Incident Response
GovernancePart 4 of 4

From Plan to Practice: Making Incident Response Part of How You Operate

Making incident response part of how you operate.

4 min read

A one-page incident response plan is a strong start. It is also, on its own, incomplete. Plans go stale. Staff change. The named decision-maker leaves the organization and nobody updates the document. Six months later, the plan that once felt solid is quietly wrong, and nobody finds out until it is needed.

This final post in the series is about the practice of resilience, not just the document.

1
Test it
Tabletop exercises don't require a consultant.

A tabletop exercise is simply a conversation: someone describes a scenario, and the team talks through what they would actually do. "Your file server has ransomware on a Friday afternoon. What happens?" is enough to start.

These exercises reliably surface gaps that look fine on paper. The decision-maker named in the plan is on vacation and nobody knows the backup. The call list has a phone number for an insurance carrier the organization switched away from two years ago. None of this is a failure. It is exactly what the exercise is for, and finding it during a 30-minute conversation is far better than finding it during a real incident.

Why this matters
Running one of these twice a year, even informally over lunch, keeps the plan connected to reality.
2
Involve leadership
Your board or leadership needs a version of this too.

Given how many nonprofits and small businesses operate with a board or advisory group, resilience cannot live only with whoever handles IT. Boards carry fiduciary responsibility, and increasingly, cyber incidents are treated as a governance failure, not just a technical one, when things go badly.

Board involvement does not need to be technical. It needs to answer three questions: does the organization have a plan, has it been tested recently, and does the board know its own role if something happens.

Why this matters
A ten-minute update at a quarterly meeting is enough to keep this current.
3
Review annually
Insurance and legal review are not one-time events.

Cyber insurance policies change terms, and coverage that fit your organization two years ago may have gaps today. The same is true of your understanding of breach notification law, which varies by state and by the type of data involved, and which occasionally changes.

Why this matters
An annual review of your policy and your notification obligations, even a short one with your broker or an attorney, closes a gap that many organizations do not realize exists until they are filing a claim mid-incident and discovering their coverage does not match what they need.
4
Make it a habit
Resilience is a habit, not a document.

The organizations that recover well from incidents are rarely the ones with the most sophisticated tools. They are the ones that treated their plan as something to revisit, not something to file away. That habit costs almost nothing and pays off precisely when it matters most.

The organizations that recover well are rarely the ones with the most sophisticated tools. They are the ones that treated their plan as something to revisit.

What this series has covered

This closes the four-part arc of this series: the reality that incidents are not optional to prepare for, the timeline of what actually happens, a practical plan you can build in an afternoon, and now, the practice that keeps that plan alive. None of it requires a security department. It requires the decision, made now, that this is worth revisiting before you need it rather than after.

The four-week series at a glance
  • Week 1 Series Kickoff: You will be breached — why incident response isn't optional, even without a security budget.
  • Week 2 The Risk: The first 24 hours — what actually happens during a breach, hour by hour.
  • Week 3 Practical How-To: Build your one-page incident response plan in an afternoon.
  • Week 4 Governance: From plan to practice — making incident response part of how you operate.
The ask this week: Take one scenario — a ransomware note, a wire fraud email, a lost laptop — and talk it through with your team for ten minutes. That conversation is worth more than the plan sitting untested in a drawer.

Ready for a clearer picture of where you actually stand?

A 30-day Security Business Review gives you a clear picture of your highest-priority gaps and a practical roadmap you can act on. No enterprise complexity. No vendor pitches. Just defensible decisions.

Start a Conversation
Incident Response Governance Resilience Board Readiness Small Business Nonprofit