Clear roles · controlled action · reliable records
Free incident response card builder.
Prepare a practical first-hour card for the moments when facts are incomplete and time matters. Set the contacts, containment boundaries, records, communications and decisions your responders need to see.
Build the response cardFour editable starting points
Choose a scenario, then name the people who can act.
Use roles, group addresses or tested contact routes. If the printed card will contain personal or sensitive contact details, store it appropriately.
A calmer operating rhythm
One lead, one log and a visible next checkpoint.
The first hour is easier to manage when responders can distinguish facts from assumptions, understand who may authorise impact and know when the whole group will review new evidence.
Containment is a decision, not a reflex
Protect the business without destroying the investigation.
Observe
Capture time, source and scope. Keep fact, inference and unanswered question separate.
Contain
Use the smallest safe action, understand its impact and record who approved it.
Preserve
Do not casually wipe, rebuild or alter originals that may explain what happened.
Reassess
Check whether the action worked, whether the attacker reacted and what the next decision is.
Official incident guidance
Prepare the card before you need it.
NCSC guidance recommends key contacts, escalation criteria, decision authority, alternative communications, simple first-hours instructions and careful records. ICO guidance asks organisations to log personal-data breaches, contain them, assess risk and decide promptly whether notification is required.
First-hour questions
Make the next safe decision visible.
Should we switch off an affected computer immediately?
Not automatically. Disconnecting it from a network may sometimes limit spread, while powering it off can remove useful volatile evidence. Follow an authorised playbook or specialist instruction and put immediate safety first.
Does selecting personal data mean we must report to the ICO?
No. It starts an urgent assessment and records the awareness time. Under current UK guidance, notifiable personal-data breaches generally must be reported without undue delay and, where feasible, within 72 hours of awareness. The actual facts, risk, jurisdiction and sector rules determine the obligation.
Why use an alternative communication channel?
If email, identity, chat or phones are affected or monitored, using them can expose response decisions or leave the team unable to coordinate. Agree and test a suitable fallback before an incident.
Does completing the card mean the incident is contained?
No. The card tracks coordination actions. Containment and recovery need technical validation, continued monitoring, accountable decisions and a later review of what happened.
Need a response process you can rehearse?
Turn the card into tested incident operations.
ACA can help define escalation paths, technical playbooks, supplier contacts, recovery dependencies and exercises that fit the way your organisation operates.