Developing your IR plan
Our incident management guidance will help you plan, build, develop and maintain an effective cyber incident response capability as our adversaries evolve.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
IR team/provider, IT, Senior Management, Legal, PR, HR, Insurance. Always consider the risk of people being unavailable - ideally include at least 2 contact methods and 2 or more people (or group) details.
This should cover the full incident life-cycle
This should be always available for urgent incident calls
When to engage legal support, HR, or follow careful evidence capture guidelines
This is a basic plan. Most of the topics and information discussed in this guidance should be documented in (or alongside) your IR plan.
In addition to an IR plan, you should also have inter-linked business continuity, disaster recovery and communications plans (covering internal and external communications).