ClearSecurity VISION
EN / RO
← All articles

Hardening · 10 July 2026 · 4 min read

A one-page incident response plan — write it today

In a crisis there's no time to invent the procedure. One page with the first 5 actions, who decides and who you call — plus the DNSC reporting deadlines if NIS2 applies to you.

ClearSecurity Vision

The first hours of an incident decide how much it costs you. And in those hours, the difference is not made by a 40-page manual nobody has read — it’s made by a single printed page that says who decides, who you call and what the first moves are. Encrypted files don’t leave you access to your procedures either, if they live only on the server.

This guide helps you write that page today. It is not a full continuity plan — it’s the minimum that turns panic into action.

What you need

  • One hour with the company’s decision-maker and whoever runs IT (in-house or the maintenance firm)
  • The critical contact list: IT, leadership, bank, lawyer, insurer (if you have a cyber policy)
  • A printer: the plan that exists only on the encrypted server does not exist

Step 1: write the first 5 actions

Adapted to your company, but in essence:

  1. Disconnect, don’t shut down. The affected computer comes off the network (cable out, Wi-Fi off) but stays on — its memory may hold traces that help the investigation.
  2. Alert the designated owner (see step 2) — immediately, at any hour. Better a false alarm than a lost day.
  3. Don’t pay and don’t negotiate anything on your own, don’t reply to the attacker — that decision belongs to informed leadership.
  4. Write everything down with timestamps: what was seen, when, by whom, what was done. A simple paper log is worth a great deal for the investigation and the reporting.
  5. Change critical passwords from a clean device — not from the possibly compromised computer: the admin email, the bank, access to central systems.

Step 2: who decides and who you call

The table on the page — four rows, no pompous titles:

  • Who leads the response (name, personal phone) and their stand-in for when they’re on holiday.
  • Who handles the technical side: in-house IT or the maintenance firm, with the emergency number and what your contract entitles you to ask of them.
  • Who speaks externally: to customers, the bank, the press if needed — one voice, so three versions don’t circulate.
  • The external numbers: the bank (to block payments), the lawyer, the insurer — and if NIS2 applies to you, the DNSC reporting channel.

Step 3: the reporting deadlines, if NIS2 applies

If your company is an essential or important entity under Romania’s transposition (GEO 155/2024), the clock starts when you become aware of the incident: early warning within 24 hours, full notification within 72 hours, final report within the legal deadline. The step-by-step details are in our DNSC reporting guide — keep the link (or a printout) next to the plan.

Step 4: tell your people

The plan only works if the incident reaches you fast:

  1. One message, repeated clearly: “anything suspicious gets reported to X immediately — no blame, even if you clicked the link.” Fear of punishment is the number-one reason incidents surface late.
  2. Print the plan and keep it in two known places (one outside the office). Save a copy on the decision-maker’s personal phone too.

Verify the result

  • The 15-minute test, once a year: gather the key people and play a scenario — “it’s Monday, 8:40, the files on the server have strange extensions”. Who does what, in what order? Fix the gaps you find on the page, on the spot. (A light warm-up: our game “The first 30 days” — 3 minutes, no account.)
  • Call the numbers on the plan: do they still answer? Does the IT contact still work there?

Common mistakes

  • The novel-length plan. 40 pages written for the auditor, zero usable at 3 a.m. One page that gets written beats a manual that gets postponed.
  • Everything on the server. The incident that encrypts your server encrypts your incident response procedure with it. Paper + a copy on a phone.
  • One person who knows everything. That’s exactly who’s on holiday. Every role has a written stand-in.
  • Employees punished for reporting. After the first sanction, you’ll learn about the next incident from your customers.

The DNSC deadlines in step 3 only concern you if NIS2 applies — but the one-page plan is just as valuable with no law behind it.

newsletter

Get new articles by email.

NIS2 compliance, incident reporting and plain-language security — only when we publish something new. No spam, unsubscribe anytime.