Current studentsFamiliesFaculty & staffAlumni & donorsBusiness & industry
University of WesconsinPorter FallsDo more from day one.

Campus Technology

Cybersecurity Incident Response Plan

A written, tested plan for what happens in the first hour after a serious security incident is discovered — not improvised in the moment.

Home Cybersecurity Incident Response Plan

The four phases

Detection and analysis (confirming something real is happening, not a false alarm), containment (isolating affected systems without destroying evidence needed later), eradication and recovery (removing the cause and restoring service), and a post-incident review that happens whether or not the incident was serious — every real incident produces a written lessons-learned report.

Who is in charge during an incident

A designated incident commander, from the technology office’s information security team, has clear authority to take systems offline without waiting for sign-off up the chain — a ransomware infection spreading on a shared drive does not wait for a meeting to be scheduled. The chancellor’s office and general counsel are looped in immediately for anything involving restricted data (see data governance & classification) or a likely legal notification requirement.

When people get told, and what they get told

An incident confirmed to expose restricted personal data triggers legal notification requirements under Wesconsin law within a defined window, sent directly to affected individuals with specifics about what was exposed and what to do — not a vague campus-wide email. A less severe incident with no data exposure is documented internally without necessarily going public.

Testing the plan before it is needed

The security team runs a tabletop exercise at least once a year, walking through a simulated incident with the people who would actually be on the call, specifically to find gaps in the written plan before a real incident does.