- Job title
- IT Manager
- Sector
- Automotive aftermarket
- Organization type
- workshop
- Joined
- Jun 2024
- Message
- 49
We're a Berlin-based B2B software and consulting company with 10 people. Most of our clients are mid-sized industrial firms across Germany. Last week, a major client sent us their annual security audit questionnaire, explicitly asking if we have a formal incident response plan and when it was last tested.
Right now, we have zero written procedures. If a security breach or server crash happens, we just talk on our internal messaging app and handle it on the fly. But copying the dozens-of-pages-long templates enterprise companies use feels completely pointless and unmanageable for a 10-person team. We don't have a full-time security specialist; two of our software devs handle the infrastructure stuff.
What should be the bare minimum in an incident response plan for a 10-person team so it’s actually actionable and doesn't just collect dust in a folder? How can we set up a practical framework that spells out who does what in the first 24 hours?