forumNew topic

Incident response plan for a 10-person company: What should it include without turning into binders of paperwork?

BBurcu A***Member
Job title
IT Manager
Sector
Automotive aftermarket
Organization type
workshop
Joined
Jun 2024
Message
49
#1

We're a Berlin-based B2B software and consulting company with 10 people. Most of our clients are mid-sized industrial firms across Germany. Last week, a major client sent us their annual security audit questionnaire, explicitly asking if we have a formal incident response plan and when it was last tested.

Right now, we have zero written procedures. If a security breach or server crash happens, we just talk on our internal messaging app and handle it on the fly. But copying the dozens-of-pages-long templates enterprise companies use feels completely pointless and unmanageable for a 10-person team. We don't have a full-time security specialist; two of our software devs handle the infrastructure stuff.

What should be the bare minimum in an incident response plan for a 10-person team so it’s actually actionable and doesn't just collect dust in a folder? How can we set up a practical framework that spells out who does what in the first 24 hours?

OOsman T***Member
Job title
Technical service technician
Sector
Furniture manufacturing
Organization type
a company within a holding
Joined
Jan 2022
Message
3
Most Helpful#2

Short answer: For a ten-person company, an incident response plan should strictly not exceed two or three pages. What matters is not thick manuals, but clarity of roles, the chain of communication, and concrete steps to take in the first 24 hours.

You can divide the plan into three main sections. The first is identifying the decision-maker and the technical lead. There should be a single, unambiguous answer to who coordinates the incident, who communicates with the client and authorities, and who leads the technical investigation. The second section is the contact directory. This must include internal emergency phone numbers, urgent support channels for your hosting and cloud providers, and your cyber law counsel's contact details. This list must be stored outside the corporate network, offline, or in an independent location.

The third section is the first 24 hours protocol. The order here is straightforward: 1) Sever the network connection of affected systems without powering them down, to prevent evidence loss; 2) Document down to the minute when the incident began, what anomalies were observed, and who performed what action; 3) If a data breach is suspected, notify management and legal counsel, keeping in mind statutory notification windows (particularly the 72-hour rule under GDPR).

Once you have written this two-page draft, run a tabletop exercise once a year on a Friday afternoon. Rehearsing for 45 minutes on who does what when an email account is compromised or a database is locked will serve you far better than an unread 50-page manual.

MMert Ö***Member
Job title
Fuel station
Organization type
early-stage startup
Joined
Nov 2023
Message
64
#3

First thing you do: do not keep that plan on the company server. If ransomware hits, you won't be able to access your own server. Keep printed copies with the manager and tech lead, and stash another copy in an independent, external cloud folder. Also pick an out-of-band communication channel ahead of time, not company email.

TTaner E***MemberCommunity member
Joined
Apr 2023
Message
118
#4

We run an agency of a similar size in Munich. Last year, a client's email account got compromised. Because we hadn't written down who calls whom beforehand, we lost the first 4 hours panicking internally and asking each other questions. After that incident, we put together a one-page flowchart. It only took us 3 hours to prepare, but during a minor DNS issue later on, we got organized within 20 minutes.

EEsraMember
Job title
Python developer
Joined
Aug 2024
Message
134
#5

On the technical side, the biggest mistake people make in a panic is pulling the server plug or immediately rebooting. That wipes the volatile memory logs in RAM, and you won't be able to tell how the attacker got in. The plan must explicitly state: 'do not shut down the machine, just pull the network cable or disable the virtual server's network adapter.'

HHakan T***Member
Job title
Investment advisor
Joined
Jan 2024
Message
96
#6

If you operate in Germany, do not disregard the legal dimension. Your incident response plan should clearly define, as a distinct step, the 72-hour obligation to notify the relevant supervisory authority pursuant to Article 33 of GDPR, as well as the procedure for notifying data subjects if necessary. Companies frequently miss this deadline amid internal chaos.

