A written incident response plan has moved from nice-to-have to expectation — baked into cyber insurance underwriting, regulatory frameworks, and Illinois’ own breach notification law. But a plan that’s never been tested with the people responsible for executing it tends to fall apart the moment a real incident hits.
What a Plan Actually Needs to Include
At minimum: a clear definition of what qualifies as a reportable incident, named roles and contacts (who leads the response, who handles legal and regulatory notification, who communicates with customers or clients, who handles technical containment), a defined process for engaging outside help if needed, and a communication plan covering internal staff, customers, and any regulatory deadlines that apply to your industry. The plan should be a short, usable reference document, not a hundred-page binder nobody actually reads when it matters.
Why an Untested Plan Is Closer to a Hope Than a Plan
A tabletop exercise is a discussion-based simulation where your team walks through a realistic incident scenario out loud — “ransomware has encrypted the file server, what happens next?” — using the actual plan as a guide. It’s a low-cost, low-disruption way to find gaps before a real incident does: who’s actually reachable at 2am, whether the contact list is current, whether people know their specific role without being told in the moment. At least annually is a reasonable baseline, with additional exercises after any significant change to systems, staff, or vendors the plan depends on. Cyber insurers increasingly ask specifically whether a plan has been exercised recently, not just whether one exists.
The Illinois Notification Clock
Illinois’ Personal Information Protection Act requires notice to affected individuals “in the most expedient time possible and without unreasonable delay” after discovering a breach. For breaches affecting more than 500 Illinois residents, notice to the Illinois Attorney General is required within 45 days of discovery, or by the time consumer notice goes out, whichever comes first. A tested plan is what makes it realistically possible to meet these deadlines, rather than scrambling to figure out the requirement after the fact, mid-incident.
Naming Real People, Not Just Roles
Even without a large staff, a plan should name specific individuals, not just job titles, for: incident lead and decision-maker, IT and technical containment (often the managed IT provider), legal counsel, and a single point of contact for external communication. Smaller businesses often combine roles across fewer people, but every role still needs a named owner. “Someone will handle it” is not a plan.
The First Move When You Suspect an Incident
Contain first, without destroying evidence. Disconnect affected systems from the network rather than shutting them down entirely, which can erase forensic evidence held in memory, and immediately engage whoever is designated in the plan as technical lead. Businesses without a plan often waste critical early hours just deciding who should be making these calls — exactly the delay a tested plan eliminates.
Should You Have a Retainer in Place?
An incident response retainer is a pre-arranged agreement with a digital forensics and incident response firm guaranteeing prioritized access if a serious incident occurs, rather than negotiating with a provider for the first time while actively under attack. For businesses without in-house security expertise, a retainer — often through a managed IT provider or cyber insurance policy — closes a critical gap, since incident response quality in the first hours has an outsized effect on total damage and cost.
How CelereTech Helps
CelereTech builds a written incident response plan tailored to your actual systems and staff, runs an initial tabletop exercise to test it, and serves as the technical first responder named in the plan itself — so the plan isn’t just a document, it’s backed by a team that already knows your environment before an incident happens. We also help schedule recurring tabletop exercises so the plan stays current as your business changes.
Get your incident response plan built and tested before you need it.