A cyber incident or service outage may begin when an organization cannot easily reach its usual email, chat, or document-storage systems. This article suggests preparing an incident contact sheet before it is needed. The sheet is not a replacement for a full incident response plan. It is a short operational reference that helps people find the right contacts, channels, and escalation points under pressure.
Why prepare the sheet in advance?
CISA describes an incident response plan as a written document that clarifies roles and includes the key people needed during a crisis. The full plan can hold detailed procedures; the contact sheet can present the people and routes for reaching them in a compact format.
CISA recommends printing the plan and its associated contact list. In addition, CISA’s ransomware guidance recommends creating, maintaining, and regularly exercising a basic cyber incident-response plan and an associated communications plan. As this article’s practical template, keep one printed copy and one digitally stored copy outside the organization’s primary corporate environment, with access restricted to appropriate people.
Keeping a copy outside the primary environment does not mean sending sensitive information to personal accounts. The practical control recommended by this article is an approved backup channel that can be reached from outside company systems. Do not send passwords, access keys, or sensitive details through an unapproved personal email account. Use a telephone or other out-of-band channel, and verify the person’s identity through another trusted method. This is an editorial security control derived from the risk that corporate communication systems may be inaccessible; it is not a quoted CISA requirement and follows CISA’s advice to keep a printed contact list available.
What should the sheet contain?
Some of the categories below are based on roles and contact categories in CISA guidance. This article’s template adds other categories according to an organization’s dependencies, such as system owners and cloud and email providers. CISA’s ransomware guidance includes coordination and contact categories such as FBI points of contact, CISA, incident-response providers, insurers, and other response partners.
- Incident manager: coordinates the response and identifies who needs updates.
- Technical lead: owns or coordinates the relevant systems, networks, or technical evidence.
- Executive decision-maker: has authority to make business decisions during the incident.
- Legal or compliance adviser: helps assess legal and regulatory questions based on the facts.
- Communications lead: coordinates internal and external messages when needed.
- Cyber-insurance contact: the claims or incident contact identified in the policy.
- External incident-response provider: the contracted firm or specialist, if one exists.
- Critical technology providers: cloud, email, and hosting providers, along with system and backup owners.
- Law enforcement and relevant authorities: contacts identified and reviewed in advance.
- Critical business partners: parties that may need specific coordination to support services or customers.
For each contact, this template suggests recording the role, primary contact, backup contact, phone number, approved alternate channel, organization, working hours or on-call status, escalation trigger, last verified date, and identity-verification notes. These are template fields, not a general legal requirement.
Law enforcement and regional scope
CISA recommends meeting local law-enforcement contacts in advance rather than determining notification procedures during a crisis. Record the relevant agency, its reviewed contact route, any non-emergency number or approved channel, and internal verification notes.
For the FBI, use the category for organizations or incidents related to the United States, consistent with the contact and coordination categories in CISA’s ransomware guidance. In other countries, list the relevant law-enforcement body or national authority. This sheet does not provide breach-notification deadlines or legal reporting duties. Refer those questions to a qualified adviser based on the facts and the applicable jurisdiction.
Choose a backup channel without adding risk
Write the name of the approved alternate channel and the safe way to reach it, but do not place passwords, access keys, or operational secrets on the sheet. The team should know where secure access instructions are held and who may use the channel. Before sharing sensitive details with a person or supplier, verify the identity through another trusted route. This is an editorial design recommendation intended to reduce impersonation and disclosure risk; it is not a promise that any backup channel will work in every incident.
Apply need-to-know access to the copies and keep the printed version in a secure location that remains reachable if primary systems are unavailable. Store the digital copy outside the primary corporate environment using the organization’s controls. This is a practical template choice; the appropriate protection depends on the sensitivity of the information and the organization’s policies.
Review and exercise
CISA recommends regularly exercising the incident-response and communications plans and treating the response plan as something to maintain. This article therefore suggests, as a non-mandatory practical application, a short rehearsal at least once a year and a check of the phone numbers. If you mention a periodic review, CISA’s Incident Response Plan Basics says to review the plan quarterly and describes it as a living document. Also, CISA recommends realistic incident-response exercises at least annually; this should not be presented as a universal legal or regulatory requirement for small and medium-sized organizations.
For the rehearsal, choose a short scenario, such as loss of access to email or suspected file encryption. Ask the team to locate the sheet, identify the incident manager, use the approved backup channel, and record whether each number works. Do not simulate sending sensitive information through an unapproved channel. Record gaps and update the sheet and full plan through the organization’s normal change process.
The sheet in organization-wide risk management
NIST SP 800-61 Rev. 3 treats incident response as part of organization-wide cybersecurity risk management and aims to support preparation, response, and recovery. The contact sheet should therefore not be owned only by the technology team. Invite leadership, legal, communications, system owners, and important suppliers to review the roles that apply to the organization.
Quick implementation checklist
- Assign an incident manager, technical lead, and executive decision-maker.
- Add legal, communications, insurance, and external response contacts.
- Record system and backup owners plus cloud, email, and hosting providers.
- Add the appropriate law-enforcement or national authority for the region.
- Document an approved backup channel reachable outside company systems.
- Print one copy and store a digital copy outside the primary environment with restricted access.
- Verify numbers, identity checks, and channels, then run a short rehearsal and record gaps.
The purpose is not to collect the largest possible list. It is to make roles and routes understandable and usable when the organization is under pressure. Keep the sheet concise, review it when staff or suppliers change, and connect it to the full incident response plan.