A cyber incident response plan tells your team what to do when ransomware, a compromised email account, stolen credentials, or an exposed customer record disrupts the business. Cyber liability insurance may help pay certain response costs, but it does not replace preparation. For Mount Pleasant employers, the practical goal is to coordinate technology, leadership, legal guidance, communications, and insurance before an incident occurs. This guide explains how to build that process, what to prioritize during the first 72 hours, and where South Carolina breach-notification rules may apply.
Key Takeaways
- Assign response roles, outside contacts, and decision authority before an incident.
- Notify the cyber insurer or broker promptly and follow the policy’s reporting requirements.
- Preserve evidence while containing affected systems; avoid rushed actions that could hinder the investigation.
- South Carolina notification duties depend on the information involved, acquisition, misuse or risk of harm, and other facts.
- Review policy definitions, conditions, exclusions, sublimits, and approved vendors before relying on coverage.
What Counts as a Cyber Incident?
A cyber incident is not limited to an outside attacker breaking into a network. It can include ransomware, phishing-based credential theft, business email compromise, accidental disclosure, a lost unencrypted device, or a breach at a payroll provider or other vendor. The response plan should explain how employees report warning signs and who decides whether to activate the full response team. Not every incident is a legally reportable breach or covered claim; those questions depend on the facts, law, and policy.
Build the Plan Around Current NIST Guidance
NIST finalized Special Publication 800-61 Revision 3 in April 2025, replacing Revision 2. The current model integrates incident response into the NIST Cybersecurity Framework 2.0. It treats Govern, Identify, and Protect as preparation activities, then organizes the incident-response cycle around Detect, Respond, and Recover, with lessons feeding continuous improvement.
For an employer, that framework becomes a practical checklist:
Prepare: Govern, Identify, and Protect
Name the incident lead and backup decision-maker. Inventory critical systems, sensitive data, vendors, and backups. Record outside contacts and review the cyber policy’s notice instructions and approved-vendor requirements.
Detect
Create a reporting channel for suspicious activity. Decide who will document the initial facts and preserve relevant logs, messages, and devices.
Respond
Confirm the scope, contain affected accounts or systems, coordinate technical and legal work, and control communications. The response should be fast but evidence-based. Disconnecting a device may be appropriate; wiping or powering it down without guidance could destroy useful forensic information.
Recover and Improve
Restore operations from known-clean systems or backups and monitor for continued access. Then update controls, training, and the plan based on what the team learned.
What to Do in the First 24 to 72 Hours
The exact order varies, but most organizations should be prepared to take these actions:
- Activate the response team. Start the plan, open an incident log, and assign one coordinator.
- Contain the event carefully. Isolate affected systems or accounts with technical guidance while preserving evidence and essential business operations.
- Secure access. Reset compromised credentials, revoke suspicious sessions, and protect privileged and financial accounts without interfering with forensic analysis.
- Notify the insurer or broker. Follow the policy’s notice method and timing. Obtain approval before hiring vendors or incurring costs when the policy requires it.
- Engage appropriate specialists. Depending on the event, that may include forensic investigators, privacy or breach counsel, law enforcement, and communications support.
- Determine notification duties. Identify the people, data, systems, locations, and vendors involved. Plan promptly, but establish the facts before sending notices.
- Keep communications controlled. Give employees one reporting path and designate who may communicate with customers, vendors, regulators, or the media.
Keep an offline copy of the plan and contact list in case the network is unavailable.

South Carolina Data Breach Notification Requirements
South Carolina Code Section 39-1-90 applies to a person conducting business in the state that owns or licenses data containing defined personal identifying information. Notification to affected South Carolina residents may be required when qualifying information was not rendered unusable and was, or is reasonably believed to have been, acquired by an unauthorized person, with illegal use, likely illegal use, or a material risk of harm. The statute calls for notice in the most expedient time possible and without unreasonable delay, subject to legitimate law-enforcement needs and measures needed to determine the breach’s scope and restore system integrity.
A company maintaining data it does not own must notify the owner or licensee immediately following discovery when the statutory conditions are met. If one breach notice is sent to more than 1,000 people at one time, additional notice is required. The South Carolina Department of Consumer Affairs says a business notifying 1,000 or more South Carolina residents must also notify the Department and national consumer reporting agencies. Other federal or sector-specific requirements may apply. Businesses should coordinate with qualified counsel rather than treating a general checklist as legal advice.
How Cyber Liability Insurance May Support the Response
Cyber policies vary, but coverage may address certain first-party expenses the insured incurs and third-party claims against the insured.
| Coverage area | What it may address, subject to the policy |
| Incident response | Forensics, breach counsel, notification, credit monitoring, and crisis communications |
| Business interruption | Covered lost income and extra expense during a qualifying disruption |
| Cyber extortion | Negotiation and certain payment-related expenses, when legally permissible and covered |
| Data or system recovery | Costs to restore covered data, software, or systems |
| Third-party liability | Defense and covered damages arising from privacy or network-security claims |
| Regulatory response | Certain defense, investigation, or penalty costs where covered and legally insurable |
Coverage is not automatic because an event involves technology. Definitions, exclusions, deductibles, sublimits, security representations, prior acts, and vendor requirements can change the outcome.
Policy Details to Review Before an Incident
Ask these questions during a policy review:
- What events trigger coverage, and how are “computer system,” “security failure,” and “privacy event” defined?
- Does social engineering or funds-transfer fraud have a separate limit or endorsement?
- What notice deadline and reporting channel apply?
- Must the insured use approved counsel, forensic firms, negotiators, or communications vendors?
- What security practices were represented in the application, such as multifactor authentication or backup controls?
- How do business interruption waiting periods and calculation methods work?
- How does the policy treat incidents involving cloud providers or other vendors?
Compare these terms with actual systems and the response plan, not only the declarations-page limit. Benni Agency’s business and commercial insurance services include cyber liability among the coverage areas businesses can review. The Mount Pleasant insurance and benefits page explains the local service relationship.
Frequently Asked Questions
Should a business call its cyber insurer before hiring a forensic firm?
Often, yes. Policy terms may require prompt notice or approved vendors. Follow the policy’s instructions and ask the carrier or broker before committing to costs.
Does cyber insurance always cover ransomware payments?
No. Coverage depends on policy language, approvals, exclusions, sublimits, and legal restrictions. Businesses should involve the insurer, counsel, and appropriate authorities before making payment decisions.
Who handles notice when a vendor is breached?
Contracts and applicable law matter. Under South Carolina’s statute, a data maintainer notifies the owner or licensee; the owner generally handles qualifying resident notices.