Incident Response Plan (IRP) Template
A structured template to help South African businesses prepare for, respond to, and recover from cybersecurity incidents.
Synaptic Technologies · v1.0 · 2026
A cyberattack is not a matter of if — it is a matter of when. Having a documented Incident Response Plan (IRP) before an incident occurs dramatically reduces damage, recovery time, and reputational harm. This template provides a structured framework that any South African SME can adapt and implement.
Section 1: Plan Overview
Section 2: Incident Response Team
Define who is responsible for managing a cybersecurity incident. Ensure this list is accessible offline (printed copy) in case systems are compromised.
Incident Commander
Overall coordination and decision-making during the incident.
IT Lead / Technical Responder
Technical investigation, containment, and remediation.
Communications Lead
Internal and external communications, including staff, customers, and media.
Legal / Compliance Officer
Advises on legal obligations including POPIA breach notification.
Executive Sponsor
Senior leadership oversight and authorisation of major decisions.
Key External Contacts
Section 3: Incident Classification
Classify the severity of the incident to determine the appropriate response level.
P1 — Critical
Active ransomware, full system compromise, confirmed data breach affecting customers or staff. Business operations severely impacted.
Immediate escalation to Incident Commander. All hands on deck. Consider isolating affected systems immediately.
P2 — High
Suspected breach, malware detected, significant data loss, or a single critical system compromised.
Escalate to IT Lead and Incident Commander within 1 hour. Begin containment.
P3 — Medium
Phishing email clicked, suspicious login detected, minor malware on a single device.
IT Lead to investigate within 4 hours. Monitor and contain.
P4 — Low
Spam campaign, failed login attempts, minor policy violation.
Log the incident. IT Lead to review within 24 hours.
Section 4: Response Phases
Identification
Detect and confirm that a security incident has occurred.
Containment
Limit the spread and impact of the incident.
Eradication
Remove the threat from your environment.
Recovery
Restore systems and resume normal operations.
Notification
Fulfil legal and ethical notification obligations.
Post-Incident Review
Learn from the incident to prevent recurrence.
This template is provided by Synaptic Technologies as a starting point. Customise it to reflect your organisation's specific environment, systems, and legal obligations. Contact us at [email protected] for assistance implementing your IRP.
Need Help Building Your IRP?
Our team can help you develop, test, and implement a full Incident Response Plan tailored to your business.
Contact Us