Fig Group · Practical resource
UK incident-response plan template
An incident-response plan names who can act, how the team communicates, what evidence to preserve and who decides containment, notification and recovery. Adapt this template before an incident and keep a controlled copy accessible if your usual systems fail.
By Fig Group · Updated
A planning template, not an emergency response service or legal advice. Tailor and approve it with your technical, business and privacy leads. Sector, contractual and other reporting obligations may differ.
Assign authority before an incident
| Role | Responsibility | Record in your plan |
|---|---|---|
| Incident lead and deputy | Declare severity, coordinate work and maintain the decision log | Named people, phone numbers, cover and escalation authority |
| Technical lead | Investigate, preserve evidence and propose containment/recovery | Available specialists, privileged access and supplier contacts |
| Business/service owner | Approve operational impact and recovery acceptance | Critical services, dependencies and interruption authority |
| Privacy/legal lead | Assess personal-data impact and notification obligations | Decision route, reporting clock and documented rationale |
| Communications lead | Issue approved factual updates | Audience, approver, safe channel and next update time |
Use a controlled response
Record what was observed, when, by whom and which systems or people may be affected. Distinguish facts from assumptions. Use an agreed trusted channel if email or identity systems may be compromised. Keep evidence access restricted and record collection times, sources and handlers.
Choose containment with the technical lead and service owner. Preserve relevant evidence where feasible; avoid improvised destructive actions that could obscure the incident. If there is immediate danger to people, follow the appropriate emergency procedures. Activate continuity arrangements when normal service cannot safely continue.
Record UK personal-data breach decisions
For a controller, notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of a personal-data breach unless it is unlikely to result in a risk to people’s rights and freedoms. Record the awareness time, assessment and reasons for notifying or not notifying. Where information is incomplete, the ICO permits information in phases; explain a late notification.
If the breach is likely to create a high risk to people’s rights and freedoms, inform affected individuals without undue delay, subject to applicable exceptions. A processor must inform its controller without undue delay. Record separate contractual or sector reporting duties and obtain appropriate advice. Do not wait for a completed investigation to assess notification. Use the current ICO guidance linked below.
Exercise example: compromised email account
Fictional tabletop: at 09:00 a member of staff reports unexpected mailbox forwarding and unusual sign-ins. Ask the team to identify its incident lead, trusted contact channel, technical containment authority and evidence sources. At the next inject, disclose that customer correspondence may have been accessed; ask who starts the personal-data assessment and records the awareness time.
The exercise passes only if the team records responsible people, decisions, evidence and the next update. It does not pass merely because someone says “reset the password”. Record missed contacts and unclear authority as actions with owners. Use test data; do not send exercise messages to real customers or regulators.
Prepare and exercise your plan
Complete roles and activation rules
Name the incident lead, deputies, technical and privacy contacts. Agree severity triggers, safe communications and containment authority.
Prepare logs and notification decisions
Set up the timeline, evidence register, impact assessment and approval records. Include awareness times and applicable reporting deadlines.
Exercise recovery and follow-up
Run a fictional scenario, test contacts, agree safe recovery criteria and record lessons with owners and due dates.
Copy or download the template
Use the blank worksheet in your own document editor. Replace the prompts with your organisation’s details, obtain the relevant approvals and keep a controlled copy.
UK INCIDENT-RESPONSE PLAN Organisation / scope / version / owner / approval date: Incident lead and deputy (trusted contact details): Technical lead / service owner / privacy lead / communications lead: Out-of-hours and supplier contacts: Activation and severity criteria: Trusted primary and fallback communications: Evidence storage location and access authority: INCIDENT RECORD Incident ID / discovery time / awareness time / timezone: Reported by / facts known / assumptions / affected systems: Business impact / personal-data categories / people potentially affected: Containment action / approver / time / expected impact: Evidence reference / source / collector / collection time / access history: Decision log: time | decision | reason | approver | next action NOTIFICATION ASSESSMENT Controller / processor role: Risk to rights and freedoms / evidence / uncertainty: ICO notification decision, rationale, owner and deadline: Affected-person notification decision and rationale: Controller / contractual / sector notifications and deadlines: Information still required and next update: RECOVERY AND CLOSURE Recovery criteria / verification / service-owner sign-off: Approved communication / audience / sender / time: Monitoring after recovery: Lessons / action owner / due date / verification: Next plan review and exercise date:
Explore the workflow in Fig Group
Fig Group supports structured incident records, evidence capture, owned actions and notification tracking. Demonstrate this workflow with a fictional incident and confirm permissions, escalation and reporting needs. Using the platform does not appoint an incident responder or transfer your notification decisions to Fig Group.
Common questions
Does every cyber incident need to be reported to the ICO?
No. Assess whether it involves a personal-data breach and the relevant risk to people. Record the decision and follow the current ICO guidance; other contractual or sector notifications may still apply.
Should the plan be available offline?
Keep a controlled, protected copy and current emergency contacts accessible if your usual identity, email or document systems are unavailable. Test access during an exercise.
Sources and further reading
Use the current source guidance alongside your own requirements when completing the worksheet.