Skip to main content

Your incident response plan

How the incident response plan is written from your real setup, what the green and amber dots mean, what a commitment is, and how to attest the plan.

Written for the business owner8 min readUpdated

Almost every cyber insurer, and every NIS2 supervisor, asks the same question early: do you have an incident response plan? Govern → Incident response plan writes one for you from how your organisation is actually set up — who gets told, what the platform can contain, which controls are in place today — and keeps it honest as your setup changes.

The plan is a draft until you attest it. Nothing on this page is sent to your insurer, your regulator or anybody else. You read it, you correct what is wrong, you put your name to it, and then you print it or save it as a PDF and send it yourself.

What the plan is written from

Only facts the platform already holds about your organisation. There is no questionnaire to fill in first.

The sources of each part of the plan.
SectionWritten from
ScopeYour organisation's name and the number of user accounts.
Who to contactThe escalation contacts you gave during first-run, with their response time. If there are none, the plan says incidents go to your administrators.
How incidents are detectedThe modules on your plan (sign-ins, devices, logs, privileged access) and whether Sentinel-Q investigates alerts.
How incidents are containedWhat containment can actually do in your tenant: signing a person out everywhere, isolating a device (only if an isolation action is configured) and ending privileged sessions. If you have opted in to automatic containment for any severity, the plan also lists those severities, but that opt-in has no effect today: a platform-wide safety ceiling holds every containment plan at recommend, so every containment plan waits for a person, whatever your plan or settings. Read a sentence saying automatic containment is switched on as the setting you chose, not as something that will happen.
Controls in placeThe newest posture assessment: up to twelve authentication, access-policy, privilege, logging, device and account-hygiene checks, failing ones first.
Who must be notifiedYour NIS2 reporting profile: whether you recorded yourself as an essential or important entity, and your CSIRT.
Recovery and reviewPlatform wording, always labelled as commitments.

On a paid plan, Sentinel-Q writes the text from those facts and every sentence is checked against them before you see it. A sentence that names a person, a date, a number, an address or a link that is not in your records is thrown away and the platform's own wording is shown for that section instead. On the Free plan the platform's wording is used throughout, with no AI involved; the facts and the measured dots are the same.

Green dots, amber dots and commitments

Green dot
The sentence is bound to a posture check and the check is passing. Hovering shows when it was measured and the check id, for example ZQ-M365-AUTH-001.
Amber dot
The sentence is bound to a check that is failing today. The plan still says what the check is, and a How to fix link takes you to your posture report. Fix the finding, re-run the assessment, and the dot turns green.
No dot, labelled commitment, not measured
A promise the platform cannot measure. It is still part of your plan, and an insurer may ask you to show that you keep it.
No dot, no label
A plain fact about your setup, such as the number of accounts or who is contacted.

The platform, not the AI, decides which sentences are measured. The model can only attach a sentence to a check from the list it was given, and the status shown is always the one the check recorded.

When your setup changes

Every bound sentence is re-evaluated against your newest assessment once a day, and again every time you open the page. If a control that was passing starts failing, its sentence turns amber and a notice at the top of the page says how many measured controls changed since the plan was written. The text is not rewritten behind your back: redraft the plan when the change is large enough that the words no longer fit.

Attesting the plan

  1. Read every section

    Check the contacts first: they are the part most often out of date. If a sentence is wrong, fix the fact in the product (an escalation contact, your NIS2 profile) and redraft, rather than editing around it.

  2. Choose Attest plan

    Enter your name as it should appear on the plan and how long the attestation is valid, between 1 and 24 months. Insurers usually want a plan reviewed in the last 12 months, which is the default.

  3. Print or save it as a PDF

    The footer carries the records hash, a fingerprint of the facts the plan was written from. Two plans written from the same records show the same hash.

Attesting records your name, the time and the expiry. It does not send anything. When you attest a newer draft, it replaces the previous attested plan; until then, the previous one stays in force and the page says so. An evidence pack that shows the plan describes it as attested by you, never as measured.

What to read next

  1. Evidence-bound drafts — how every drafted document is checked, and why nothing is ever sent automatically.
  2. Reporting an incident under NIS2 — the deadlines the notification section refers to.
  3. Re-running the assessment and tracking drift — how to turn an amber dot green.

Was this article wrong?

If a procedure here does not match what you see, or a limit we described has changed, tell us and we will fix the page. Email us about this article, or see how to get help if you need an answer rather than a correction.

Everything in compliance evidence