Practical guideEN058

How to Write a One-Page Incident Response Plan for Your Small Business

Create a one-page incident response plan with 5 essential sections: contacts, roles, steps, communication, and resources. Get a step-by-step guide and FAQ.

A one-page incident response plan is a practical tool that helps your team act quickly during a cybersecurity incident, data breach, or operational disruption. It focuses on the immediate actions needed to protect people, stop the spread, preserve evidence, and communicate clearly. To create one, start by listing the most likely incidents for your business, then design a simple checklist-style response for each.

This article shows you the five core sections to include, gives a step-by-step process to build it, and highlights common pitfalls. Use the provided examples as a starting point, but adapt them to your systems and local requirements. Remember to test the plan with a tabletop exercise and review it regularly.

Why a One-Page Plan Works during an Incident

During an incident, stress and confusion can lead to poor decisions. A one-page plan gives your team a clear, scannable reference that focuses on the highest-priority actions: ensuring safety, containing the issue, preserving evidence, and notifying the right people. It is more likely to be read and used than a lengthy manual, and it forces you to think through the essential steps in advance.

The U.S. Small Business Administration (SBA) offers a Business Resilience Guide that outlines how to prepare for and recover from disruptions. While that guide covers broader continuity planning, a one-page incident response plan is a complementary tool designed for the first hours of an emergency. For small businesses with limited resources, simplicity is a key factor in successful response.

  • Quick to read and memorize under stress
  • Forces prioritization of critical actions
  • Easy to update and distribute to the team
  • Reduces decision paralysis by providing clear steps
Sources and verification date: [3]

5 Essential Sections to Include

Your one-page plan should contain five sections. First, key contacts: list internal team members (incident lead, backup lead) and external resources (IT support, managed service provider, insurance agent). Include phone numbers and emails. Second, roles and responsibilities: clearly state who is in charge, who communicates with employees, and who documents the incident. Avoid assigning multiple roles to one person unless necessary.

Third, detection and reporting steps: tell employees what to do if they suspect a problem, such as 'Report to the incident lead immediately' or 'Do not turn off the computer.' Fourth, response actions for the most likely scenarios, like phishing or ransomware. For example, 'Disconnect the network cable' or 'Change all passwords from a separate device.' Fifth, communication and recovery: outline how you will inform staff and customers, and how you will restore systems. Keep it concise, not exhaustive.

  • Contact list: internal and external numbers
  • Roles: who leads, who communicates, who documents
  • Detection and reporting steps for employees
  • Response actions for top scenarios
  • Communication and recovery overview

Step-by-Step Process to Build Your Plan

Start by gathering a small team of employees who understand your operations. Brainstorm the most likely incidents, such as a phishing email, a ransomware attack, or a power outage. For each scenario, identify the immediate action to stop it. Next, decide your priorities: typically human safety, containment, evidence preservation, and communication. Keep these in mind as you write.

Draft the plan in a single page, using short phrases and checklists rather than long sentences. Involve your team in drafting so they feel ownership. Then, test the plan with a tabletop exercise: simulate an incident and walk through the steps. This will reveal missing actions or unclear instructions. Finally, set a schedule to review the plan quarterly, updating contacts and lessons learned.

The SBA's Business Resilience Guide provides a broader framework that can help you think about risk and recovery, but it does not offer a specific one-page template. Use it for additional resilience planning, not as a substitute for your own concise response document.

  • Gather a team and list likely incidents
  • Define core priorities: safety, containment, evidence, recovery
  • Write a one-page draft with checklists
  • Test with a tabletop exercise
  • Review and update at least quarterly
Sources and verification date: [3]

Common Mistakes and How to Avoid Them

A common mistake is letting the plan become outdated. If contact numbers change and the plan is not updated, it could cause dangerous delays. Another is making the plan too detailed, defeating its purpose. Avoid using legal jargon or complex flowcharts that are hard to read under stress. Also, do not overlook internal communication: if employees are not informed, rumors can spread and hinder recovery.

Do not rely on one person. If the designated lead is unavailable, you need a backup. Also, if your business has no in-house IT, include a managed service provider or security consultant in your contacts and ensure you have a valid contract for incident support. Be realistic about your team's skills and capacity, and update the plan whenever a major system or personnel change occurs.

  • Creating the plan but never updating it
  • Making the plan too long or jargon-heavy
  • Failing to include internal communication steps
  • Relying on a single point of contact with no backup

Where to Get Help and Template Ideas

The U.S. Small Business Administration publishes a Business Resilience Guide that includes checklists and worksheets for general disruption planning. The U.S. Department of Energy offers guidance on energy and water audits for federal buildings, which, while not incident-specific, can help you identify operational vulnerabilities that might trigger an incident. These official sources are free and can be adapted to your business.

Additionally, your cybersecurity insurance provider or industry association may offer sample plans or required forms. If you have cyber liability insurance, your insurer might require a written plan and may provide a template. Always check with your local authorities or legal counsel to ensure your plan meets any specific regulations for your industry or region.

  • SBA Business Resilience Guide
  • DOE energy and water audit resources
  • Cybersecurity insurance provider's templates
  • Industry association or local chamber of commerce resources
Sources and verification date: [1][3]

What to verify

  • The SBA guide and DOE audit page are general resources; they do not provide a specific incident response template, so you must adapt them to your context.
  • This article provides generic guidance; check your local laws and industry regulations for specific requirements.
  • Always consult with a qualified professional for legal, cybersecurity, or operational advice tailored to your business.

Questions and answers

How often should I review and test my one-page incident response plan?

Update the plan at least quarterly, and after any drill or real incident. Also review whenever you change major systems or key personnel. Testing with a tabletop exercise every six months can reveal gaps and keep the team ready. [3]

What should I do if my business has no internal IT staff?

Include an external managed IT service provider or a security consultant in your contact list. Your plan should state to call them first in case of a suspected breach. Ensure you have a service contract that covers incident response, and share that contact with your team.

Do I need to include legal and customer notification steps in the plan?

Yes, at a high level. For many regions, you may be required to notify affected individuals and regulators after a data breach. Your plan should include an instruction to consult legal counsel before any external notification, and then note the method and typical timeline. Do not write specific legal deadlines unless you verify them regularly with your advisor.

Sources and verification date

  1. Official source: energy.govenergy.gov · Checked
  2. Official source: help.shopify.comhelp.shopify.com · Checked
  3. Official source: sba.govsba.gov · Checked

Related reading