4 min. read Email this page Bryley Systems Inc.

Listen to this report:

This is part 3 of a 3-part series

Looking in a mirror

So many scammers, so many phishing attempts, so many stories about others being hacked, but do we really see? Do we really know?

What’s an Incident Response Plan?

What are you looking at?

Can you see how we’re under constant attack on our computers?

Most threats are rebuffed by spam filters or website blockers or by not falling for a crown prince ready to transfer a fortune. These surface attacks are the mere tip of the iceberg of criminals who want your money either directly like getting into your bank account or through selling the data you possess (even selling it back to you via ransomware).

There must be about a million angles. And don’t you think about a million ai agents at work automating these breaking and stealing operations on behalf of the criminals? The data testifies to LLMs widespread use by criminals.

This leads to the inevitable truth: almost every organization suffers the consequences of a breached system. Has this happened to you yet? Has an employee or have you clicked a link that unleashed malware? Have you or your staff fallen for a fraud and sent funds? I hope the answer is ‘no.’

Facing the worst kinds of attacks unprepared

Let’s say it’s easy-to-understand ransomware: a criminal has gotten access to your systems and data and locks you and your employees out while threatening to release the stolen data on the web unless you pay.

Facing this unprepared the first response is panic. ‘How much money?’ ‘Why won’t they just ask for more if I pay the first demand?’ ‘Do we have insurance for this?’ ‘Do we have backups?’ ‘Whose fault is this?’ ‘Did I do something wrong?’ and employees also ask, ‘am I going to get fired?’ ‘Nobody can work,’ you wonder, ‘do I send everybody home? For how long?’

Where is the answer?

What it takes to survive a big one

Because of the inevitability of landed cyberattacks, yes, you do whatever is reasonable to prevent them, but the chief characteristic an organization needs to develop is resilience in the face of adversity. And the main tool to achieve that is the Incident Response Plan.

An Incident Response Plan (IRP) is equivalent to any other emergency preparation; equivalent to mapping out escape routes from your house and a place to meet in case of fire.

Begin with the end in mind

At its base, an Incident Response Plan is a set of employee roles and responsibilities and a checklist of organizational procedures to contain, neutralize and report a cybersecurity incident. But by starting with an emergency in mind: like how thinking about escaping your house gets you thinking about it in a way you never thought of before, preparing an IRP makes an organization fully aware of its data practices and cybersecurity.

You’ll document where data assets like all client and employee records are being held – intentionally or not. You’ll see in one place are they encrypted and how. You’ll be aware of how well the data are backed up. Creating an IRP will give an opportunity to understand the reliability of those backups. Are they on the same system which can make them vulnerable to the same ransomware? What is it like to restore from these backups? How long will it take?

You’ll see what’s behind a firewall – a growing point of vulnerability – and its patching schedule.

Here’s looking at you and your staff looking at an IRP

Is this your before-it’s-too-late opportunity?

Consider the company that we met with and acknowledged we were probably right and still passed on taking their security posture seriously. They were hit with a ransomware attack less than a year later and told me they regretted passing up that window of opportunity.

A discovery call doesn’t commit you to anything, but can give you a better idea of where you stand, what’s at risk, and what closing gaps would involve for an organization in your industry.

So consider contacting Bryley’s Roy Pacitto at rpacitto@Bryley.com or reach him by phone at 978.562.6077 x217.


Kudos to you and your cybersecurity exploration if you participate in the following quiz, provided as a tool for learning and modeled on cybersecurity certification tests. The quiz collects no data.

Incident Response Plan Quiz (#15)


by Lawrence Strauss, August 25, 2026
Lawrence has written for Bryley since 2015. His coverage of cyber-scams appears on moneywise.com

Connect with Bryley to look at co-managed/managed IT options

Get more New England-based technology and security information. Subscribe to Up Times by Bryley monthly newsletter.
This field is for validation purposes and should be left unchanged.