Clear roles · controlled action · reliable records

Free incident response card builder.

Prepare a practical first-hour card for the moments when facts are incomplete and time matters. Set the contacts, containment boundaries, records, communications and decisions your responders need to see.

Build the response card

Four editable starting points

Choose a scenario, then name the people who can act.

Use roles, group addresses or tested contact routes. If the printed card will contain personal or sensitive contact details, store it appropriately.

01

Command details

Set the response frame

02Add the signals that need specialist routingSelect what may be involved. The card will add decisions; it will not decide reportability for you.

The card is assembled in your browser and is ready to copy or print.

A calmer operating rhythm

One lead, one log and a visible next checkpoint.

The first hour is easier to manage when responders can distinguish facts from assumptions, understand who may authorise impact and know when the whole group will review new evidence.

00
DeclareOpen the record and name the lead
15
TriageAvailability, confidentiality, integrity
60
CheckpointReview actions, evidence and decisions
FACTACTIONOWNERTIME

Containment is a decision, not a reflex

Protect the business without destroying the investigation.

Observe

Capture time, source and scope. Keep fact, inference and unanswered question separate.

Contain

Use the smallest safe action, understand its impact and record who approved it.

Preserve

Do not casually wipe, rebuild or alter originals that may explain what happened.

Reassess

Check whether the action worked, whether the attacker reacted and what the next decision is.

Official incident guidance

Prepare the card before you need it.

NCSC guidance recommends key contacts, escalation criteria, decision authority, alternative communications, simple first-hours instructions and careful records. ICO guidance asks organisations to log personal-data breaches, contain them, assess risk and decide promptly whether notification is required.

First-hour questions

Make the next safe decision visible.

Should we switch off an affected computer immediately?

Not automatically. Disconnecting it from a network may sometimes limit spread, while powering it off can remove useful volatile evidence. Follow an authorised playbook or specialist instruction and put immediate safety first.

Does selecting personal data mean we must report to the ICO?

No. It starts an urgent assessment and records the awareness time. Under current UK guidance, notifiable personal-data breaches generally must be reported without undue delay and, where feasible, within 72 hours of awareness. The actual facts, risk, jurisdiction and sector rules determine the obligation.

Why use an alternative communication channel?

If email, identity, chat or phones are affected or monitored, using them can expose response decisions or leave the team unable to coordinate. Agree and test a suitable fallback before an incident.

Does completing the card mean the incident is contained?

No. The card tracks coordination actions. Containment and recovery need technical validation, continued monitoring, accountable decisions and a later review of what happened.

Need a response process you can rehearse?

Turn the card into tested incident operations.

ACA can help define escalation paths, technical playbooks, supplier contacts, recovery dependencies and exercises that fit the way your organisation operates.

Explore managed IT support