DEV Community

Hive80-lab
Hive80-lab

Posted on

The 3 questions your IR plan must answer in the first 30 minutes (free checklist)

If you're a founder, an office manager, or the one IT person for a 1–50 person team, your incident response plan probably doesn't exist. Most IR plans are written for organisations that already have a security team — and that's exactly the wrong default for small teams. You don't need a 40-page plan. You need to answer three questions fast, in order, when something goes wrong.

This is general guidance, not legal or regulatory advice — adapt everything to your own environment.

Question 1: What is actually happening?

Before you touch anything, write down what you observed, when, and on which machine. One incident log file, opened in the first five minutes. This isn't bureaucracy — it's the record you'll need for the vendor call, the insurance claim, and the post-mortem.

Guessing "it's probably ransomware" and acting on the guess is how encrypted backups get destroyed. Log first, conclude later.

Question 2: What do we disconnect first?

Containment beats eradication for speed. Your plan should name, in advance:

  • which machines get pulled off the network,
  • who is authorised to pull them,
  • and the one shared drive or cloud folder to freeze first.

If the answer lives in someone's head, it isn't a plan.

Question 3: Who says what, to whom?

The first 30 minutes are also a communications problem: staff need a one-line "what to do right now" message, and anything customer-facing waits until you have facts. Your plan should hold the message templates already written — because you will not write well under pressure.


That's the whole spine: log it, cut it, say it. Everything else — severity levels, playbooks, the tabletop exercise that makes it stick — is structure around those three answers.

Free checklist + full templates

Launch coupon HIVE-LAUNCH30 takes 30% off both paid kits until Sep 11 2026, 23:30 ACST (UTC+9:30).

We're Hive80 Lab — a small ops lab shipping honest, no-fluff security templates for teams with no security staff. Feedback and war stories welcome in the comments.

Top comments (1)

Some comments may only be visible to logged-in visitors. Sign in to view all comments.