We run an 18-person team in Madrid providing custom software and cloud infrastructure support to enterprise clients in logistics and finance. One of our major enterprise clients, with an annual contract value of 120,000 EUR, asked us for a NIST-aligned incident response plan during this year's vendor audit.
Up until now, we've handled things through unwritten practices; whenever a server crashed or there was a suspicious login attempt, the tech team would just jump on a call, resolve the issue, and then verify database backups. But the audit team wants to see documented workflows, defined roles, and tabletop exercise records.
We don't want to burn a 15,000 EUR budget on an outside consultant. Would implementing the NIST incident response framework be total overkill for an SME of our size? How can we adapt our processes without drowning in this framework, and which stages are strictly required in an audit?