# Incident response worksheet

Purposeful Security | Template version 1.1 | 2026-09-30

Free to download and adapt for your team. Open this Markdown file in a text editor. Fill in the blanks before an incident, keep a restricted copy available without business email, and review after exercises or changes. This worksheet is not a live response service or a complete incident response plan.

Never record passwords, recovery keys, customer records, or confidential incident evidence here. Use restricted references for evidence. Normal local/cloud folder and backup settings apply to copies you save.

## Owners and contacts

- Plan owner / backup: [fill in]
- Last review / next review: [fill in]
- Who can declare an incident: [fill in]
- Who can authorize containment or service interruption: [fill in]
- Who can authorize restoration: [fill in]
- IT provider / qualified response support and known phone number: [fill in]
- Legal / insurer / notification decision owner: [fill in]
- Primary internal reporting route: [fill in]
- Alternative route if email or identity services are unavailable: [fill in]
- How to verify a caller's identity: [fill in]
- Where the protected offline copy is available: [location reference]

## Critical services

| Service | Business owner | Acceptable outage/data loss | Recovery dependencies | Recovery procedure reference |
| --- | --- | --- | --- | --- |
| [service] | [owner] | [agree objectives] | [identity, network, supplier] | [restricted reference] |

## First report and decisions

- Time and timezone / reporter / reliable callback route: [fill in]
- What was observed and which services appear affected: [brief factual summary]
- What remains unknown: [fill in]
- Immediate safety or business impact: [fill in]
- Triage lead and next update time: [fill in]
- Containment decision, approver, scope, time and expected impact: [fill in]
- Evidence owner and protected evidence location: [reference only]
- External support contacted and agreed next steps: [fill in]
- Notification obligations assessed by / decision and rationale: [fill in]

Preserve evidence and seek qualified advice before wiping systems. Do not conduct unapproved scans, delete suspected files, or reconnect affected systems merely to test recovery.

## Recovery and follow-up

- Cause and scope understood sufficiently to restore safely: [decision owner / evidence reference]
- Backup integrity and restoration prerequisites checked: [result]
- Restoration approval / rollback criteria: [fill in]
- Business owner validation of restored service: [result and time]
- Monitoring and follow-up owner: [fill in]
- Lessons, corrective actions, owners and target dates: [fill in]

## Rehearse: fictional email outage

This is a discussion exercise, not a production shutdown. Business email becomes unavailable and staff cannot receive password-reset messages.

1. Find the alternative reporting route without using email.
2. Identify who may declare an incident and approve a disruption.
3. Explain how the team would reach the IT provider through a previously verified number.
4. Identify identity, backup and supplier dependencies needed for recovery.
5. Record missing contacts, unresolved decisions and improvements below. Do not mark a contact reachable unless you actually verified it through an authorized check.

| Gap or decision | Owner | Target date | Verification method | Actual result |
| --- | --- | --- | --- | --- |
| [fill in] | [fill in] | [fill in] | [fill in] | Not tested |

## Fictional one-hour account-compromise tabletop

This is a clearly announced discussion about an invented Microsoft 365 mailbox sending an unexpected invoice request. No real account or service changes are part of this exercise. Use invented names and messages. Invite the person who owns business decisions as well as the IT responder; one person may cover more than one role.

| Time | Discuss and record |
| --- | --- |
| 0–10 minutes | Name facilitator and note-taker. Confirm who receives reports, who can declare an incident, and how to contact the team without business email. |
| 10–25 minutes | Identify who could review sign-ins, mailbox forwarding and app consent, and what records are actually available under your roles and licenses. Mark unknowns as unknown. |
| 25–40 minutes | Discuss who could authorize account containment, protect evidence, reach the affected person through a trusted route, and decide whether outside response, legal, insurer or customer notification input is needed. Do not carry out account changes. |
| 40–55 minutes | Describe how the business owner and IT responder would decide whether access is secure, messages or data were affected, and normal work can resume. |
| 55–60 minutes | Assign each gap an owner, target date and verification method. Set a date to revisit the plan. |

Discussion prompts: Can an authorized responder reach the right administrator without the suspect mailbox? Who can approve a session revocation or password reset? Where would evidence be preserved? What is the fallback if a required log or administrator is unavailable? Follow current Microsoft instructions during a real event, with qualified help as needed; this worksheet is not an emergency playbook.

| Gap or decision | Owner | Target date | Verification method | Actual result |
| --- | --- | --- | --- | --- |
| [fill in] | [fill in] | [fill in] | [fill in] | Not tested |

Supporting guidance: https://www.cisa.gov/stopransomware/ransomware-guide
Microsoft account-response guidance: https://learn.microsoft.com/en-us/defender-office-365/responding-to-a-compromised-email-account
Related guide: https://purposefulsecurity.com/remediations/incident-response-plan