BBurcu Ö***New member
Job title
Store associate
Sector
Media and publishing
Organization type
40-person manufacturing company
Joined
Sep 2026
Message
2

Doki · Server maintenance contract · 2026

#7

Those audit questionnaires clients send over are generic corporate checklists. The two-page plan you write will work great internally, but an enterprise auditor might be looking for checkboxes like a 24/7 SOC. Write the plan, but when presenting it to the client, frame it clearly as an 'agile plan tailored to a 10-person organizational structure,' otherwise you'll make life unnecessarily hard for yourselves.

Edit: asked below, I wrote the answer in the second message.

TTaner K***Member
Job title
Sales Manager
Sector
Seafood
Organization type
medium-sized business
Joined
Sep 2023
Message
3
#8

we're an 8-person team and when something similar happened to us we realized no one had our lawyer's number... an emergency phone list and backup contact info for everyone is the most critical part... just title the doc Incident Response Plan, keep the content to a 2-page summary and you're good.

İİlker K***Expert
Job title
Software developer
Sector
Freight
Organization type
300-person organization
Joined
Nov 2022
Message
42
#9

In the audit, is your client just asking whether a plan exists, or are they also requesting the latest test report and third-party sign-off? Some audits only want to see exercise minutes, while others require an external audit report. Have you checked the security addendum in your contract?

EEsra D***Member
Job title
SME Consultant
Joined
Feb 2024
Message
124
#10

Don't be too hard on yourselves, no need to drown in enterprise templates. Just add a simple severity classification to your plan: Low (single user affected), Medium (service outage, but data is safe), High (data breach or critical data loss). This classification makes it crystal clear who needs to be alerted and when.

OOnur A***ExpertCommunity member
Joined
Nov 2025
Message
64
#11

I'm in the same situation, that's why I'm asking. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

Solutions that work at a small scale collapse when you grow; I learned this late. If you post the result here, it will help others too.

EErcan Y***MemberCommunity member
Joined
Mar 2024
Message
350
#12

I agree, and I'd like to emphasize that. Most incidents start with a leaked password, not a vulnerability.

If you post the result here, it will help others too.

LLeyla Y***Member
Job title
Accounting clerk
Sector
Freight
Organization type
workshop
Joined
Feb 2022
Message
2
#13

I have a question don't want to go off-topic though. Payment information changes are never verified through the channel they came from.

Having backups accessible on the same network and with the same identity makes them part of the target. btw correct me if I'm wrong.

AAyşe B***Member
Job title
Operations manager
Sector
Real estate
Organization type
two-branch business
Joined
Mar 2023
Message
20
#14

Thanks a lot, I'll try it today.

HHasan Ö***MemberCommunity member
Joined
Dec 2024
Message
39
#15

i'll try it. when making a decision first look at what data you have on hand.

i'm also curious if anyone does it differently.

KKübra Y***MemberCommunity member
Joined
Dec 2023
Message
40
#16

This thread is archived.

VVolkan Ö***Expert
Job title
Intern
Sector
E-commerce
Organization type
early-stage startup
Joined
Oct 2022
Message
51
#17

Here's how it went for us. Having backups accessible on the same network and with the same identity makes them part of the target.

I'm also curious if anyone does it differently.

PPolat B***Member
Job title
Data Analyst
Sector
Textile
Organization type
20-person company
Joined
Oct 2023
Message
240

Doki · Mobile app · 2026

#18

Timely topic.

HHüsniye Ç***MemberCommunity member
Joined
Oct 2024
Message
17
#19

let me summarize the topic, since several diffreent answers were given but most time waste accumulates in tasks waiting for approval.

hope this helps.

FFurkan U***Member
Job title
Administrative manager
Sector
Energy
Organization type
40-person manufacturing company
Joined
Jul 2025
Message
84
#20

Yes, that's exactly how it is with incident response plan. Taking measures without an inventory leaves doors you haven't seen open.

This topic has been closed.The moderator marked the topic as resolved. If you have a similar issue, you can open a new topic.
New topic