This is for you if

  • You do not have a written incident response plan, or nobody could find it today
  • Your plan lives on the file shares or in the email platform it is meant to recover
  • You are not sure when the ICO must be told, or who else to notify
  • An insurer, client or auditor has asked whether you have a plan and when it was last tested

The first hour of an incident is spent finding phone numbers, deciding who is in charge and arguing about whether to switch things off. Then the 72 hours for the ICO start running from the moment you became aware, not from the end of the investigation. A one-page plan, filled in and printed before the day, turns that hour into a list.

This template is the page to fill in and print, plus the steps behind it: the first 15 minutes, the first hour, the first day, the 72-hour deadline and who to notify, each reporting rule quoted from its first-party source.

The Cyber Security Breaches Survey 2025/26 (DSIT and the Home Office, published 30 April 2026) found formal incident response plans in 25% of businesses: 21% of micro businesses, against 57% of medium-sized and 76% of large ones. The reporting rules below were checked against the ICO, the NCSC and Report Fraud on 5 October 2026. This is a template, not legal advice: adapt it to your organisation, and take advice on any decision to report.

Your plan on one page

Two people and two ways to reach each one, for every role. Fill it in, print it, and keep the copy with the backup credentials, somewhere that does not depend on the email platform or the file shares. The PDF version can be typed into on screen.

Incident lead (declares the incident and makes the calls; name and two ways to reach them)
Deputy (if the lead cannot be reached; name and two ways to reach them)
IT lead or IT provider's incident line (contains and restores)
Data protection lead (decides whether the ICO and the people affected must be told)
Communications lead (staff, customers, suppliers, press)
Director who signs off decisions (payments, legal advice, the insurer)
Insurer incident line and policy number (if you have cyber cover)
Legal adviser and bank fraud line
How staff are reached if email and Teams are down
Where the offline copy of this plan, the backup credentials and this contact list are kept

1. The first 15 minutes: declare and protect

  • Whoever spots it tells the incident lead by phone, not only by email, and notes the time
  • The incident lead declares an incident and opens a log: the time, what was seen, who has been told
  • Affected devices are disconnected from the network (cable out, Wi-Fi off); check with your IT lead before switching anything off, so evidence is not lost
  • Nobody replies to, pays or negotiates with an attacker without a decision from the incident lead and advice from your insurer or responders

2. Within the hour: contain and call

  • Your IT lead or IT provider is on the call, and confirms what is affected and what is not
  • Accounts that may be compromised are reset and their sessions revoked, administrators first; activity is blocked and affected systems isolated
  • If you have cyber cover, your insurer's incident line is called as the policy sets out: some insurers provide forensic, legal and public relations support
  • Staff are told what to do and what not to do, through a channel that does not depend on the affected systems
  • Evidence is kept: logs, ransom notes, suspicious emails and screenshots are not deleted while cleaning up
  • Every action and decision goes in the log with the time and who made it

3. Within 24 hours: assess, and decide who to tell

  • You have decided whether personal data is involved and, if so, whether the breach is likely to result in a risk to people's rights and freedoms
  • If you suspect criminal intent, it is reported to Report Fraud (England, Wales and Northern Ireland) or Police Scotland
  • You have considered reporting to the NCSC; if you are not sure which organisations to contact, the government signposting service at gov.uk/report-cyber helps
  • You have decided what customers and suppliers are told, and who speaks for the organisation
  • Systems are restored from known-good backups only once the way in has been closed

4. Within 72 hours: report and record

  • If the breach is notifiable, it is reported to the ICO without undue delay, and not later than 72 hours after becoming aware of it
  • If you do not have every detail yet, you report what you know: the information can be provided in phases, without undue further delay
  • If the breach is likely to result in a high risk to individuals, the people affected are told directly and without undue delay
  • If you decide not to report, the reason is written down: you need to be able to justify the decision
  • The breach is recorded whether or not it is reported
Who to notify after a cyber incident: when, how, and the source for each rule
WhenHowSource, checked 5 October 2026
Your insurerAs your policy sets out, if you have cyber cover: check its notification terms now, not on the dayThe incident line in your policy documentsICO: consider notifying your insurer. NCSC cyber insurance guidance
The ICOA notifiable personal data breach: without undue delay, and not later than 72 hours after becoming awareOnline form, about 30 minutes; details can follow in phasesICO, Personal data breaches: a guide
The people affectedA high risk to their rights and freedoms is likely: directly and without undue delayDirectly, in clear termsICO, Personal data breaches: a guide
Report Fraud, or Police ScotlandYou believe there may be criminal intentEngland, Wales and Northern Ireland: Report Fraud; a business under attack can call 0300 123 2040. Scotland: Police Scotland on 101ICO breach page; reportfraud.police.uk
The NCSCThe incident was caused by a malicious actor; worth considering in any significant incidentgov.uk/report-cyber signposts you to the right organisationsICO breach page; NCSC incident management
Who to notify after a cyber incident, when, and how, each with its first-party source, checked 5 October 2026. The ICO's guidance asks you to consider all of these: it is your responsibility to notify all the appropriate organisations.

5. Afterwards: review and rehearse

Our recommendation, not a regulatory requirement.

  • A short review once systems are back: what happened, what worked, what to change
  • The plan, the contact list and the offline copy are updated with what was learned
  • The plan is walked through with the people named in it at least once a year, and whenever one of them changes

What makes a plan work on the day

Not length. Names, deputies, a second way to reach them, the steps in order, and a copy you can read with the systems down. The restore step is the one most plans assume rather than prove; our backup and recovery review looks at coverage, immutability and recovery order against what you run.

  • The plan lives on the systems it is meant to recover

    Print it. Keep a copy with the backup credentials and the contact list somewhere that does not depend on the email platform or the file shares.

  • One name against every role

    Add a deputy and a second way to reach each person. Incidents rarely start at a convenient time.

  • The 72 hours counted from the day IT finished investigating

    The ICO counts from becoming aware of the breach. Report what you know and add the detail later, in phases.

  • Every field filled, and walked through this year

    A plan people can follow on the worst possible day. Keep it dated, and review it whenever someone named in it changes.

Sources

Checked on 5 October 2026:

For the recovery side of the plan, the backup and restore readiness checklist tests whether you could restore, not whether you have backups. The rest of our checklists and templates are listed on all our resources.

Frequently asked

When do we have to tell the ICO about a breach?

The ICO's guidance says you must report a notifiable breach without undue delay, but not later than 72 hours after becoming aware of it. If a risk to people's rights and freedoms is unlikely, you do not have to report it, but you need to be able to justify that decision, and you should record all breaches whether or not they are reported. If you do not have every detail within 72 hours, you can provide the information in phases. Checked against ico.org.uk on 5 October 2026.

Who else should we notify after a cyber incident?

The ICO's guidance suggests considering your insurer, law enforcement and the NCSC if the breach was caused by a malicious actor. Where you suspect criminal intent, report to Report Fraud (England, Wales and Northern Ireland) or to Police Scotland. If you are not sure which organisations to contact, the NCSC points to the government's signposting service at gov.uk/report-cyber. Your cyber insurance policy sets out how and when to notify your insurer.

Should we switch off an infected computer?

Disconnect it from the network first, by unplugging the cable and turning off Wi-Fi, and check with your IT lead or your insurer's responders before switching it off, so evidence is not lost. Whatever you do, write it in the log with the time and who decided.

Is this template legal advice?

No. It is a template to adapt to your organisation, with the reporting rules quoted from their first-party sources and dated. Take advice on any decision about whether to report.