure, Assurance) to organise every control into a clear operating model that works alongside any standard. Start with the free CYBER9 assessment to benchmark your business across nine critical domains -- including incident response readiness -- in under 10 minutes. Use the results to prioritise the areas that matter most for your IRP and build a plan that is practical, not theoretical.
How secure is your business?
Take the free CYBER9 assessment and get your security score in under 10 minutes. No credit card required.
Try CYBER9 Free