Incident response process templates (6 linked flowcharts)
Six linked flowcharts for the full escalation ladder: incident management, severity classification, cybersecurity response, data breach notification, disaster recovery and business continuity.
An IT incident becomes a security incident becomes a notifiable breach becomes a disaster-recovery invocation — and each rung of that ladder is owned by a different team working to a different clock.
What's in the package
1. Incident management process flowchart
The front door: detection, logging, triage, and the major-incident declaration.
2. Incident severity classification flowchart
The decision that routes everything else — impact, urgency, and the exposure test.
3. Cybersecurity incident response process flowchart (SOC)
The security branch: containment, eradication, forensics, and recovery to clean state.
4. Data breach response process flowchart (GDPR 72-hour clock)
The regulatory branch and its seventy-two-hour clock, including notification decisions.
5. Disaster recovery process flowchart (IT systems)
The rebuild: invocation authority, recovery order, and validation before return to service.
6. Business continuity process flowchart: invoke to stand-down
Keeping the business running on workarounds while the rebuild happens.
How they connect
- Incident management process flowchart → Incident severity classification flowchart
- "Categorise and set priority" is where the incident process defers to the classification chart. Keeping severity in its own chart means one definition of P1 that every other process points at, rather than three that disagree.
- Incident management process flowchart → Business continuity process flowchart: invoke to stand-down
- "Declare major incident" is the point at which the question stops being how to fix the failure and becomes how the business keeps operating while it is fixed. Those are different teams, different plans and different clocks.
- Incident severity classification flowchart → Cybersecurity incident response process flowchart (SOC)
- "Data or safety exposure?" is a decision diamond, and a link on a decision is the most useful place for one: a decision is exactly where a process forks into another process rather than continuing.
- Cybersecurity incident response process flowchart (SOC) → Data breach response process flowchart (GDPR 72-hour clock)
- "Identify affected assets and accounts" is where the security team learns whether personal data is in scope. If it is, the regulatory clock started at detection, not at this step — which is why the breach process is linked rather than appended.
- Cybersecurity incident response process flowchart (SOC) → Disaster recovery process flowchart (IT systems)
- "Rebuild systems from clean backups" is the handoff from security to infrastructure. Security decides what is clean; recovery decides the order things come back.
- Disaster recovery process flowchart (IT systems) → Business continuity process flowchart: invoke to stand-down
- "Authorise DR invocation" triggers the continuity plan in parallel, not afterwards. Recovery has an RTO; the business needs to operate before it expires.
- Business continuity process flowchart: invoke to stand-down → Disaster recovery process flowchart (IT systems)
- "Activate workarounds and manual processes" links back the other way, because continuity is often invoked first — the business notices it cannot trade before infrastructure has decided this is a disaster.
How it works
Fix the severity matrix before anything else
Every other chart in the package routes on the classification chart's output. Put your real impact and urgency definitions in first, then check the five charts that depend on them still read correctly.
Put a name and a phone number on every invocation authority
Both the major-incident declaration and the DR invocation are authority decisions. A chart that says "management approves" will produce a twenty-minute argument at the worst possible moment.
Start the regulatory clock at detection in the breach chart
The seventy-two hours run from awareness, not from confirmation. If your chart implies the clock starts when legal is briefed, it is describing a deadline you will miss.
Run a tabletop using the links as the script
Walk the group from the front door through classification into the security branch and out to recovery, following the badges. Every hesitation about who takes over is a gap in the chart, not in the group.
Share the folder read-only with everyone on call
These are the charts people need at three in the morning. Read-only access for the whole on-call rota costs nothing and removes the "who has the current version" question entirely.
Frequently asked questions
Does this follow ITIL?
The incident chart uses the ITIL shape — detect, log, categorise, prioritise, investigate, resolve, close — without adopting ITIL's full vocabulary. The security, breach, recovery and continuity charts follow the practice in ISO 27035, ISO 22301 and the common regulatory patterns rather than ITIL.
Do I need a paid plan for this?
Yes — template packages are included with Plus. A package creates six charts at once, and the free plan holds three. Each chart is also available on its own for free.
Why do disaster recovery and business continuity link to each other?
Because either can be invoked first. Infrastructure may declare a disaster before the business notices, or the business may activate workarounds before anyone has called it a disaster. A one-directional link would describe only half of the real behaviour.
Is the seventy-two-hour clock specific to GDPR?
The breach chart is drawn around a seventy-two-hour notification window because that is the GDPR requirement and the most commonly applicable one. Other regimes differ — some are shorter for critical infrastructure — so change the interval in the chart to match what you are subject to.
Add all six charts to my library — 6 charts in one folder. Included with Plus.