Skip to main content
FrameworkMapper
 
Prepared Before You Need It

Write the Plan. Keep It Current. Hand It Over.

Most organizations have an incident response plan that was written once and has not been opened since. FrameworkMapper gives you a plan built from published federal and industry standards, tailored to your sector, filled in with your own people and contacts — and a briefing set generated from the assessment data you have already entered, so responders can act on day one instead of interviewing you.

 

The First Days of a Breach Are Spent Asking Questions You Already Answered

What identity provider do you run? Is there EDR on the servers? How far back do the logs go? Can ransomware reach the backups? Who has to be notified, and by when? Incident responders ask these questions on day one — and organizations answer them slowly, from memory, under the worst possible pressure.

If you have completed a FrameworkMapper assessment and added your tools, those answers already exist. The packet composes them into briefing documents a responder can act on in minutes. The questions it cannot answer from data — who declares an incident, who may take a system offline, who calls the carrier — are the ones the plan makes you decide in advance, while there is time to decide them well.

70
Plan sections, drawn from 7 public standards
0
Extra data entry — the briefing set builds itself
Offline
Readable even when your sign-in is down
Auto
Refreshes when your data changes
 

Start With a Plan You Did Not Have to Write

Seventy sections, grouped into nine parts, synthesized from NIST SP 800-61r3, CISA’s Federal Incident and Vulnerability Response Playbooks, CISA’s IRP Basics, the National Cyber Incident Response Plan, the SANS Incident Handler’s Handbook and industry readiness guidance. Every section says what it is for and cites the standards behind it, so the plan is defensible to an auditor and readable by a responder at 2am.

Written for your sector

A district gets student records and instructional continuity. A hospital gets patient safety and clinical downtime. A defense supplier gets CUI handling. Nine sector groups, offered automatically — and every other sector’s sections remain one click away, because we set the default and you know your organization.

The decisions, not just the headings

Who may declare an incident at 2am. Who authorises taking a system offline. What the first hour looks like. Which channel you use when your own email may be read by the attacker. These are the questions a template leaves blank and an incident asks first.

Already have a plan?

Upload it and keep it, use ours, or run both — your document travels with the generated packet either way. Write your own sections where the template has nothing to say about how your organization works.

Your Incident Response Plan Printable PDF

Generated with a cover page carrying your organization’s name, a table of contents, part dividers, and an appendix citing every standard the guidance draws on. Turn the guidance notes on and it doubles as a tabletop workbook that shows the sections you have not filled in yet; turn them off for the lean operational copy. Your contacts, your notification obligations and your call order can be appended to the same document.

The sample is a fictitious K-12 district with a dozen sections filled in and the rest left blank, so you can see both states. Guidance is reference material, not legal advice.

Who to Call

A contact order for each kind of incident — eleven of them, from phishing and ransomware to a lost device. National and state contacts are maintained for you; yours slot in beside them. Anything your organization does not use stays on the page with your reason, because a responder who never learns an option existed cannot judge whether the reason still holds.

Your response contacts

Your insurer, your IT provider, your counsel, your local police, and whoever answers at 2am. Encrypted with your organization’s key — we store the date you last edited them and never the contents. Anything you leave blank is left out rather than guessed at.

 

What's Inside the Packet

Every sample below is a real, fully rendered document — built from a fictitious organization ("Client Company", a K-12 district) so you can see exactly what responders receive. View it in the browser or download the PDF.

Responder Brief

The environment snapshot an external firm normally spends days assembling: identity provider, email platform, data types, staffing, and your assessed capabilities — EDR, logging, MFA, backups — each with the assessment evidence behind its status and what a responder can rely on.

Kill-Chain Gap Overlay

Enter the attacker techniques observed in an incident and see them mapped against your assessed control coverage, phase by phase — where the attacker likely moved unopposed, and which containment actions your organization can actually execute versus the ones that assume capabilities you don't have.

Tool KEV History

Your tool inventory checked against products with confirmed CISA Known Exploited Vulnerabilities history — a "check these first" triage ordering for the initial-access hypothesis. Honestly labeled: it knows your products, not your patch levels, and says so.

Notification Obligations

The reporting duties your sector, location, and data types are likely to trigger — insurance carrier, state breach statute, FERPA, law enforcement — ordered by which clock runs out first, with the ones that don't apply shown too. Decision support to bring to counsel, not legal advice.

Evidence Bundle Companion ZIP

Every evidence file your team submitted during the assessment and its check-ins — one folder per control, a clickable index, and a SHA-256-verified manifest. Shipped as its own download, so you can hand responders the reports freely and share raw evidence deliberately. Controls with zero evidence show zero: during an incident, knowing what documentation doesn't exist saves time too.

Remediation Crosswalk Coming Soon

Post-incident findings mapped to every framework you maintain — remediate once, close the gap in CIS, CMMC, CSF, and your cyber-insurance questionnaire at the same time. Arrives with FrameworkMapper's capability question bank.

 

Getting It Into the Right Hands, Before You Need To

A plan only the person on vacation can reach is not a plan. Incident response access is granted separately from everything else — an organization you trust to help at 2am is not necessarily one you want reading your assessments the rest of the year.

Share it with the people who respond

Give a linked organization — your MSP, your regional support unit, a parent organization — standing read or edit access to your incident response material, without giving them your assessments.

Or keep it sealed until it matters

Emergency access grants nothing day to day. During an incident the other organization opens it themselves — always granted, because nobody should wait on an approval mid-incident, and always recorded with who opened it, why, and when. The window closes on its own.

An account for responders only

The Incident Responder role reaches the packet, the plan, your tool inventory and the activity log — and nothing else. No assessments, no billing, no team management. The right account to hand a contractor or an on-call volunteer.

Available to client and partner organizations alike: a partner runs its own incident response on the same pages, because an incident at your organization is not a different problem because of what you sell.

 

Built for the Day Everything Else Is Down

Always current

The briefing set regenerates whenever the data feeding it changes — an assessment save or check-in, a tool inventory update, a profile edit. Your plan stays yours: when we improve a section’s guidance you are told it changed, and nothing you wrote is ever overwritten or removed.

Protected like your answers

On the platform, packet contents are encrypted with your organization's key — the same protection as your assessment answers. It describes your gaps as well as your strengths, and is treated accordingly.

Yours, offline

You download the packet and keep it where your response plan lives — the break-glass binder, storage that isn't domain-joined. During an incident your identity provider may be unreachable or contested; the packet doesn't depend on it.

Every document is composed deterministically from data your organization entered. Statuses reflect your self-assessment — decision support for responders and counsel, never a forensic finding.

 

Included With Your FrameworkMapper Bundle

The Incident Response Packet is part of the bundle subscription — no separate purchase. Complete an assessment and add your tools, and the packet builds itself from there.