NIST SP 800-61r3 Aligned · 7-Phase · PDF Download
Your Custom Incident Response Plan
8 inputs. A complete, regulation-aware IR plan built for your industry, size, and regulatory regime — with notification timelines, containment playbooks, and pre-populated contact trees.
HIPAA · CMMC · CJIS · GLBA · FERPA
OT/SCADA Aware
Pre-Populated Notification Timelines
Roles & Contact Tree
<\!-- Tool Wrap -->
<\!-- Step progress bar -->
<\!-- Step 1: Industry -->
Step 1 of 8
What Industry Are You In?
Selects industry-specific containment playbooks, threat actor profiles, and regulatory defaults.
HIPAA · TX HB 300
Hospitals, clinics, health systems, dental
CMMC · DIBNet
DIB primes, subs, DoD suppliers
CJIS · TX DIR
Cities, counties, state agencies, public safety
GLBA · NCUA · FFIEC
Financial / Credit Unions
✓
Banks, CUs, RIAs, insurance, mortgage
TSA Pipeline · CISA
Upstream/midstream/downstream, pipelines
AWIA · EPA · TCEQ
Community water systems, wastewater
NIST CSF · CISA
Industrial, process, discrete manufacturing
TX Eth. Op 712 · ABA
Law firms, legal services, title companies
FERPA · COPPA · CJIS
School districts, charter schools
NIST CSF
Retail, hospitality, technology, nonprofits
Continue →
<\!-- Step 2: Size -->
Step 2 of 8
Organization Size
Sets staffing assumptions for IR roles and scales severity response times.
Small org — lean IR team, vendor-dependent
Mid-market — partial IT staff, growing complexity
Enterprise-SMB — dedicated IT, IR team forming
Large enterprise — full IR program expected
← Back
Continue →
<\!-- Step 3: Regulatory Regime -->
Step 3 of 8
Regulatory Regime
Select all that apply. Notification deadlines, regulator contacts, and compliance-specific controls will be auto-inserted into your plan.
✓
HIPAA / HITECH
60-day breach notification · HHS OCR
✓
TX HB 300
60-day notification · TX AG · Patient data
✓
CMMC Level 1
FCI protection · Self-assessment
✓
CMMC Level 2
72-hr DIBNet · CUI protection · C3PAO
✓
CJIS v6.0
24-hr notification · FBI · CJI access revocation
✓
GLBA Safeguards
30-day FTC notification · Financial data
✓
NCUA 748 / IRPS 23-1
72-hr NCUA notification · Credit unions
✓
PCI DSS v4.0
Immediate card brand notification · CHD
✓
FERPA
ED notification · Student education records
✓
TSA Pipeline SD 2021-02C
12-hr CISA notification · OT/pipeline
✓
AWIA §2013 / EPA
EPA notification · Water sector
✓
TX SB 820
Ransomware reporting · State entities
None / Not Sure — Skip
← Back
Continue →
<\!-- Step 4: OT/SCADA -->
Step 4 of 8
OT / SCADA Exposure
Determines whether OT isolation steps, ICS air-gap procedures, and operational continuity sections are included.
IT-only environment, no industrial control systems
Some OT/ICS exposure, partial IT/OT convergence
SCADA/DCS/HMI central to operations, IT/OT converged
← Back
Continue →
<\!-- Step 5: IR Retainer Status -->
Step 5 of 8
Current IR Retainer Status
Sets escalation paths and fill-in-the-blank SOC contact fields in your plan.
Self-managed — internal IT handles incidents
IT MSP on retainer, not security-specialized
MSSP or IR firm on active retainer
Current Client
CoreRecon SOC on 24/7 retainer
← Back
Continue →
<\!-- Step 6: Insurance -->
Step 6 of 8 — Optional
Cyber Insurance Status
Optional but recommended. Carrier name is included in your IR plan's insurer-notification section.
✓
Active Policy
I have cyber insurance in force
✓
Pending / Shopping
In underwriting or renewal process
✓
No Policy
No cyber insurance currently
✓
Not Sure
Need to verify with broker
Carrier / Insurer Name (optional)
← Back
Continue →
<\!-- Step 7: Roles -->
Step 7 of 8 — Optional
Key Response Roles
Name + email are inserted into your plan's communication tree. All fields are optional — leave blank to use role placeholders.
← Back
Continue →
<\!-- Step 8: RTO/RPO -->
Step 8 of 8
Recovery Targets & Critical Systems
Used to populate the eradication & recovery phase, backup verification steps, and the severity matrix.
Recovery Time Objective (RTO)
Select target...
4 hours (critical ops)
8 hours (same day)
24 hours (next day)
48 hours (2 days)
72 hours (3 days)
1 week
Recovery Point Objective (RPO)
Select target...
1 hour (near-real-time backup)
4 hours
8 hours
24 hours (daily backup)
48 hours
1 week
Business-Critical Systems (optional)
List your most critical systems — these will be prioritized in the recovery section.
Organization Name
← Back
Generate My IR Plan →
<\!-- Email Gate -->
📋
Your IR Plan Is Ready
Enter your work email to receive your custom NIST 800-61r3 IR plan — including the PDF and a free IR retainer scoping call offer.
<\!-- Spinner -->
Building your custom IR plan…
<\!-- Plan Output -->
Phase 1: Govern
Phase 2: Prepare
Phase 3: Detect
Phase 4: Analyze
Phase 5: Contain
Phase 6: Eradicate & Recover
Phase 7: Post-Incident
Run This Plan in a Live Tabletop
Test your IR team against a custom ransomware scenario with injects, decision points, and comms templates.
Generate Tabletop Runbook →
<\!-- /ir-wrap -->
<\!-- Cross-link footer strip -->