An incident response plan your people have rehearsed, with ransomware playbooks, decision rights and a tested tabletop exercise.
Make sure that when a serious incident happens — ransomware, data breach, business email compromise — the organisation knows who decides what, how to contain it, when to notify regulators and customers, and how to recover, because it has practised.
The plan follows our delivery framework. Steps that do not apply to this kind of work are left out rather than padded.
What you keep at the end.
What it is built to change.