[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-1-en-105":3,"doc-seo-243308-105":53,"doc-detail-243308-en":126},{"code":4,"msg":5,"data":6},0,"success",[7,14,19,24,29,34,39,44,49],{"id":8,"doc_module":9,"doc_module_name":10,"category_name":11,"show_sort_weight":12,"slug":13},11,1,"Template","Presentations",90,"presentations",{"id":15,"doc_module":9,"doc_module_name":10,"category_name":16,"show_sort_weight":17,"slug":18},12,"Resumes",80,"resumes",{"id":20,"doc_module":9,"doc_module_name":10,"category_name":21,"show_sort_weight":22,"slug":23},14,"Invoices",70,"invoices",{"id":25,"doc_module":9,"doc_module_name":10,"category_name":26,"show_sort_weight":27,"slug":28},15,"Posters",60,"posters",{"id":30,"doc_module":9,"doc_module_name":10,"category_name":31,"show_sort_weight":32,"slug":33},16,"Social Media",50,"social-media",{"id":35,"doc_module":9,"doc_module_name":10,"category_name":36,"show_sort_weight":37,"slug":38},17,"Forms",40,"forms",{"id":40,"doc_module":9,"doc_module_name":10,"category_name":41,"show_sort_weight":42,"slug":43},18,"Letters",30,"letters",{"id":45,"doc_module":9,"doc_module_name":10,"category_name":46,"show_sort_weight":47,"slug":48},21,"Paper Templates",5,"papers-templates",{"id":50,"doc_module":9,"doc_module_name":10,"category_name":51,"show_sort_weight":4,"slug":52},158,"General","general-158",{"code":4,"msg":54,"data":55},"ok",{"site_id":56,"language":57,"slug":58,"title":59,"keywords":60,"description":61,"schema_data":62,"social_meta":119,"head_meta":121,"extra_data":123,"updated_unix":125},105,"en","incident-response-plan-irp-basics-key-activities-before-during-and-after","Incident Response Plan (IRP) Basics - Key Activities Before, During, and After","","An Incident Response Plan (IRP) is a senior-leadership approved, written playbook that guides an organization across the full lifecycle of a confirmed or suspected security incident. The guide defines pre-incident preparation steps—training, legal review, stakeholder planning, crisis communications, external technical resources, and tabletop attack simulations. It then outlines incident execution with clear incident, technical, and communications management roles. Finally, it covers blameless postmortem retrospectives, policy updates, and transparent staff communication.",{"@graph":63,"@context":118},[64,80,101],{"@type":65,"itemListElement":66},"BreadcrumbList",[67,71,74,77],{"item":68,"name":69,"@type":70,"position":9},"https://docshare.wps.com","Home","ListItem",{"item":72,"name":10,"@type":70,"position":73},"https://docshare.wps.com/template/",2,{"item":75,"name":51,"@type":70,"position":76},"https://docshare.wps.com/template/general/",3,{"item":78,"name":59,"@type":70,"position":79},"https://docshare.wps.com/template/incident-response-plan-irp-basics-key-activities-before-during-and-after/243308/",4,{"url":78,"name":59,"@type":81,"image":82,"author":87,"headline":59,"publisher":90,"fileFormat":93,"inLanguage":57,"description":61,"dateModified":94,"datePublished":95,"encodingFormat":93,"isAccessibleForFree":96,"interactionStatistic":97},"DigitalDocument",{"url":83,"@type":84,"width":85,"height":86},"https://docshare.wps.com/thumbnails/incident-response-plan-irp-basics-key-activities-before-during-and-after/243308.png","ImageObject",442,249,{"name":88,"@type":89},"Skyler","Person",{"url":68,"name":91,"@type":92},"DocShare","Organization","application/pdf","2026-09-23","2026-09-12",true,{"@type":98,"interactionType":99,"userInteractionCount":76},"InteractionCounter",{"@type":100},"ViewAction",{"@type":102,"mainEntity":103},"FAQPage",[104,110,114],{"name":105,"@type":106,"acceptedAnswer":107},"What is the purpose of an Incident Response Plan (IRP)?","Question",{"text":108,"@type":109},"An IRP is a written, senior-leadership approved document that helps the organization before, during, and after a confirmed or suspected security incident. It clarifies roles, responsibilities, and key activities during the incident lifecycle.","Answer",{"name":111,"@type":106,"acceptedAnswer":112},"What should organizations do before a cybersecurity incident?",{"text":113,"@type":109},"Before an incident, organizations should train staff on reporting and security culture, review the plan with an attorney, coordinate with CISA and local law enforcement, prepare printed documents and contact lists, plan incident staffing and stakeholders, review the plan quarterly, prepare press responses, select outside technical resources, and run tabletop attack simulation exercises.",{"name":115,"@type":106,"acceptedAnswer":116},"What happens after a cybersecurity incident?",{"text":117,"@type":109},"After an incident, the organization should hold a formal, blameless retrospective (postmortem), report the known incident timeline, collect analysis and improvement suggestions, update policies and procedures, and communicate findings transparently to staff to build trust and strengthen security culture.","https://schema.org",{"og:url":78,"og:type":120,"og:title":59,"og:site_name":91,"og:description":61},"article",{"robots":122,"canonical":78},"index,follow",{"doc_id":124,"site_id":56},243308,1789202498,{"code":4,"msg":5,"data":127},{"doc_id":124,"user_id":128,"nickname":88,"user_avatar":129,"doc_module":9,"category_id":50,"category_name":51,"doc_title":59,"doc_description":61,"doc_content":130,"file_id":131,"file_url":132,"file_type":133,"file_size":134,"view_count":76,"is_deleted":4,"is_public":9,"is_downloadable":9,"audit_status":9,"page_count":73,"language":135,"language_code":57,"site_id":56,"html_lang":57,"table_of_contents":136,"faqs":137,"seo_title":138,"seo_description":61,"update_tm":125,"read_time":9},2336464648746,"https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c","Incident Response Plan (IRP) Basics  \nOVERVIEW  \nAn Incident Response Plan is a written document, formally approved by the senior leadership team, that helps your organization before, during, and after a confirmed or suspected security incident. Your IRP will clarify roles and responsibilities and will provide guidance on key activities. It should also include a cybersecurity list of key people who may be needed during a crisis.  \nBEFORE A CYBERSECURITY INCIDENT  \n• Train the staff. All staff need to understand their role in maintaining and improving the security of the organization. That includes knowing how to report suspicious events. Be gracious when people report false alarms. Reward people who come forward to report suspicious events as part of your commitment to a culture of security.  \n• Review your plan with an attorney. Your attorney may instruct you to use a completely different IRP template. Attorneys often have preferences on how to engage with outside incident response vendors, law enforcement, and other stakeholders.  \n• Meet your CISA regional team. You can find your regional office information here. Within each CISA Region are your local and regional Protective Security Advisors (PSAs), Cybersecurity Advisors (CSAs), Emergency Communications Division Coordinators, and other CISA personnel to handle a wide array of needs.  \n• Meet your local law enforcement agency (LEA) team. In coordination with your attorney, get to know your local police or FBI representatives. The time to figure out how to notify LEA representatives isn’t in the heat of battle.  \n• Print these documents and the associated contact list and give a copy to everyone you expect to play a role in an incident. During an incident, your internal email, chat, and document storage services may be down or inaccessible.  \n• Develop an incident staffing and stakeholder plan. What roles will everyone play? Which people and groups will need to be notified that won’t be top of mind during the incident? Examples include the board of directors, key investors, and critical partners.  \n• Review this plan quarterly. The best IRPs are living documents that evolve with business changes.  \n• Prepare press responses in advance. If a reporter calls you, claiming to have data stolen from your file servers, what will you say? Having a good “holding statement” will help.  \n• Select an outside technical resource/firm that will investigate potential compromises.  \n• Conduct an attack simulation exercise, sometimes called a tabletop exercise, or TTX. A TTX is a roleplaying game where a facilitator presents a scenario to the team. The exercise might start with the head of communications receiving an email from a reporter about rumors of a hack. The facilitator will provide other updates during the game to see how everyone plays their role. Every sports team rehearses, and you should too!  \nDURING A CYBERSECURITY INCIDENT  \n• Assign an Incident Manager (IM). This person leads the response. They manage communication flows, update stakeholders, and delegate tasks. However, the IM does not perform any technical duties. During a time of crisis, time dilation affects people’s perception of time passing. The IM will monitor the clock to avoid that common problem. The IM may also lead the retrospective meeting (outlined below) to gather  \nlessons learned.  \n• Assign Tech Manager (TM). The TM will serve as the subject matter expert. They will bring in other internal and possibly external technical experts (with the consent of the IM and possibly your attorney!)  \n• Assign Communications Manager (CM). The CM will interact with reporters, post updates on social media, and may interact with external stakeholders (like shareholders) .  \nAFTER A CYBERSECURITY INCIDENT  \n• Hold a formal retrospective meeting (sometimes called a “postmortem”) . In the retrospective, the IM will report out the known incident timeline and ask for additions and edits. They will then ask for analysis from the ","cbCaiu14M46mrlkO","https://ap.wps.com/l/cbCaiu14M46mrlkO","pdf",307866,"English","# Overview\n# Before a Cybersecurity Incident\n## Train the staff and enable reporting\n## Review the plan with an attorney\n## Coordinate with CISA and local law enforcement\n## Prepare contacts, staffing, and press responses\n## Select external technical resources and run tabletop exercises\n# During a Cybersecurity Incident\n## Assign an Incident Manager (IM)\n## Assign a Tech Manager (TM)\n## Assign a Communications Manager (CM)\n# After a Cybersecurity Incident\n## Conduct a formal, blameless retrospective\n## Update policies and procedures\n## Communicate findings to staff\n# See Also","[{\"question\":\"What is the purpose of an Incident Response Plan (IRP)?\",\"answer\":\"An IRP is a written, senior-leadership approved document that helps the organization before, during, and after a confirmed or suspected security incident. It clarifies roles, responsibilities, and key activities during the incident lifecycle.\"},{\"question\":\"What should organizations do before a cybersecurity incident?\",\"answer\":\"Before an incident, organizations should train staff on reporting and security culture, review the plan with an attorney, coordinate with CISA and local law enforcement, prepare printed documents and contact lists, plan incident staffing and stakeholders, review the plan quarterly, prepare press responses, select outside technical resources, and run tabletop attack simulation exercises.\"},{\"question\":\"What happens after a cybersecurity incident?\",\"answer\":\"After an incident, the organization should hold a formal, blameless retrospective (postmortem), report the known incident timeline, collect analysis and improvement suggestions, update policies and procedures, and communicate findings transparently to staff to build trust and strengthen security culture.\"}]","Incident Response Plan (IRP) Basics - Key Activities Before, During, and After | PDF"]