we had a client get popped last year, wordpress, old contact form plugin, the usual. the incident response plan for cyber attack they paid a consultat to write was a 60 page pdf sitting in a google drive, and the drive belonged to the guy who left in march. nobody could open it while the site was serving spam to anyone who searched the brand. what actually worked was a one page text file i keep in the repo: who to call, where dns lives, where the last backup is, which host, which registrar, and the two commands that put the site behind a maintenence page. Nothing clever. the paid plan had org charts and a communications matrix and it was useless at 11pm on a sunday. if yours is longer than a page you will not read it under pressure, thats the whole lesson. keep a copy off the network as well, ours lived on the same drive as everything else and that was dumb. cheers
Source: r/WebsiteHealth · by /u/anouk_98