Your incident response plan
How the incident response plan is written from your real setup, what the green and amber dots mean, what a commitment is, and how to attest the plan.
Almost every cyber insurer, and every NIS2 supervisor, asks the same question early: do you have an incident response plan? Govern → Incident response plan writes one for you from how your organisation is actually set up — who gets told, what the platform can contain, which controls are in place today — and keeps it honest as your setup changes.
The plan is a draft until you attest it. Nothing on this page is sent to your insurer, your regulator or anybody else. You read it, you correct what is wrong, you put your name to it, and then you print it or save it as a PDF and send it yourself.
What the plan is written from
Only facts the platform already holds about your organisation. There is no questionnaire to fill in first.
| Section | Written from |
|---|---|
| Scope | Your organisation's name and the number of user accounts. |
| Who to contact | The escalation contacts you gave during first-run, with their response time. If there are none, the plan says incidents go to your administrators. |
| How incidents are detected | The modules on your plan (sign-ins, devices, logs, privileged access) and whether Sentinel-Q investigates alerts. |
| How incidents are contained | What containment can actually do in your tenant: signing a person out everywhere, isolating a device (only if an isolation action is configured) and ending privileged sessions. If you have opted in to automatic containment for any severity, the plan also lists those severities, but that opt-in has no effect today: a platform-wide safety ceiling holds every containment plan at recommend, so every containment plan waits for a person, whatever your plan or settings. Read a sentence saying automatic containment is switched on as the setting you chose, not as something that will happen. |
| Controls in place | The newest posture assessment: up to twelve authentication, access-policy, privilege, logging, device and account-hygiene checks, failing ones first. |
| Who must be notified | Your NIS2 reporting profile: whether you recorded yourself as an essential or important entity, and your CSIRT. |
| Recovery and review | Platform wording, always labelled as commitments. |
On a paid plan, Sentinel-Q writes the text from those facts and every sentence is checked against them before you see it. A sentence that names a person, a date, a number, an address or a link that is not in your records is thrown away and the platform's own wording is shown for that section instead. On the Free plan the platform's wording is used throughout, with no AI involved; the facts and the measured dots are the same.
Green dots, amber dots and commitments
- Green dot
- The sentence is bound to a posture check and the check is passing. Hovering shows when it was measured and the check id, for example
ZQ-M365-AUTH-001. - Amber dot
- The sentence is bound to a check that is failing today. The plan still says what the check is, and a How to fix link takes you to your posture report. Fix the finding, re-run the assessment, and the dot turns green.
- No dot, labelled commitment, not measured
- A promise the platform cannot measure. It is still part of your plan, and an insurer may ask you to show that you keep it.
- No dot, no label
- A plain fact about your setup, such as the number of accounts or who is contacted.
The platform, not the AI, decides which sentences are measured. The model can only attach a sentence to a check from the list it was given, and the status shown is always the one the check recorded.
When your setup changes
Every bound sentence is re-evaluated against your newest assessment once a day, and again every time you open the page. If a control that was passing starts failing, its sentence turns amber and a notice at the top of the page says how many measured controls changed since the plan was written. The text is not rewritten behind your back: redraft the plan when the change is large enough that the words no longer fit.
Attesting the plan
Read every section
Check the contacts first: they are the part most often out of date. If a sentence is wrong, fix the fact in the product (an escalation contact, your NIS2 profile) and redraft, rather than editing around it.
Choose Attest plan
Enter your name as it should appear on the plan and how long the attestation is valid, between 1 and 24 months. Insurers usually want a plan reviewed in the last 12 months, which is the default.
Print or save it as a PDF
The footer carries the records hash, a fingerprint of the facts the plan was written from. Two plans written from the same records show the same hash.
Attesting records your name, the time and the expiry. It does not send anything. When you attest a newer draft, it replaces the previous attested plan; until then, the previous one stays in force and the page says so. An evidence pack that shows the plan describes it as attested by you, never as measured.
What to read next
- Evidence-bound drafts — how every drafted document is checked, and why nothing is ever sent automatically.
- Reporting an incident under NIS2 — the deadlines the notification section refers to.
- Re-running the assessment and tracking drift — how to turn an amber dot green.