How to Build a Cyber Incident Response Plan | Microbyte

How to Build a Cyber Incident Response Plan

IT security solutions

A cyber incident response plan gives a United Kingdom (UK) business a written, tested way to contain damage, protect customers, and keep trading when systems are attacked. It should name the people, decisions, evidence, timings, suppliers, and recovery steps before the pressure arrives.

Microbyte has been operating since 1992, holds Cyber Essentials Plus, and runs 24/7/365 support through our own engineers. This guide explains how to build the plan, what evidence to include, how to test it, and when to bring in outside help.

Why Your Response Plan Has to Be Built Before the Breach

A good response plan is a business continuity tool, not an IT document. It protects trading, cash flow, customer trust, and regulatory deadlines by turning a stressful event into a controlled response with named owners, agreed steps, and clear communication.

The Cyber Security Breaches Survey 2025 (gov.uk) found that 43% of UK businesses identified a breach or attack in the previous 12 months. While this overall percentage represents a slight decrease from 50% in 2024, driven mainly by better phishing identification among micro-businesses, the picture changes as organisations get bigger.

Specifically, 67% of medium-sized businesses and 74% of large businesses identified breaches in 2025. That matters for smaller firms too, because many work inside larger supply chains.

The Cost is Not Just the First Invoice

The first visible cost of an incident rarely shows the whole picture. It doesn’t show the lost hours, delayed orders, staff disruption, legal questions, or customer calls that follow a serious event.

Ransomware attacks doubled in prevalence from less than 0.5% of businesses in 2024 to 1% in 2025, affecting an estimated 19,000 UK organisations. A response plan gives your team permission to act quickly, rather than waiting for someone senior to decide what counts as serious.

Poor planning turns technical trouble into business interruption, so the next job is to define what your plan must cover.

What A Good Incident Response Plan Must Cover

A Cyber Security Incident Response Plan should cover eight basics: scope, roles, contact details, severity levels, evidence handling, containment steps, recovery priorities, and lessons learned. If any one of those is missing, your team may lose time when every hour matters.

Some online guides focus on insurance forms. Others focus on technical tooling. Your business needs both the business decision trail and the technical response process, because attackers don’t wait while teams argue over ownership.

The National Cyber Security Centre Annual Review 2025 (ncsc.gov.uk) reported handling 204 nationally significant cyber incidents between September 2024 and August 2025. This represents a staggering 130% increase from the 89 incidents recorded in the previous year.

The Eight Elements to Write Down

A practical plan should include these elements in plain English:

  • Scope: Which systems, sites, cloud services, and suppliers are covered.
  • Response team: The named people who make decisions during an event.
  • Contact list: Staff, IT support, legal advice, insurers, banks, and law enforcement.
  • Severity levels: What counts as low, medium, high, or critical.
  • Evidence rules: What logs, screenshots, emails, and incident data must be kept.
  • Containment steps: How to isolate accounts, devices, networks, and cloud access.
  • Recovery order: Which systems come back first, based on business need.
  • Review process: How you record lessons and fix weak points after the event.

Define Technical Terms Before Stress Hits

A Computer Security Incident Response Team (CSIRT) is the group that coordinates the response. In a small and medium-sized enterprise (SME), that may include the managing director, operations lead, finance lead, IT provider, and a legal contact.

Containment means stopping the damage spreading. That may mean disabling a user account, removing a laptop from the network, blocking a malicious email rule, or temporarily switching off remote access.

Once the essentials are clear, you can turn the plan from a document into a working response.

How to Build the Plan Without Turning IT Into IT Homework

Start with the business impact, then work back to the technology. The right plan tells you which services matter most, who can approve disruption, how customers will be told, and which systems must be recovered first.

If you start with tools, the plan gets too technical. Start with a Monday morning scenario instead: payroll is due, email is locked, and a supplier says your account has sent a strange payment request.

For businesses without in-house security staff, our cyber security for small business service helps turn that scenario into a written plan, tested actions, and ongoing prevention.

Step 1: Run A Risk Assessment

A risk assessment asks three plain questions: what could go wrong, how likely is it, and what damage would it cause. It should cover phishing, stolen passwords, ransomware, supplier failure, lost devices, and cloud account compromise.

Use a simple scoring table before you write procedures:

Step 2: Build Your Response Team

Your response team should be small enough to move fast. Name deputies too, because the person you need may be on holiday.

For most SMEs, the team includes an owner or director, office manager, finance lead, IT provider, cyber insurer contact, and external legal contact. If you rely on a managed service provider (MSP), make sure their role is written down rather than assumed.

Step 3: Write Playbooks for the Events You Fear Most

A playbook is a short set of actions for one type of event. It stops people inventing the response while the clock is ticking.

Write separate playbooks for ransomware, lost device, business email compromise, supplier breach, and suspected insider access. Each playbook should say who acts, what they check, what they isolate, what they save, and who gets told.

Step 4: Analyse Data Before You Reopen Systems

Don’t rush to switch everything back on. Logs, alerts, email rules, login records, and backup timestamps can show how far the attacker got.

