Key Takeaway: An incident response plan that exists only as a document is not an incident response plan. It is a liability. The plan that works is the one your team has practiced, your clients know about, and your vendors are already contracted to support before the breach happens.
Every MSP will face a security incident. The question is not whether it happens but whether you are ready when it does. The MSP that has a tested incident response plan contains breaches faster, recovers clients more completely, and retains those clients after the incident. The MSP that improvises loses clients, faces regulatory exposure, and spends weeks in reactive chaos that could have been avoided.
This guide covers what an MSP incident response plan needs to include, how to build one that actually works, and how to use the IR planning process as a client advisory service.
Why Most MSP Incident Response Plans Fail
They exist as documents, not as practiced processes. An IR plan that lives in a folder and has never been tested is a false sense of security. When an actual incident happens, people do not remember what the document says. They do what feels right in the moment, which is usually wrong.
The plans that work are the ones that have been walked through in tabletop exercises, where the team has practiced the decisions they will need to make under pressure. The team that has rehearsed the ransomware scenario knows who calls the cyber insurance carrier, who notifies the client, who isolates the affected systems, and who contacts the IR firm. The team that has not rehearsed it figures all of that out while the clock is running and the damage is growing.
According to IBM’s 2025 Cost of a Data Breach Report, organizations with a tested incident response plan and a dedicated IR team contain breaches 54 days faster than those without one. At an average breach cost of $4.88 million, that containment speed translates directly to financial outcome.
The Six Phases of Incident Response
Preparation. Everything that happens before an incident. This includes the IR plan itself, the contact list for vendors and carriers, the communication templates, the forensic tools staged and ready, and the tabletop exercises that test whether the plan works. Preparation is the phase most MSPs skip or do incompletely.
Identification. Determining that an incident has actually occurred and understanding its scope. Not every alert is an incident. Not every anomaly is a breach. The identification phase involves triaging alerts, correlating events across systems, and making the determination that something real is happening. This requires the SIEM and EDR data that a SOC function provides.
Containment. Stopping the spread. Short-term containment means isolating affected systems immediately, even if that means taking them offline. Long-term containment means understanding how the attacker got in and closing that path while keeping the business running on unaffected systems. Containment decisions made too slowly allow ransomware to spread to additional systems. Containment decisions made too aggressively can destroy forensic evidence needed to understand the attack.
Eradication. Removing the threat from the environment. This means identifying every system the attacker touched, every credential that may have been compromised, every backdoor that may have been installed. Eradication that misses a persistence mechanism means the attacker comes back. This phase requires forensic capability that most MSPs do not have in-house, which is why IR firm retainers matter.
Recovery. Restoring systems and returning to normal operations. This is where the backup and disaster recovery investment pays off. The MSP that has tested restores, documented recovery time objectives, and clean backup copies recovers in hours. The MSP that has never tested a restore discovers during recovery that the backups are corrupted or incomplete.
Lessons learned. The post-incident review that most MSPs skip because they are exhausted and relieved it is over. This is the phase that prevents the next incident. What was the initial access vector? What detection gaps allowed the attacker to dwell undetected? What containment decisions were wrong? What would you do differently? The answers to these questions are the most valuable output of the entire incident.
What Your IR Plan Must Include
Roles and responsibilities. Who is the incident commander? Who handles client communication? Who contacts the cyber insurance carrier? Who engages the IR firm? Who talks to law enforcement if required? These decisions made in advance prevent the paralysis that happens when everyone is looking at each other during an active incident.
Contact lists. Cyber insurance carrier and claim hotline. IR firm retainer contact. Legal counsel. Law enforcement contacts (FBI IC3, CISA). Key client contacts. Vendor emergency lines for your critical tools. These contacts need to be accessible offline because the incident may have compromised your systems.
Communication templates. Pre-written client notification templates for different incident types. A ransomware notification is different from a data breach notification. Having templates ready means you are not writing communications under pressure while also managing the technical response. It also means your communications are reviewed and legally appropriate before the incident, not drafted in panic during one.
Playbooks for common scenarios. Ransomware. Business email compromise. Credential stuffing. Insider threat. Each scenario has a different response sequence. A ransomware playbook tells the team exactly what to do in what order: isolate affected systems, preserve forensic images, contact IR firm, notify cyber insurance, assess backup integrity, begin recovery planning. The playbook removes decision-making from a situation where decision-making is impaired by stress.
