Exact question
What should we send when a customer asks for our incident-response policy?
Independent expert review has not yet been recorded. This page provides operational guidance, not professional advice.
First clarify whether the customer needs the policy itself, a summary, or evidence that incident response is tested and used. Share an approved, current and appropriately redacted document that identifies scope, roles, escalation and review, then distinguish it from exercise records or incident evidence that show the process has operated.
What the requester is trying to establish
The customer may want to see that incidents affecting their service or data will be recognized, escalated, contained, communicated and learned from. They may also be checking a contractual notification process.
Who this normally applies to
This applies to organizations asked about cyber or information-security incident handling. Privacy, sector, insurance and contractual duties can add context-specific requirements.
Questions to answer before responding
- Which incident types, services and legal entities are in scope?
- Is the customer asking for design evidence or operating evidence?
- Which contact, security and infrastructure details require redaction?
- Is a contractual notification clause being tested?
- When was the policy approved, exercised and last reviewed?
Likely internal owners
Security or engineering typically owns technical response. Management owns escalation and major decisions. Privacy, legal, communications, People and insurance contacts may own specialist decisions.
Evidence commonly requested
| Evidence | What it can show | What it cannot show alone |
|---|---|---|
| Approved incident-response policy or plan | Intended roles, scope and process | That the process works under pressure |
| Exercise record | A scenario was run and actions recorded | Readiness for every incident type |
| Incident record | Process used for a specific event | Broad or continuous effectiveness |
| Training or acknowledgement | People received or acknowledged material | Their performance during an incident |
What each evidence item proves
Document approval supports governance; an exercise supports rehearsal; a dated incident record supports operation on that event; follow-up actions support learning when their closure is evidenced.
What it does not prove
No single document proves that every incident will be detected or handled successfully. A plan is not a guarantee of a contractual outcome.
Weak or insufficient responses
An undated template, a policy with stale contacts, a generic security policy, or an exercise invitation without results is weak evidence for the respective claim.
Step-by-step completion process
- Clarify the requested artifact and assurance objective.
- Confirm approval, owner, scope, version and review date.
- Check that roles, escalation, communications and recovery interfaces are represented.
- Redact exploitable and unnecessary personal details.
- Add exercise or incident evidence only when requested and safe to disclose.
- State exceptions and confidentiality controls.
- Obtain authorized review before sharing.
Example response structure
State the policy title and version, approval and review dates, scope, summary of the process, redactions made, related exercise evidence, exceptions and the secure channel for any further disclosure.
Common mistakes
Do not email operational contact trees unnecessarily, claim a tabletop exercise proves all controls, or confuse incident-response policy with a customer-specific breach-notification commitment.
Matters requiring professional judgment
Notification duties, privilege, insurance notification, evidence preservation and disclosure of real incidents can require legal, privacy, forensic or insurance advice.
Sources
NCSC and NIST publish incident-response guidance. They provide useful structure but do not replace the obligations and risk context that apply to your organization.
Author and expert reviewer
Organizational editorial byline; no independent expert review recorded.
Original publication date
13 July 2026.
Last reviewed date
13 July 2026.
Change history
- 13 July 2026: Initial publication.
Related guides and evidence entries
See the exercise-record entry for the difference between an approved plan and evidence of rehearsal.
How EvidenceFit helps with this situation
EvidenceFit helps clarify the request, connect the correct artifacts to accountable owners and preserve the scope, redactions and approval of the response.
Source references
- Plan your cyber incident response processes — UK National Cyber Security Centre. Accessed 13 July 2026. primary
- Computer Security Incident Handling Guide — NIST. Accessed 13 July 2026. primary
Sources inform this page; applicability still depends on the request, contract, framework and jurisdiction.
Related practical records
Cite this page
EvidenceFit Editorial Team. (2026). How to respond when a customer asks for an incident-response policy. EvidenceFit. https://evidencefit.io/common-requests/respond-incident-response-policy/
APA-style approximation and BibTeX
Last updated: 13 July 2026
@online{evidencefit2026,
author = {EvidenceFit Editorial Team},
title = {How to respond when a customer asks for an incident-response policy},
year = {2026},
url = {https://evidencefit.io/common-requests/respond-incident-response-policy/},
urldate = {2026-07-20}
}