Define what should activate the plan
Write down the signals that should trigger an incident response: unexpected administrator accounts, unauthorised page changes, browser security warnings, unexplained redirects, a hosting alert, loss of domain or DNS control, exposed services, or credible notice from a supplier or customer.
A signal is not automatically proof of compromise. Record what was observed, when it appeared and who noticed it, then use the plan to decide who verifies the event and how urgently it should be escalated.