Evidence preservation procedures. What to capture before you start remediation. System images, memory dumps, log files, network captures. Evidence destroyed during hasty remediation cannot be recovered. It may be needed for insurance claims, regulatory investigations, or legal proceedings.
The IR Firm Retainer
Most MSPs cannot handle a serious incident alone. Forensic investigation, malware analysis, and complex recovery require specialized skills and tools that are not part of a standard MSP operation. The IR firm retainer means you have a relationship with specialists before you need them, not a frantic search for help while an incident is active.
Cyber insurance carriers increasingly require documented IR firm relationships as part of the underwriting process. The retainer also typically reduces the hourly rate when you engage the firm during an incident, which matters when IR engagements can run $300 to $500 per hour for senior analysts.
The retainer conversation with clients is also a service opportunity. Helping clients establish their own IR firm relationships, or including IR firm access as part of your security service tier, is a differentiator that most MSPs have not built.
Tabletop Exercises
A tabletop exercise is a structured discussion of a simulated incident scenario. The facilitator presents a scenario: ransomware has encrypted three servers and is spreading. The team walks through their response decisions in real time. Who does what? In what order? What information do you need that you do not have? Where does the plan break down?
Tabletop exercises reveal gaps that document reviews never find. The contact list that has an outdated phone number. The backup that nobody has tested. The client notification process that requires a system that is now offline. The team member who does not know their role. These gaps are cheap to find in a tabletop. They are expensive to find during an actual incident.
Run a tabletop exercise at least annually. Run one after any significant change to your environment or your client base. Run one after any actual incident, using the real scenario as the exercise.
Using IR Planning as a Client Service
Every client needs an incident response plan. Most do not have one. The MSP that helps clients build their IR plan, conduct tabletop exercises, and establish IR firm relationships is delivering advisory value that goes beyond keeping systems running.
The IR planning engagement also surfaces gaps in the client’s security posture. The client who cannot answer “where are your backups and when were they last tested?” during an IR planning session has a backup problem that needs to be addressed before an incident, not during one.
Cyber insurance carriers now require documented IR plans as part of the underwriting process. Helping clients build and maintain their IR plan is a service that directly supports their insurability. That is a concrete, measurable value that clients understand.
Frequently Asked Questions
What is the first thing to do when you suspect a security incident?
Do not panic and do not start remediating immediately. First, confirm that an incident is actually occurring. Then preserve evidence before you start making changes. Then follow your containment playbook. The instinct to immediately wipe and rebuild destroys forensic evidence and may not remove the attacker’s persistence mechanisms.
Should I pay a ransomware demand?
This is a legal and business decision, not a technical one. Contact your cyber insurance carrier and legal counsel before making any payment decision. Paying does not guarantee decryption. It funds future attacks. It may violate OFAC sanctions if the attacker is a sanctioned entity. The decision requires legal and insurance guidance, not just a technical assessment.
When do I need to notify clients of a breach?
Notification requirements depend on the type of data involved and the applicable regulations (state breach notification laws, HIPAA, PCI DSS, GDPR). Legal counsel should be involved in notification decisions. Most state laws require notification within 30 to 72 hours of discovering a breach involving personal information. Do not delay notification to avoid embarrassment. Late notification compounds the damage.
How long does incident response take?
Containment of an active incident typically takes hours to days. Full eradication and recovery can take weeks for a serious ransomware incident. The IBM data shows the average breach lifecycle (from initial access to containment) is 258 days for breaches that are not detected by the organization’s own security team. Early detection through SOC capabilities dramatically compresses that timeline.
What is the difference between incident response and disaster recovery?
Incident response addresses security incidents: breaches, ransomware, data theft. Disaster recovery addresses operational failures: hardware failure, natural disaster, power outage. They overlap in the recovery phase but have different triggers, different processes, and different teams. Both require documented plans and tested procedures.
Sources
- IBM Cost of a Data Breach Report 2025
- CISA Incident Response Resources
- NIST Cybersecurity Framework
- SANS Incident Handler’s Handbook
Related Reading: Cyber Insurance Requirements 2026 | NOC vs SOC | Backup Is Not Business Continuity | MSP Attestation Letters | MSP Cybersecurity Hub