forumNew topic

They asked for an incident response plan — at our size, who writes it and where do we even start?

BBarış B***Member
Job title
Project manager
Sector
Cosmetics
Organization type
regional distributor
Joined
Aug 2024
Message
77
#1

We're a 15-person software and technical consulting company. We're currently renewing a 350,000 TL annual support contract with a corporate client. But this year, due to audit requirements, their corporate procurement department added a clause demanding a "written cyber incident response procedure" and wants a signed document.

We don't have a full-time info-sec specialist, a sysadmin, or an OHS expert on staff. A freelance IT guy comes in once a week to handle the office server and network stuff. The templates I found online are clearly designed for massive enterprise holdings with hundreds of employees; they talk about digital forensics labs, dedicated call centers, and none of it fits us.

What is the minimum required content for this kind of document for a business of our size? Can we draft something that reflects our actual operations and get it approved by the client without paying for expensive external consulting?

EEmre P***Member
Job title
Field sales representative
Sector
Cosmetics
Organization type
medium-sized business
Joined
Nov 2022
Message
55
Most Helpful#2

Short answer: At your size, you don't need to shell out an exorbitant amount to an outside consulting firm. What your client's audit team is really looking for isn't a complex digital forensics lab; they just want to know that in a crisis, you know who takes the lead, how communication is handled, and how a data leak would be contained.

When tailoring the document to your setup, covering these four core sections is plenty: 1) Detection and Reporting: Who employees report to internally if they spot a suspicious email, ransomware, or server outage. 2) First Response and Isolation: Basic steps like immediately unplugging network cables from an infected PC, turning off Wi-Fi, and revoking server privileges. 3) Crisis Team and Communication: Assigning one partner as the "Crisis Lead" and your freelance IT specialist as the "Technical Response Lead." 4) Legal Notifications and Closure: How the client gets notified immediately if their data is compromised, plus the official 72-hour KVKK notification workflow.

If you map this framework onto a clean 4-5 page flowchart and sign and stamp it with your company seal, corporate audit teams will accept it seeing you've taken ownership of the process. The key is writing down steps you can actually execute, not making empty promises you can't keep.

FFeyza K***Expert
Job title
Clinic manager
Sector
Catering
Organization type
regional distributor
Joined
May 2022
Message
302

Doki · Interface design · 2024

#3

Big companies are putting these clauses in their standard contracts now to manage vendor risk. Whatever you do, don't copy-paste a template full of terms like "SOC team" or "security operations center." If a minor hiccup happens tomorrow and they ask "did you follow your procedure?", you'll be cornered.

RRabia B***Expert
Job title
Sales Manager
Sector
Education
Organization type
family business
Joined
May 2025
Message
83
#4

Just grab an A4 sheet right now and put an emergency phone tree at the top. 1) Who does the person who spots the issue call first? 2) Who pulls the plug or cuts the internet? 3) Which email template goes out to the client? Put that in a Word doc, sign it off and you're good.

DDeniz B***VeteranCommunity member
Joined
May 2025
Message
243
#5

On the technical side, the most critical detail is log management. Definitely mention where system logs are kept and how long backups are stored in an off-network environment. If an incident happens, an external specialist investigating it will want to see at least a 30-day activity log history.

MMelis E***Expert
Job title
Quality control inspector
Sector
Automotive aftermarket
Organization type
20-person company
Joined
Mar 2023
Message
50
#6

Including a 3-tier incident classification will make a great impression on the corporate side: 1) Low: A phishing email caught by one user and deleted before being opened. 2) Medium: A workstation gets infected with malware but hasn't spread to the network. 3) High: Unauthorized access to the client database or servers getting locked down.

HHasan K***Member
Job title
Sales Manager
Sector
Healthcare services
Organization type
chain store
Joined
Sep 2024
Message
404
#7

Is the client only asking for the document itself, or did they also request extras like an incident drill report from the past year or pentest results? Have you checked the rest of the specifications carefully?

PPınar A***MemberCommunity member
Joined
Apr 2024
Message
1
#8

Two years ago, when we were a similar-sized automotive supplier they asked us for the same thing. We sat down and handed over a 30-page document fitting for a huge conglomerate. Three months later, an employee's PC caught malware, and we didn't notify the client. In the audit they realized we violated our own policy and fined us 50,000 TL. Keep it short and sweet, but follow it to the letter.

MMert D***MemberCommunity member
Joined
Feb 2023
Message
40
#9

mate dont panic and definitely dont waste money outsourcing it. I mean u are only 15 people anyway, just make it clear who calls who and state that backups are kept offline thats plenty for enterprise clients.

RRecep T***Veteran
Job title
Human Resources Specialist
Sector
Catering
Organization type
8-person team
Joined
Mar 2025
Message
1
#10

These documents requested by corporate procurement units generally target the basic controls of the ISO 27001 standard. Including KVKK data breach notification obligations and an executive sign-off mechanism in your text will also ensure full legal compliance.

BBurak O***Member
Job title
Store Manager
Sector
Catering
Organization type
40-person manufacturing company
Joined
Oct 2023
Message
18

Doki · E-commerce infrastructure · 2026

#11

My perspective changed after experiencing that. Solutions that work at a small scale collapse when you grow; I learned this late.

Just leaving this note, it might be useful.

UUfuk D***MemberCommunity member
Joined
Jan 2026
Message
71
#12

quick summary for newcomers: Just because everyone does it doesn't mean it's right.

proven by experience.

CCansu P***MemberCommunity member
Joined
Mar 2024
Message
237
#13

I think differently. If it's your first time, start small; scaling comes later.

Good luck with that.

YYiğit K***New member
Job title
Marketing director
Sector
Sports and fitness
Organization type
workshop
Joined
Sep 2026
Message
7

Doki · Server maintenance contract · 2023

#14

Three different views emerged, they all complement each other. Security isn't absolute; it's about making attacks not worth the effort.

Hope this helps.

MMert K***Expert
Job title
Data entry clerk
Sector
Leather
Organization type
40-person manufacturing company
Joined
Jun 2023
Message
18
#15

I agree with this. When you try to change everything at once, nothing settles.

Proven by experience.

GGökhan C***Member
Job title
Intern
Sector
Media and publishing
Organization type
a company within a holding
Joined
Feb 2023
Message
37
#16

I don't think this advice fits everyone. Everyone rushing into incident response plan gets stuck at the same point.

I'm also curious if anyone does it differently.

GGülMember
Job title
Fashion brand
Organization type
40-person manufacturing company
Joined
Nov 2023
Message
128
#17

the discussion got scattered, let me summarize. when you try to change everything at once, nothing settles.

correct me if I'm wrong.

EElif T***Member
Job title
Human Resources Manager
Sector
Freight
Organization type
120-person company
Joined
Sep 2024
Message
265
#18

Exactly like that. Having backups accessible on the same network and with the same identity makes them part of the target.

When you try to change everything at once nothing settles.

MMurat K***MemberCommunity member
Joined
Feb 2023
Message
6
#19

I don't think this advice fits everyone. Hasty decisions become decisions you have to fix six months later.

Proven by experience.

SSelim E***Member
Job title
Director of Finance
Sector
Tourism
Organization type
cooperative
Joined
Oct 2025
Message
209
#20

Let me clarify the technical side. An automated scan report is not the same as a penetration test.

If you post the result here, it will help others too.

Reply