Home/Documentation/Programme-level documentation
Incident Response & Business Continuity Programme
An incident response plan with scenario playbooks, and a business continuity plan with impact analysis and recovery procedures, written to work together.
What this set does
The plan you write before an incident is the one you will follow during it. This programme covers detection through post-incident review (NIST SP 800-61 R3 structure), with playbooks for the incidents most organisations actually face, and a continuity plan that picks up where containment ends.
What's inside
- Incident response policy, plan and severity classification
- Playbooks: ransomware, business email compromise, data breach, insider misuse, DDoS, supplier compromise
- Regulatory notification matrix (UK GDPR, EU GDPR, NIS2, DORA, SEC) with template notices
- Communications plan and holding statements
- Business impact analysis workbook
- Business continuity and IT disaster recovery plans
- Tabletop exercise pack with three scenarios and scoring
- Post-incident review template
Who it is for
Organisations that need a plan an auditor will accept and a team can actually run at 2am.
How the documents are structured
Every document opens with its purpose, scope and owner, then the substantive content, then a control cross-reference showing which framework requirements it satisfies. Standards state requirements in testable language ("must", with the parameter). Procedures follow one format: trigger, roles, steps, frequency, records produced. Placeholders are limited to things only you can know: organisation name (which we fill in), system names, role titles, tool names and timelines. There are no "[insert policy here]" sections.
Tailoring effort
Expect to spend a few hours on a policies-and-standards set and longer on procedures, because procedures describe how your team actually works. The document register in each set lists every file with a suggested owner so you can split the work.
Included in these bundles
- ISO 27001 Certification Bundle — £1,595
- NIST 800-171 & CMMC Level 2 Bundle — £1,995
- EU Resilience Bundle (NIS2, DORA, GDPR) — £1,595
Licence
One purchase covers one organisation for internal use, with unlimited users and unlimited edits. Consultancies and MSPs tailoring documents for clients need the multi-client licence; see the terms or ask us.
Related products
Policies & Standards — ISO/IEC 27001:2022
A complete policy and standards set structured to the 93 Annex A controls of ISO/IEC 27002:2022, plus the clause 4–10 management-system requirements.
£495 · 41 documentsPolicies & Standards — NIST CSF 2.0
Policies and standards organised by the six CSF 2.0 functions, with standards written at the subcategory level so each one is auditable.
£445 · 36 documentsPolicies & Standards — NIST SP 800-53 R5 (Moderate)
Family-by-family policies and control-level standards for the moderate baseline, written to satisfy the -1 policy-and-procedure control in each family.
£695 · 48 documents