“Can’t log in. Is it just me?” That message lands in a consultants’ WhatsApp group at 07:52 on a Monday. By 08:05 there are forty replies, and none of them comes from anyone who can say what is going on.
The firm is a UK consultancy of around 800 people, with three offices and 90 live client engagements. A change made over the weekend has broken single sign-on, so email, chat and the document store are all out of reach. Two client workshops start at 09:30, a board paper is due with a client at noon, and roughly 500 of the firm’s people are at client sites or on their way to one.
The firm has a business continuity plan. It runs to 46 pages and is saved in the document store nobody can open. The operations director has a printed copy at home, dated two years ago, which names an incident lead who has since left.
Questions fill the group chat faster than anyone can answer them. Who is in charge of this? Do the workshops go ahead? What should a consultant say to the client sitting across the desk, and who is calling the client waiting for the board paper?
An incident response checklist for consulting firms is written for that first hour. It doesn’t replace the plan. It is the one page that tells the people on duty what to confirm first, in what order, and who owns each answer.
An Incident Response Checklist For Consulting Firms Is One Page, Not The Plan
An incident response checklist for consulting firms is a short list of what a firm must confirm in the first hour of an incident, each item with a named owner. It covers where the firm’s people are, what was agreed with each client site, who speaks to which client, who holds each role that day and what record is being kept.
The plan explains why, and in what detail. The checklist is what someone can read on a phone at 07:55 and act on. The National Cyber Security Centre’s guidance on incident response processes draws the same line, advising organisations to add “simple checklists which can be used easily during an emergency” to a basic response plan.
Why Does A 46-Page Plan Stall In The First Hour?
A long plan stalls in the first hour because nobody can find the right page while the incident is moving. Continuity plans are written to be complete, which is what an auditor wants to see. The duty lead at 07:55 needs something else: five answers, and the names of the people who owe them.
Consulting firms have more reason than most to get this right. In the UK government’s Cyber Security Breaches Survey, 55% of professional, scientific or technical businesses identified a breach or attack in the previous 12 months. Across all businesses, only 23% had a formal incident response plan.
The Five Parts Of The Checklist
The incident response checklist has five parts: people, client sites, client calls, roles and the record. Five parts, and they are narrow on purpose. Each is a question the duty lead at a consulting firm should be able to answer within the first hour of an incident, and each was covered in detail in an article earlier this week.
- People: who is where, and who has answered?
- Client sites: what was agreed with each client site?
- Client calls: who calls which client, and what is the agreed line?
- Roles: who holds each role today, and have they practised it?
- Record: what record will exist tomorrow?
The order of the five checks matters. People come first, then clients, then the evidence. A firm that starts the client calls before it knows which consultants are affected will make promises it can’t keep.
1. Who Is Where, And Who Has Answered?
The first check on a consulting firm’s incident checklist is a count of its people by engagement and location, with a reply from each. In the scenario, around 500 people are spread across client sites, trains and home offices, and the outage has cut the channel the firm would normally use to reach them. The count has to run on something else, and the page records four things:
- The groups a message goes to, built around engagements and offices instead of departments
- The channel to use when email and chat are down
- The time by which a reply is expected, and who chases silence
- One named owner for the incident, with a deputy
This week’s article on incident coordination for consulting teams covers how to build those groups, and what to do when a travelling consultant doesn’t answer. Silence needs an owner too.
2. What Was Agreed With Each Client Site?
The second check covers client sites. Consultants at a client’s premises follow two sets of instructions, the client’s and the firm’s, and the checklist should say which applies to what. An IT outage at the firm doesn’t trigger the client’s emergency plan. A fire alarm at the client’s office does, and the firm still needs to know its people are out.
In Great Britain, regulation 12 of the Management of Health and Safety at Work Regulations 1999 requires a host employer to give the employer of visiting workers comprehensible information about the risks and the measures taken. The checklist entry is short: for each live placement, the firm holds those details and the consultant knows how to report in.
The article on duty of care at client sites sets out six things to confirm before a placement starts. Associates and subcontractors belong on the same list, because the client’s roll call may treat them as visitors.
3. Who Calls Which Client, And What Is The Agreed Line?
The third check is client communication: every client with a live engagement needs one named person to call them, working from one agreed line. Without that, the consultant across the desk improvises, the engagement partner says something different an hour later, and the client has two versions before lunch. The National Cyber Security Centre’s guidance on effective communications in a cyber incident advises that messages should address the concerns of each group while the core points stay consistent across them.
For the Monday outage, a first line could be as plain as this: “Our email and document systems are unavailable this morning. Your 09:30 workshop is going ahead from printed materials. Your engagement partner will call you by 10:00 with an update on the board paper.”
The checklist doesn’t hold the wording. It holds the name of the person who approves the line, the list of clients with a deadline that day and the owner of each call. The article on keeping clients informed during an incident covers what a firm can say before it has all the facts.
4. Who Holds Each Role Today, And Have They Practised It?
The fourth check names the person in each incident role on the day, with a deputy, and it is only as good as the last time those people used it. The printed plan in the scenario names an incident lead who left the firm, and the deputy has never been asked to make the decision the plan gives them.
The UK Resilience Academy’s Exercising Best Practice Guidance says that planning and preparation for risks “cannot be considered reliable until they have been exercised and shown to be workable”. A consulting firm usually can’t take twenty people out of client work for an afternoon. So practice has to be short, and the article on incident management training for consulting teams lays out sessions of ten, fifteen and sixty minutes.
