A plan that saves lives: The Incident Response Management Plan
A plan that saves lives: The Incident Response Management Plan
"In a house fire, it makes a big difference that we know where the fire extinguisher is beforehand." The problem with IT security is that it's difficult to stay one step ahead of the attackers - because that's exactly what it's all about: hacker groups are working around the clock on new ways to launch cyber attacks. This sometimes makes it impossible to predict the next attack. This may read as if good IT security is impossible and that it should perhaps be left alone - but the exact opposite is the case.
IT experts know the market and can make very good predictions based on many analyses. This knowledge helps them to recognise attacks quickly and have the right solution ready. However, relying on this type of prevention is only advisable for experts who have a time machine. Unfortunately, it's in the nature of things that cybercriminals are always coming up with new ways to attack. Preparation is still possible: with an incident response management plan.
Time is very, very expensive
Time is very, very expensive
When it comes to cyber attacks, perfect preparation often makes the difference between millions or even a threat to your existence.
Why perfect preparation is necessary is demonstrated anew every year by the world of IT. Attacks on companies are increasing every day. Several billion euros in damage are caused every year, and the behaviour of professional hacker gangs is becoming increasingly perfidious. However, a study by the industry association Bitkom has revealed that only around a third of all companies in Germany are adequately protected against cyber attacks. There is often a lack of expertise, infrastructure or resources. This is precisely where our Incident Response Management Plan comes in. At the same time, however, 90% of companies stated that they had already experienced cyber attacks.
Know your cyber size
Like a business suit, we tailor the IRMP to your company. It is an individual prevention plan that not only defines responsibilities, but also analyses the circumstances of your company and, based on this, takes organisational and technical measures, defines communication guidelines and designs a suitable incident response model.

Our own presentation
Our IT experts are always up to date and have years of experience in dealing with cyber attacks. Together, we identify your assets worth protecting, your critical business processes and work with you to develop the perfect defence strategy. In doing so, we take recognised best practices and the latest industry standards into account.
The phases of an IRMP
An IRMP involves six phases, which may also overlap:
Phase 1 - Preparation
This phase 1 serves to prepare for a security incident. This phase is of essential importance. Strictly speaking, the creation of the incident response management plan already belongs in this phase 1.
Phase 2 - Identification
Phase 2 is used to identify a security incident. Ideally, the security incident is identified as early as possible via alerting by a SIEM or a SOC. False alarms are qualified in this phase.
Phase 3 - Containment and investigation (forensics)
After identification, the first step in phase 3 is to contain the attack as best as possible and then investigate it.
Phase 4 - Elimination
Phase 4 involves eliminating the malware and the known gateways and vulnerabilities
Phase 5 - Recovery
In phase 5, the reconstruction of the IT infrastructure can now begin.
Phase 6 - Post-Incident
Phase 6 concludes the security incident with a critical review and subsequent improvement of plans and processes.
An IRMP is therefore like drawing an emergency map for your company - only in the digital realm. Should an incident occur, countermeasures can be initiated immediately. This can make the difference between an "incident" and a "business interruption" and thus preserve the livelihoods of employees and the entire company. Before the data is deleted - let's put out the fire.

Philipp Lessig
Content Creator
Published on 17.05.2025
