
IRPForge
Incident response planning nonprofits can actually afford.
I've spent the last 25 years in IT and cybersecurity, a lot of it in incident response. Early on that meant being the one responding when something actually broke or got breached. More recently it's meant building the plans and processes that are supposed to exist before anything happens in the first place.
One thing that career teaches you is you rarely solve every problem alone. The real skill is knowing who the right expert is and bringing them in. When I built a full incident response plan for an organization that had nothing in place, I didn't do it solo. I had it independently audited and had lawyers review the final version to make sure it would hold up if it was ever actually needed.
Getting a plan like that built by a consulting firm typically runs $5,000 to $35,000. Most nonprofits and small organizations just skip it and hope for the best.
That gap is what became IRPForge. You fill out a guided intake form, no security background needed, and it generates a branded, audit-ready incident response plan built on CIS Controls v8 and the NIST Cybersecurity Framework. You get three documents: the full plan, an incident report form, and a one-page emergency contact sheet for the moments when something's actively going wrong and nobody has time to dig up phone numbers.
Starter is $199, one time, no subscription. Built mainly with nonprofits and small orgs in mind since they're usually the ones with nothing in place at all, but it works for any small organization.
This is version 1.0, and I'd genuinely like feedback from this community, especially anyone who's built something in a compliance or security adjacent space. Does the structure hold up? Where would you push on it?
About
Nonprofits get hit by cyberattacks as often as anyone else, but they can't afford what enterprise security vendors charge for incident response planning — a single tabletop exercise from a consulting firm runs $5,000 to

1 Comment
25+ years in the field gives this a very different starting point from most compliance tools. Curious what feedback from security professionals changes your thinking about v1.0.