5. What Record Will Exist Tomorrow?
The fifth check is whether a consulting firm can show, the day after an incident, who was told what and who decided what. Clients ask. So do insurers and, where personal data is involved, regulators. The National Cyber Security Centre’s incident response guidance notes that a careful record of decisions made and actions taken is especially useful when evidence of the response has to be presented to a regulatory body.
A WhatsApp group produces a record of sorts, and it is the wrong one. It shows what people typed, in the order they typed it. It doesn’t show which clients were called, who approved the line or when the workshops were confirmed.
The checklist entry names where the record is kept and who keeps it. If the answer is “someone will write it up afterwards”, the record will be a reconstruction.
A Complete Plan Is Not The Same As A Usable One
A complete business continuity plan and a usable one are different things. Most continuity plans are judged on whether anything is missing, and that test rewards length. Each review adds a section, an appendix or a contact table. The document that results satisfies an audit and gets harder to use at 07:55.
A firm needs both documents. The full plan carries the detail: recovery priorities, supplier contacts, insurance, the legal and regulatory steps. The checklist is the part that has to work in the first hour, and it should point to the plan for everything else.
Where Should The Checklist Live?
An incident checklist has to live outside the systems most likely to fail with it, on paper and on a platform that doesn’t share the firm’s sign-in. In the scenario the plan sat in the document store, behind the sign-in that had broken. The NCSC guidance suggests at least two contact methods and two or more people for each key contact, and alternative communications for when normal channels are unavailable. In practice that means four things:
- A printed copy with each incident lead and deputy, re-issued whenever a name changes
- A copy on a platform that doesn’t depend on the firm’s own sign-in, email or chat
- Contact details for every consultant and associate, with a second channel such as a personal mobile number
- A date on the page, so a stale copy is obvious
The Whole Checklist As A Table
The five-part checklist for a consulting firm fits on one page as a table of checks, answers and owners. The owner column is the one most often left blank, and it matters more than the other two.
Check | What the duty lead can say within the hour | Owner on the day |
1. People | Which consultants are affected, and who has replied | Incident lead |
2. Client sites | Which placements are live, and how each team reports in | Engagement managers |
3. Client calls | Who is calling each client, and the line they are using | Managing partner or delegate |
4. Roles | Who holds each role today, and who is the deputy | Operations director |
5. Record | Where messages, decisions and actions are being logged | Named note-taker |
Titles will differ between firms. Each row still needs one person’s name against it on the day, and a team name doesn’t count.
Where Crises Control Fits
Crises Control is an Operational Incident Coordination Platform. Its business continuity software page starts from the view that most organisations already have a documented plan, and that the hard part is executing it when disruption arrives. The platform turns a plan into alerts, tasks and a record.
Three modules map onto the five checks. Incident Manager, Crises Control’s incident management software, lets authorised users launch predefined incident response plans with message templates, recipient groups and attached documents such as procedures and contact lists. Ping, the mass notification software, can be configured to cascade a message across channels such as SMS, voice call and push notification until recipients acknowledge. Task Manager, the incident task management software, assigns tasks to a named owner or team when a plan is activated, and escalates tasks that are overdue or unclaimed.
Professional services firms use those modules in the order the checklist suggests. One has adopted Ping for ad hoc messages to staff and Incident Manager for the emergency scenarios it has defined in advance, with acknowledgements and status updates collected and non-responders escalated through channel cascading. Its business continuity exercises draw on the same audit trail and reports. A continuity consultancy goes a step further and builds response plans inside the platform on behalf of its own client.
Every notification, acknowledgement, task and decision is recorded automatically, which covers the fifth check without anyone writing it up afterwards. For a professional services parallel, the page for legal services firms describes coordination across offices, practice areas and time zones.
The software does not decide whether a workshop goes ahead, or what a client should be told about a missed deadline. Those remain decisions for the incident lead and the engagement partner. Its role is to carry the decision to the right people and show who has acted on it.
Five Answers Before The First Client Call
A consulting firm with the one-page checklist in hand answers the 07:52 message differently. The deputy incident lead sends one message through a channel that still works, and by 08:30 the two workshop leads know they are running from printed materials, and the client waiting for the board paper gets a call from a named partner before 10:00. Nobody has opened the 46-page plan yet, and nobody has needed to.
Most consulting firms can already send an alert. The step up is coordination that leaves a record: named owners, decisions made in order, and proof the next day of what was done.
Frequently Asked Questions
What is an incident response checklist for consulting firms?
An incident response checklist for consulting firms is a one-page list of what the firm must confirm in the first hour of an incident, with a named owner for each item. It covers people, client sites, client calls, roles and the record, and points to the full plan for detail.
What should a consulting firm's incident plan include?
A consulting firm’s incident plan should include key contacts with more than one contact method, escalation criteria, role holders and deputies, an owner for each client conversation and the legal or regulatory steps that apply. The National Cyber Security Centre also recommends simple checklists that can be used during an emergency.
How is business continuity for professional services firms different from other sectors?
Continuity planning in a professional services firm is different because most of the workforce is on someone else’s premises and the work is delivered to client deadlines. An incident response checklist for consulting firms puts both ahead of the detail of system recovery.
Where should an incident checklist be kept?
An incident checklist should be kept outside the systems that could fail with it. A printed copy with each incident lead and deputy, and a copy on a platform that does not rely on the firm’s own sign-in, email or chat, cover most cases.
How often should a consulting firm test its incident checklist?
A consulting firm should use its incident checklist in a short drill several times a year and review it whenever a named role holder changes. The National Cyber Security Centre advises a full review of incident response plans, playbooks and other guidance at least yearly.
This article was drafted with AI assistance and reviewed by the Crises Control team. Featured image: AI-generated.


