An incident response plan is the thing you least want to be writing at 2 a.m. while an attacker is already inside your systems. Yet that is roughly what happened to America's top cyber-defence body. According to TechCrunch, the Cybersecurity and Infrastructure Security Agency (CISA) admitted it "missed" a chance to get ahead of a security incident by not having a response plan ready before it happened.

Sit with that for a second. The agency whose entire job is telling everyone else to be prepared got caught improvising its own playbook mid-fire. If it can happen to CISA, it will happen to your three-person startup in Colombo. So let me turn this into something useful instead of a dunk.

The failure here is not technical. It is a planning failure, and planning failures are the cheapest ones to fix. When you write your response steps during an incident, three things go wrong at once:

You make decisions under stress. Adrenaline is bad for judgement. Who do we call, do we take the box offline, do we tell users yet? These are hard questions that get worse when you are panicking.

Nobody knows their role. Two people fix the same thing, a third thing gets ignored.