Skip to content

Cyber Crisis Management Plan

Be ready to manage a major cyber incident, not just respond to it.

Plan Review

Against NIST SP 800-61 and ISO 27035

Tabletop Validation

Plan tested through realistic exercises

Board-Endorsed Plan

An executive-level crisis playbook

IR Leaders

Seasoned incident-response leads

Cyber Crisis Management Plan compliance and audit

What it is

A Cyber Crisis Management Plan is a documented, board-endorsed plan defining how an organisation detects, escalates, responds to and recovers from major cyber incidents. It assigns roles, decision authority, communication and regulatory-notification steps, and is validated through tabletop exercises.

Who must comply

Boards and executives, regulated entities (financial services, critical infrastructure, government suppliers) and any organisation needing to satisfy regulators, insurers or enterprise customers.

How IntelligenceX helps

CCMP development aligned to NIST, ISO 27035, ISO 22301 and CERT-In
Roles, RACI and escalation design with scenario playbooks
Regulatory-notification mapping
Tabletop exercise facilitation and after-action report
Crisis-communication and stakeholder-notification templates
Annual plan review and re-exercise cadence
Gap AssessmentISMS DesignInternal AuditStage 1 & 2 SupportRemediation GuidanceCertification Readiness

Frequently Asked Questions

An IR plan is the technical runbook for handling incidents. A CCMP is the broader executive-level crisis plan covering decision authority, board and regulator communication, legal/PR and business continuity.

By testing it. We facilitate a realistic tabletop exercise, capture gaps in an after-action report and refine the playbooks. A CCMP that has never been exercised is the most common failure we find.

At least annually, and after any major change to your business, systems or threat landscape. Each cycle we run a fresh tabletop, capture gaps and refine the playbooks so the plan stays current rather than becoming shelf-ware.

Talk to a security expert today

A penetration test, an audit, or 24/7 monitoring, our team is ready across the UK, USA, EU and India.