The following document outlines the creation of an information security incident management plan specifically designed for small and medium-sized enterprises (SMEs). It is structured in four phases based on the NIST 800-61 framework, tailored to meet the needs of these organizations. The employed methodology, participatory action research, allows for a direct and immersive engagement with SME members, providing a wellsupported approach. The document encompasses an assessment of the current situation of SMEs and their distinctive characteristics. Subsequently, it introduces a specific solution model designed for SMEs. Finally, it is evaluated through a proposed implementation plan, demonstrating the model's functionality in a case study. This ensures its feasibility and effectiveness within an actual organization.