Back to Learning Centre
Template

Incident Response Plan (IRP) Template

A structured template to help South African businesses prepare for, respond to, and recover from cybersecurity incidents.

Synaptic Technologies · v1.0 · 2026

A cyberattack is not a matter of if — it is a matter of when. Having a documented Incident Response Plan (IRP) before an incident occurs dramatically reduces damage, recovery time, and reputational harm. This template provides a structured framework that any South African SME can adapt and implement.

Section 1: Plan Overview

Organisation Namee.g. Acme (Pty) Ltd
Plan Owner (Information Officer)Full name and job title
Date ApprovedDD/MM/YYYY
Review Frequencye.g. Annually or after every incident
Next Review DateDD/MM/YYYY

Section 2: Incident Response Team

Define who is responsible for managing a cybersecurity incident. Ensure this list is accessible offline (printed copy) in case systems are compromised.

Incident Commander

Overall coordination and decision-making during the incident.

Name: ___________________Contact: ___________________

IT Lead / Technical Responder

Technical investigation, containment, and remediation.

Name: ___________________Contact: ___________________

Communications Lead

Internal and external communications, including staff, customers, and media.

Name: ___________________Contact: ___________________

Legal / Compliance Officer

Advises on legal obligations including POPIA breach notification.

Name: ___________________Contact: ___________________

Executive Sponsor

Senior leadership oversight and authorisation of major decisions.

Name: ___________________Contact: ___________________

Key External Contacts

IT / Cybersecurity PartnerSynaptic Technologies — 087 163 6398
Cyber Insurance Provider
Legal Counsel
Information Regulator (POPIA)inforegulator.org.za | 010 023 5207
SAPS Cybercrime Unit10111 or [email protected]

Section 3: Incident Classification

Classify the severity of the incident to determine the appropriate response level.

P1 — Critical

Active ransomware, full system compromise, confirmed data breach affecting customers or staff. Business operations severely impacted.

Immediate escalation to Incident Commander. All hands on deck. Consider isolating affected systems immediately.

P2 — High

Suspected breach, malware detected, significant data loss, or a single critical system compromised.

Escalate to IT Lead and Incident Commander within 1 hour. Begin containment.

P3 — Medium

Phishing email clicked, suspicious login detected, minor malware on a single device.

IT Lead to investigate within 4 hours. Monitor and contain.

P4 — Low

Spam campaign, failed login attempts, minor policy violation.

Log the incident. IT Lead to review within 24 hours.

Section 4: Response Phases

01

Identification

Detect and confirm that a security incident has occurred.

Receive alert or report from staff, system, or security tool.
Determine whether the event is a genuine incident or a false positive.
Classify the incident severity (P1–P4).
Log the incident: date, time, who reported it, initial description.
Notify the Incident Commander.
02

Containment

Limit the spread and impact of the incident.

Isolate affected systems from the network (disconnect from Wi-Fi/LAN — do NOT power off unless instructed).
Disable compromised user accounts.
Block malicious IP addresses or domains at the firewall.
Preserve evidence — take screenshots, save logs, document everything.
Notify affected staff not to use compromised systems.
03

Eradication

Remove the threat from your environment.

Identify the root cause of the incident.
Remove malware, close vulnerabilities, and patch affected systems.
Reset all potentially compromised credentials.
Verify that the threat has been fully removed before proceeding.
04

Recovery

Restore systems and resume normal operations.

Restore systems from clean, verified backups.
Monitor restored systems closely for 48–72 hours for signs of re-infection.
Gradually reconnect systems to the network.
Confirm business operations have returned to normal.
05

Notification

Fulfil legal and ethical notification obligations.

Assess whether personal information was compromised (POPIA obligation).
If personal data was breached, notify the Information Regulator as soon as reasonably possible.
Notify affected data subjects (customers, staff) if their information was compromised.
Notify cyber insurance provider.
Prepare internal communication for staff.
06

Post-Incident Review

Learn from the incident to prevent recurrence.

Conduct a post-incident review within 5 business days.
Document: what happened, how it was detected, how it was resolved, and how long it took.
Identify gaps in controls, processes, or training that allowed the incident to occur.
Update this IRP based on lessons learned.
Implement corrective actions with assigned owners and deadlines.

This template is provided by Synaptic Technologies as a starting point. Customise it to reflect your organisation's specific environment, systems, and legal obligations. Contact us at [email protected] for assistance implementing your IRP.

Need Help Building Your IRP?

Our team can help you develop, test, and implement a full Incident Response Plan tailored to your business.

Contact Us