Skip to content
PolicyForge
All posts
By Vyrhak SATH · Founder, NAGASHIELD SECURITY6 minReviewed

How to write an incident response policy

An incident response policy defines how you detect, contain and recover from security incidents. Here are the sections auditors expect — and a free template.

Why it matters

When an incident hits, improvisation costs money and trust. An incident response policy defines roles, decisions and timelines in advance, so your team acts instead of panicking — and so you can prove to auditors and regulators that you were prepared.

What to include

  1. Definitions and severity — what counts as an incident, and a severity scale that drives the response.
  2. Roles — who leads, who communicates, who decides on containment; an on-call path.
  3. Lifecycle — detection, triage, containment, eradication, recovery, and post-incident review.
  4. Communication — internal escalation and external notification, including the breach-notification clock.
  5. Regulatory timelinesGDPR's 72-hour notification to the supervisory authority; NIS2 and DORA reporting where applicable.
  6. Evidence and forensics — preserve logs and chain of custody.
  7. Lessons learned — a blameless review that feeds back into controls.

Common mistakes

  • A plan no one has rehearsed; run at least one tabletop exercise a year.
  • Ignoring notification deadlines — under GDPR the clock starts when you become aware, not when you finish investigating.
  • No defined severity scale, so every alert becomes a fire drill.

Framework alignment

Maps to ISO 27001:2022 Annex A 5.24–5.28 (incident management), the SOC 2 incident criteria, and NIST CSF Respond and Recover.

Primary sources

Generate it in minutes

See a sample incident response policy or generate yours free.

Frequently asked questions

When does the GDPR 72-hour breach notification clock start?

It starts when you become aware of a personal-data breach, not when you finish investigating. Article 33 requires notifying the supervisory authority without undue delay and within 72 hours where feasible. Your policy should make this trigger explicit so the team escalates immediately.

What should an incident response policy contain?

Define incident categories and a severity scale, roles (who leads, communicates and decides containment), the lifecycle (detection, triage, containment, eradication, recovery, review), communication and regulatory timelines, evidence handling, and a blameless lessons-learned step that feeds back into controls.

How often should you test an incident response plan?

At least once a year with a tabletop exercise. A plan no one has rehearsed fails under pressure. Testing surfaces gaps in roles, escalation paths and notification timelines while the stakes are low, and auditors look for evidence that exercises actually happen.