Security Information and Event Management (SIEM) means collecting security logs in one place so they can be reviewed. Endpoint Detection and Response (EDR) means monitoring laptops and servers for suspicious activity, while Managed Detection and Response (MDR) means a security team reviews alerts and responds around the clock.

A plan works best when prevention and response sit together, which is why Microbyte frames security around Stamp Out Support: fewer emergencies, less firefighting, and clearer control when something does happen.

Case Studies: M&S and Co-op Show Why Practice Matters

The spring 2025 retail attacks showed the difference between a plan on paper and a practised response. In the spring of 2025, a highly sophisticated threat actor group known as Scattered Spider, deploying the DragonForce Ransomware-as-a-Service (RaaS) payload, targeted several major UK retailers, including Marks & Spencer (M&S), the Co-operative Group (Co-op), and Harrods.

The estimated combined cost of the spring 2025 ransomware campaign targeting major UK retailers reached between £270 million and £440 million, according to a Cyber Monitoring Centre estimate (thehackernews.com). The point for SMEs is not that your firm looks like a national retailer. It is that identity checks, supplier access, and helpdesk scripts can decide how far an attack spreads.

The Helpdesk is Part of Security

Reports on the 2025 incidents describe attackers using social engineering, including impersonating IT staff and pushing for password resets. Multi-Factor Authentication (MFA) helps, but people can still be pressured into bypassing normal checks.

Your communications plan should include helpdesk rules. For example, no password reset should happen without an agreed identity check, and no urgent executive request should skip verification.

Third-Party Access Changes the Risk

The Cyber Security Breaches Survey 2025 highlighted a critical weakness: only 14% of businesses and 9% of charities actively reviewed the cybersecurity risks posed by their immediate suppliers, while just 7% of businesses reviewed risks in their wider supply chain. This gap in third-party risk management is precisely what threat actors are exploiting, using the one-to-many access privileges held by MSPs to compromise multiple downstream targets at once.

MSPs must not only construct response plans for their own infrastructures but must also architect, implement, and govern these frameworks on behalf of their clients. That supplier risk makes regulation the next pressure point, not a separate issue.

The 24/72-Hour Compliance Pressure for UK Businesses

UK cyber regulation is moving toward faster reporting, wider scope, and tougher penalties. For regulated firms and suppliers, a response plan now needs evidence, timings, and customer notification steps that can stand up to external review.

Introduced to the UK Parliament for its first reading on 12 November 2025, the Cyber Security and Resilience Bill (CS&R Bill) represents the most significant reform to the UK’s cyber security framework since the Network and Information Systems Regulations 2018. The bill is expected to receive Royal Assent in 2026 and aims to modernise outdated laws, align with elements of the European Union’s Network and Information Security Directive 2 (NIS2), and protect the digital economy.

What the Bill Changes for MSPs

Historically, the Network and Information Systems Regulations 2018 applied mainly to operators of essential services, such as healthcare, water, and transport, as well as certain relevant digital service providers. The Cyber Security and Resilience Bill collection (gov.uk) expands the discussion to IT managed service providers, data centres, and critical suppliers.

The UK government estimates that between 900 and 1,100 MSPs will be captured by the bill, turning them into regulated entities called Relevant Managed Service Providers (RMSPs). That changes the standard expected from providers who manage access, backups, monitoring, and recovery for client networks.

Why Penalties Change the Design

Under the previous regime, organisations had 72 hours to report an incident. The new legislation mandates an initial early warning notification to regulators and the National Cyber Security Centre within 24 hours of becoming aware of a significant cyber incident, followed by a full report within 72 hours.

Regulators will be empowered to levy turnover-based penalties, with proposed fines reaching up to £100,000 per day for continuing non-compliance, or up to 10% of annual daily turnover. The fine structure mirrors parts of the Telecommunications (Security) Act 2021, and the bill grants powers for proactive directions and investigations.

For London firms in legal, financial services, property, and professional services, our cyber security London team can help align response planning with practical business operations. Once the legal clock starts, the value of a tested plan becomes obvious.

How to Test, Review, and Improve Your Response Plan

A plan that has never been tested is still a guess. Testing shows whether people know their roles, whether contact details work, whether backups restore, and whether decision-makers can act quickly under pressure.

The SANS Institute incident response definition (sans.org) describes incident response as handling the aftermath of a security breach or attack. Its widely used six-step model is often described as Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned (PICERL).

Run Exercises, Not Just Reviews

A tabletop exercise is a meeting where your team walks through a realistic incident. No systems are switched off, but every decision is tested.

The IASME cyber incident exercise guidance (iasme.co.uk) recommends using exercises to test how people respond, not just whether a document exists. Good scenarios include ransomware, business email compromise, supplier breach, lost laptop, and finance fraud.

Update for Modern Threats

The CREST Cybersecurity Incident Management Guide 2025 (crest-approved.org) is relevant for UK business-to-business firms because it covers newer vectors, including artificial intelligence (AI) manipulation, deepfake-enabled social engineering, and supply chain compromises. That means your plan should cover voice verification, payment approval checks, and supplier access review.

