Answers · Security

Do I need a cyber incident plan?

The short answer

Yes. A short plan means that when something goes wrong, people know who to call, what to switch off and what to tell customers. Most larger firms have one: 75% of large UK businesses and 53% of medium ones have a formal plan. For a small firm, one page is enough.

What to put on one page

  • Who is in charge, and who stands in for them.
  • Phone numbers for your IT provider, your bank and your insurer.
  • What to switch off first, such as an email account that has been taken over.
  • Who tells customers and staff, and what they say.
  • Where your backups are, and how to get them back.
  • Where to write down what happened, and when.
UK businesses with a formal cyber incident plan, 2025. Source: DSIT, 2025

When you may need to report it

If personal data is involved, you may need to report the breach to the Information Commissioner's Office within 72 hours of finding it.

Test it once a year

Read it through with your team. Ask: if our email was taken over tomorrow, what would we do first? Fix whatever nobody knows. Keep a printed copy, because you may not be able to open your files during an attack. Xevrion's Security part keeps a one-page plan with your incidents.

Sources

  1. Cyber Security Breaches Survey 2025. Department for Science, Innovation and Technology. Published 2025.
  2. Incident management. National Cyber Security Centre. Published 19 September 2019.
  3. Report a breach. Information Commissioner's Office. Checked 4 October 2026.

Last checked: 4 October 2026.

See where your business stands.

Type your website address and get a score and the three fixes that matter most. Free, with no sign-up.