incident responsepolicies and training

Exact question

What should we send when a customer asks for our incident-response policy?

By EvidenceFit Editorial TeamPublished 13 July 2026Reviewed 13 July 2026Next review 13 January 2027

Independent expert review has not yet been recorded. This page provides operational guidance, not professional advice.

Direct answer

First clarify whether the customer needs the policy itself, a summary, or evidence that incident response is tested and used. Share an approved, current and appropriately redacted document that identifies scope, roles, escalation and review, then distinguish it from exercise records or incident evidence that show the process has operated.

What the requester is trying to establish

The customer may want to see that incidents affecting their service or data will be recognized, escalated, contained, communicated and learned from. They may also be checking a contractual notification process.

Who this normally applies to

This applies to organizations asked about cyber or information-security incident handling. Privacy, sector, insurance and contractual duties can add context-specific requirements.

Questions to answer before responding

  • Which incident types, services and legal entities are in scope?
  • Is the customer asking for design evidence or operating evidence?
  • Which contact, security and infrastructure details require redaction?
  • Is a contractual notification clause being tested?
  • When was the policy approved, exercised and last reviewed?

Likely internal owners

Security or engineering typically owns technical response. Management owns escalation and major decisions. Privacy, legal, communications, People and insurance contacts may own specialist decisions.

Evidence commonly requested

Evidence What it can show What it cannot show alone
Approved incident-response policy or plan Intended roles, scope and process That the process works under pressure
Exercise record A scenario was run and actions recorded Readiness for every incident type
Incident record Process used for a specific event Broad or continuous effectiveness
Training or acknowledgement People received or acknowledged material Their performance during an incident

What each evidence item proves

Document approval supports governance; an exercise supports rehearsal; a dated incident record supports operation on that event; follow-up actions support learning when their closure is evidenced.

What it does not prove

No single document proves that every incident will be detected or handled successfully. A plan is not a guarantee of a contractual outcome.

Weak or insufficient responses

An undated template, a policy with stale contacts, a generic security policy, or an exercise invitation without results is weak evidence for the respective claim.

Step-by-step completion process

  1. Clarify the requested artifact and assurance objective.
  2. Confirm approval, owner, scope, version and review date.
  3. Check that roles, escalation, communications and recovery interfaces are represented.
  4. Redact exploitable and unnecessary personal details.
  5. Add exercise or incident evidence only when requested and safe to disclose.
  6. State exceptions and confidentiality controls.
  7. Obtain authorized review before sharing.

Example response structure

State the policy title and version, approval and review dates, scope, summary of the process, redactions made, related exercise evidence, exceptions and the secure channel for any further disclosure.

Common mistakes

Do not email operational contact trees unnecessarily, claim a tabletop exercise proves all controls, or confuse incident-response policy with a customer-specific breach-notification commitment.

Matters requiring professional judgment

Notification duties, privilege, insurance notification, evidence preservation and disclosure of real incidents can require legal, privacy, forensic or insurance advice.

Sources

NCSC and NIST publish incident-response guidance. They provide useful structure but do not replace the obligations and risk context that apply to your organization.

Author and expert reviewer

Organizational editorial byline; no independent expert review recorded.

Original publication date

13 July 2026.

Last reviewed date

13 July 2026.

Change history

  • 13 July 2026: Initial publication.

See the exercise-record entry for the difference between an approved plan and evidence of rehearsal.

How EvidenceFit helps with this situation

EvidenceFit helps clarify the request, connect the correct artifacts to accountable owners and preserve the scope, redactions and approval of the response.

Source references

  1. Plan your cyber incident response processes — UK National Cyber Security Centre. Accessed 13 July 2026. primary
  2. Computer Security Incident Handling Guide — NIST. Accessed 13 July 2026. primary

Sources inform this page; applicability still depends on the request, contract, framework and jurisdiction.

Related practical records

Cite this page

EvidenceFit Editorial Team. (2026). How to respond when a customer asks for an incident-response policy. EvidenceFit. https://evidencefit.io/common-requests/respond-incident-response-policy/

APA-style approximation and BibTeX

Last updated: 13 July 2026

@online{evidencefit2026,
  author = {EvidenceFit Editorial Team},
  title = {How to respond when a customer asks for an incident-response policy},
  year = {2026},
  url = {https://evidencefit.io/common-requests/respond-incident-response-policy/},
  urldate = {2026-07-20}
}

Suggest a correction to this page