Test at least once a year, and after major changes such as a Microsoft 365 migration, a new finance system, or a change of IT provider. Practice turns the plan from paperwork into muscle memory, but some firms need outside support to make that happen properly.

When to Bring in Cyber Security Support

Bring in support when your business cannot confidently detect, contain, recover, and report an incident with its own people. That point arrives sooner than most owners expect, especially when Microsoft 365, remote working, suppliers, and cyber insurance conditions all overlap.

Microbyte’s role is to make the response calm and practical. We support SMEs from our Peterborough head office, Bermondsey Street in London, Woking, Lincoln, Dubai Business Bay, Portland, Los Angeles, and our Philippines-based 24/7 Security Operations Centre (SOC) personnel.

Prevention and Response Belong Together

Cyber security consultants should not just hand over a template. Our cyber security consultants work focuses on practical controls, tested recovery, supplier review, and plain communication.

As a Microsoft Gold Partner and Direct Cloud Solutions Provider (CSP), we can license, configure, and support Microsoft 365 and Azure directly. We also hold Cyber Essentials Plus ourselves, which means we follow the same external audit discipline that we help clients prepare for.

What We Would Check First

Where risk is higher, we start with the basics that reduce the chance of an incident and speed up response. That includes password policy, Multi-Factor Authentication (MFA), backup recovery, endpoint monitoring, supplier access, user permissions, and insurance reporting requirements.

For firms in London Bridge, the City of London, Canary Wharf, Stamford, Cambridge, Bedford, Lincolnshire, the Midlands, Woking, Dubai International Financial Centre (DIFC), and Abu Dhabi, the plan also needs to reflect local trading needs. The document has to match how your business works, or people won’t use it when pressure hits.

FAQs About Incident Response Planning

Use these quick answers to check whether your current plan covers the basics, the operating model, and the terminology a board or insurer may ask about.

How to Create a Cybersecurity Incident Response Plan?

Create a cybersecurity incident response plan by listing your most likely incidents, naming the response team, setting severity levels, and writing playbooks for ransomware, lost devices, supplier compromise, and email fraud. Test the plan with a tabletop exercise, update contact details, and link it to backups, insurance, legal reporting, and customer communication.

What Are the 8 Basic Elements of an Incident Response Plan?

The eight basic elements are scope, roles, contact list, severity levels, evidence handling, containment steps, recovery priorities, and post-incident review. Together, they tell people what is covered, who decides, who gets contacted, how damage is contained, which systems return first, and how weaknesses are fixed afterwards.

What Are the 5 C’s of Incident Management?

The five C’s of incident management are command, control, coordination, communication, and continuity. Command means clear ownership, control means disciplined decisions, coordination keeps teams aligned, communication keeps staff and customers informed, and continuity keeps the business trading while systems are checked and restored.

What Are the 7 Phases of an Incident Response Plan?

The seven phases are preparation, detection, analysis, containment, eradication, recovery, and lessons learned. Some frameworks combine detection and analysis into identification, creating a six-step model. For SMEs, the seven-phase version is useful because it makes early warning signs and decision points clearer.

How Often Should You Test the Plan?

Test the plan at least once a year, and after major changes such as a new IT provider, cloud migration, office move, or cyber insurance renewal. Run a tabletop exercise first, then test backups and access controls. Update the document immediately when names, phone numbers, suppliers, or recovery priorities change.

If your plan is still a blank document, Microbyte can help you turn it into a tested business process. Talk to our Peterborough or Bermondsey Street team and we’ll review what’s working, what isn’t, and what it would cost to fix the gaps.

Similar blogs

Header image for Cloud Service page - Servers

The Real Cost of a Data Breach for UK SMEs (2026 Statistics)

In May 2026, the real cost of a data breach for United Kingdom (UK) small and medium-sized enterprises (SMEs) is still not one neat number. The latest official United Kingdom government survey shows median perceived costs of £0 for many businesses, but the highest-cost cases still rise sharply, whil

Avatar photo

Close up of Desktop and Servers - Banner image

What is DMARC, DKIM and SPF and Does Your Business Have Them?

Domain-based Message Authentication, Reporting, and Conformance (DMARC), DomainKeys Identified Mail (DKIM), and Sender Policy Framework (SPF) are the three checks that help prove your business emails are legitimate. They protect your domain from impersonation, reduce failed deliveries, and stop crim

Avatar photo

Outsourced IT Support London

How AI is Making Phishing Attacks Harder to Spot

Artificial intelligence (AI) is making phishing harder to spot because it removes the old clues staff were taught to look for, then personalises the message at speed. Research by Keepnet Labs and VIPRE Security Group (zensec.co.uk) reveals that 82.6% of phishing emails detected between September 202

Avatar photo

Outsourced IT Support London

What is Zero Trust Security?

Zero trust security is a way of protecting your business by checking every person, device, and application before access is allowed. The blunt idea is this: trust is earned every time, not granted because someone is inside the office network.

Avatar photo