surable

Incident response plan (IRP)

Also called: IR plan

In one sentence

A written playbook for what to do when a breach hits: who to call, how to contain it, how to recover.

An incident response plan names roles, contains contact numbers (including your carrier's hotline), and lays out the first steps to isolate systems, preserve evidence, notify the right people, and restore from backups. In a real incident the first hours decide the cost.

Why it's on your cyber insurance application

A written AND tested IR plan is a hard requirement on most applications; untested plans are treated as shelfware.

How the Readiness Check scores it

The free Check asks the same question a carrier will. Here it is, why it's asked, and the fix if today's honest answer is no. The full application question list has the rest.

Incident response

Do you have a written incident response plan?

Why carriers ask: A written, tested incident response plan is a hard requirement on most applications. Untested plans are treated as no plan.

If the answer is no: Write the one-page version today (who to call, how to isolate, where backups are), then grow it into a full plan with the template.

The written evidence carriers accept

A “yes” on the application needs a document behind it. In the Readiness Pack, that document is:

Guides that cover this

Related terms

Would you pass this question today?

The free Readiness Check scores you across the ten control domains carriers probe, in five minutes, no email required for the score.

← All terms