Incident Response
Develop and Exercise an Incident Response Plan
Start with an accessible one-page plan and a discussion exercise your team can run without new software.
Content review: 2026-09-30 · Estimated effort: Medium
Priority and effort are editorial starting points, not calculated risk or mandatory deadlines. Adapt to business impact, vendor instructions, available licenses, and applicable obligations. Test changes before broad rollout.
Before you start
Before starting: agree who can declare an incident, approve disruption, and contact your IT provider, insurer, legal adviser, or qualified response support.
Put it into practice
- Create a one-page plan with primary and backup owners, critical services, and a communication method that works when business email is unavailable. One person can hold multiple roles.
- Document how staff report incidents and who triages them. For a Microsoft 365 account concern, identify in advance who can review sign-ins, revoke sessions, reset credentials, inspect forwarding rules and app consent, and preserve relevant records. Available views and actions depend on roles, configuration, and licenses.
- Include containment, evidence preservation, recovery decisions, and who determines notification obligations. Seek qualified help before wiping systems; no single reporting deadline applies everywhere. A worksheet and spoken rehearsal need no new software subscription.
- Keep an accessible protected copy. Review after incidents, exercises, and important business changes, and schedule a regular rehearsal.
- Verify: run a clearly announced one-hour discussion exercise using the fictional scenario below. Check roles, an out-of-band contact route, evidence ownership, and recovery prerequisites. Do not disable accounts or revoke sessions during this discussion exercise.
Fictional one-hour discussion: a compromised Microsoft 365 account
An invented small team receives a report that an employee's mailbox sent an unexpected invoice request. This is a tabletop, not a real incident, lab result, or instruction to change a live account.
- 0–10 minutes: announce the exercise, name a facilitator and note-taker, and confirm the alternate contact route and who may declare an incident.
- 10–25 minutes: discuss what facts to gather and who may review available sign-in, mailbox forwarding, and app-consent records. Record missing permissions or unavailable logs rather than claiming visibility.
- 25–40 minutes: decide who would authorize containment, preserve evidence, contact the affected person through a trusted route, and assess business, legal, insurer, or customer notifications. Discuss account actions; do not perform them on a live account.
- 40–55 minutes: identify how the team would verify access has been secured, check for affected data or messages, and restore normal work with the business owner. Note what requires a licensed feature or outside help.
- 55–60 minutes: assign owners and dates to gaps in the worksheet. Keep the restricted plan accessible if business email or identity services fail. A discussion does not prove technical containment or recovery.
Make a start
Tools and templates
Start with what you already have. “Included” means part of an existing eligible product or subscription, not a free standalone service. Options reviewed 2026-09-30; check current vendor terms before choosing.
Start without another software subscription
Use the free CISA checklist and incident worksheet to assign roles, verify contacts and run a discussion exercise.
Where this stops: Templates do not supply emergency responders, recovery infrastructure or specialist support. Identify how those needs will be met before an incident.
See the official sources and eligibility details below. Free software can still require equipment, storage and staff time.
CISA ransomware response checklist
Free public guidance
Use the response checklist to discuss isolation, evidence preservation and recovery decisions, then fill in the local worksheet with your actual owners and contacts.
Limits: General guidance, not live incident support. Contact qualified responders when needed; do not wipe systems or run disruptive exercises without authorization.
Your information: Reading the guide requires no incident upload. Keep your completed contact worksheet restricted but accessible during an email outage.
Official instructions: CISA ransomware response checklist ↗Microsoft 365 compromised-account response guidance
Free instructions; available administrative actions and records depend on your tenant, roles, and licenses
During planning, use the official response sequence to identify who could investigate a mailbox, revoke access, review authentication methods, and inspect forwarding or app consent. Record unavailable capabilities as gaps.
Limits: The article is guidance, not an automated responder. Do not run live containment steps as part of a discussion exercise. Actual response may need qualified help and business approval.
Your information: Sign-in and mailbox records can contain personal and business information. Review them only with authorized access and store evidence in approved restricted locations, not on this website.
Official instructions: Microsoft 365 compromised-account response guidance ↗Download a working template
Free to download and adapt for your team. Open CSV files in Microsoft Excel using your existing Office license; Markdown files open in a text editor such as Notepad. Save an Excel Workbook (.xlsx) copy if you add formatting. These are manual worksheets, with no macros, scoring or automatic verification.
- Incident response worksheet (Markdown) ↓
Open in a text editor or Markdown editor. Fill in roles and an out-of-band contact route, then run the clearly fictional account-compromise tabletop or email-outage discussion.
Fictional worked example
Illustration only. This is not a customer story, lab result, or evidence that your environment is protected. Replace the example entries and record your own observations.
In a clearly announced one-hour discussion, an invented Microsoft 365 mailbox appears to send an unexpected invoice request.
Use the Incident response worksheet template.
What to enter before testing
- Plan owner / backup
- Fill in the authorized coordinator and alternate
- Alternative route if email or identity services are unavailable
- Fill in an approved route independent of business email
- Who can declare an incident
- Fill in the role authorized to make this decision
- Account investigation and containment owner
- Name the authorized role; do not change a live account during this exercise
How to verify
Before the exercise, fill the worksheet’s real contact and authority sections. Discuss the fictional report, who can review available sign-in and mailbox records, who could approve containment, and how to preserve evidence and reach the affected person. Test only an approved alternate contact route with informed participants; record gaps and owners.
If the result is unexpected
If a contact is unreachable, a log is unavailable or authority is unclear, update the plan and rehearse that step again. Do not disable accounts, revoke sessions, simulate a real outage, or send an emergency alert to uninformed recipients. A discussion does not prove technical containment or recovery.
Save completed worksheets privately. They can describe security gaps, systems and people. Do not include passwords, recovery keys or confidential message content. This site does not receive your edits; a cloud editor or synced folder may send them to its provider.
Sources and review approach
Original small-team guidance with selected NIST CSF 2.0 alignments, not an official crosswalk or a complete framework implementation. These instructions are a starting point, not a claim of testing in your environment.
- NIST CSF 2.0: GV.RR, ID.IM-04: roles and maintained plans
- NIST CSF 2.0: RS.MA-01: executing a plan, not documentation alone
- https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20 ↗
- https://csrc.nist.gov/pubs/sp/800/61/r3/final ↗
- https://learn.microsoft.com/en-us/defender-office-365/responding-to-a-compromised-email-account ↗
- https://www.cisa.gov/news-events/news/take-first-steps-towards-better-cybersecurity-these-four-goals ↗