← Back to Blog Cybersecurity

Cybersecurity Incident Response — A Practical Plan for Your Business

Published: 5 June 2026 | Updated: 20 July 2026 | CT Bedfordview
Security operations center monitoring dashboard showing cybersecurity threat detection Security Operations Center dashboard with threat detection alerts and response workflows

No business is immune to cyber incidents. Whether it's a phishing attack, ransomware, a data breach, or an insider threat, how you respond in the first hours determines the outcome.

What Is an Incident Response Plan?

An incident response plan is a documented set of procedures to detect, contain, and recover from cybersecurity incidents. It ensures your team knows exactly what to do when something goes wrong — no panic, no guesswork.

The 6-Step Incident Response Framework

1. Preparation

Before an incident happens:

2. Detection

How do you know you've been hit? Common indicators:

3. Containment

Stop the incident from spreading:

4. Eradication

Remove the threat:

5. Recovery

Get back to business:

6. Lessons Learned

After the dust settles:

POPIA Breach Notification

Under POPIA, you must notify the Information Regulator within 72 hours of becoming aware of a data breach that poses a risk to data subjects. Your incident response plan should include:

Common Incident Scenarios

It's helpful to plan for specific scenarios your business is likely to face. The most common incidents affecting SA SMBs include ransomware attacks, business email compromise (where attackers trick staff into fraudulent payments), and phishing attacks that compromise user credentials. Each scenario requires a slightly different response — your plan should cover the most relevant threats to your business.

Tabletop Exercises

A tabletop exercise is a simulated incident where your team walks through the response plan verbally. Run these at least twice a year. Example scenario: "Your finance manager receives an email that appears to be from the CEO, requesting an urgent payment of R450,000 to a new supplier. The email address is one character different from the real CEO's address." Walk through who gets notified, how the request is verified, and what steps are taken. These exercises reveal gaps in your plan before a real incident exposes them.

Incident Response FAQ

Q: How long does it take to build an incident response plan?

A: A basic plan can be documented in a day. A comprehensive, tested plan typically takes 2–4 weeks including stakeholder input, documentation, and initial tabletop testing. CT Bedfordview can help you build and test your plan as part of our managed security service.

Q: Do I need cyber insurance?

A: Yes. Cyber insurance covers the costs of incident response (forensics, legal, notification) and may cover ransom payments and business interruption losses. Most insurers now require you to have an incident response plan in place before issuing a policy, so building your plan is a prerequisite for getting covered.

Need help building an incident response plan for your business? CT Bedfordview can guide you through the process and help you prepare. Get in touch.