Cyber Incident Response Plan Kit

Prepare your organisation to respond calmly and confidently when a cyber incident occurs.

Cyber incidents move quickly. Your response plan should too.

When a cyber incident occurs, your team needs clear roles, escalation paths and decision points already in place. This practical kit helps you document how your organisation will detect, assess, contain, recover from and review cyber security incidents.

What’s covered in this kit

A.

Roles and responsibilities

Define who is involved, what they own and when they need to be contacted.

B.

Incident classification

Assess common cyber incidents, including phishing, ransomware, data breaches, malware and business email compromise.

C.

Severity and escalation

Use impact and likelihood ratings to classify incidents and escalate consistently.

D.

Containment and evidence collection

Plan how to limit damage while preserving the information needed for investigation and compliance.

E.

Recovery and restoration

Document how affected systems will be cleaned, restored, monitored and returned to normal operations.

F.

Lessons learned

Review what happened, what worked and what needs to improve after an incident.

G.

Notification requirements

Prepare to meet notification requirements, including Privacy Act and Notifiable Data Breaches scheme, and avoid non‑compliance and unexpected penalties