A security incident can interrupt donations, expose sensitive records, or lock staff out of essential systems. In the middle of a disruption, people need clear instructions—not a scramble to decide who is in charge. A written incident response plan gives your nonprofit a practical starting point. Document the people who make decisions, the steps for communicating safely, and the services to restore first. Keep the plan accessible when your usual email, files, or network are unavailable.
Assign Clear Roles
Name an incident lead who can coordinate the response and make time-sensitive decisions. List a backup in case the lead is unavailable. Assign specific responsibilities for technical investigation, legal or privacy review, staff communications, and operational recovery. One person may cover several roles in a small organization, but write down each duty so nothing is left to assumption.
Include current contact details for staff, leadership, your IT provider, cyber insurance contact, legal counsel, and other relevant vendors. Note who has authority to shut down systems, approve outside support, or notify affected people. Review this list regularly, and store a copy somewhere staff can reach without logging in to the systems that may be compromised.
Set Communication Steps
Specify how staff should report a suspected incident and what details to provide, such as when it began, which device or account is affected, and what unusual activity they noticed. Tell employees not to delete evidence, forward suspicious messages, or investigate on their own. Give them a backup reporting method, such as a phone number, in case email or chat is unavailable.
Choose an out-of-band channel for response coordination, separate from the systems under investigation. Define who can send updates to staff, board members, donors, service providers, and the public. Before contacting anyone about exposed information, have the incident lead coordinate with legal counsel and follow applicable reporting requirements. Prepare brief message templates, but verify facts before sending them.
Prioritize Recovery
List the systems and services your organization needs to deliver its mission, such as donor records, payment processing, case management, email, and shared files. For each one, identify the business owner, technical contact, backup location, and dependencies. Rank services by the harm an outage would cause—not simply by how visible or convenient each system is.
Document how to restore systems from clean, tested backups, including who can access them and where recovery instructions are stored. Note which accounts need password resets or stronger authentication, and how to confirm a restored system is safe before staff use it. Keep recovery steps realistic for your team and available support; do not rely on credentials or instructions saved only in a potentially affected account.
Practice and Update the Plan
A plan works best when people know where to find it and what their responsibilities are. Walk through a realistic scenario, such as a compromised staff mailbox or unavailable donor database. Ask each role holder what they would do first, which contact they would use, and what decisions need leadership approval. Record confusing steps and revise the plan after the exercise.
Update the document when staff, vendors, systems, or contact details change, and after an actual incident. Keep a dated copy in a secure location that authorized responders can reach offline. Limit access to sensitive details, but make sure the people expected to act can find the plan quickly. A short, current guide is more useful than a detailed document no one can use under pressure.
A useful incident response plan names decision-makers, provides safe communication routes, and sets a mission-focused recovery order. Start with those essentials, confirm that backups and contacts are accessible, and test the instructions with your team. Cape Fear Cyber can help your nonprofit review its response planning and identify practical next steps.