Why Does Your Small Business Need an Incident Response Plan?
When a cyber incident occurs, the default for most small organizations is chaos. People don’t know who to call, what to unplug, or what to say to customers. An incident response (IR) plan replaces that chaos with a clear, pre-approved set of actions.
The real issue here is not technology; it’s decision-making under pressure. Without a plan, you are forced to make critical financial and operational decisions in a panic. A simple IR plan makes those decisions for you ahead of time, when you can think clearly.
In practice, having a documented plan also helps with cyber insurance. Many insurers now ask for a formal IR plan during the application or renewal process. A plan demonstrates you are taking proactive steps to manage your risk.
What Does a Simple Incident Response Plan Include?
A functional plan for a small organization does not need to be a 50-page binder. A short, actionable document that anyone can follow is all you need. Think of it less like a technical manual and more like a fire escape plan for your data.
Your plan should fit on two or three pages and contain four core sections:
- Roles and Responsibilities: A list of who is on the incident response team and their specific duties. This includes contact information that works after hours.
- Incident Triage: A simple guide to help you determine if an alert is a real problem or a false alarm. It also helps categorize the incident’s severity.
- Response Checklists: Step-by-step instructions for specific scenarios like a ransomware attack, a data breach, or a phishing-compromised email account.
- Communication Plan: Pre-written templates and a list of who to notify and when. This includes employees, key customers, vendors, and any legal or regulatory bodies.
Who Should Be on Your Incident Response Team?
Your incident response team is not just your IT person. An incident affects finance, operations, and communications. The team should be small and empowered to make decisions quickly.
In my experience, a small organization needs these four key roles. One person may hold more than one role.
- Incident Coordinator: This person leads the response, follows the plan, and ensures tasks are being completed. This is often the owner, executive director, or office manager. They don’t need to be technical, but they must be organized.
- Technical Lead: This is your IT expert, whether they are an employee or an outside consultant (your Managed Service Provider, or MSP). They are responsible for the hands-on technical work of containing and removing the threat.
- Communications Lead: This person manages all internal and external messages. They ensure a consistent, factual message is delivered to staff, customers, and partners. This prevents rumors and misinformation.
- Executive Leadership: The owner or board chair. This person is the final authority for major decisions, especially those involving significant expense or legal risk.
List these people by role, name, and provide at least two forms of contact information (e.g., cell phone and personal email). Do not rely on company email, as it may be compromised during an incident.
Before You Start
- Identify your IT support. Do you have an internal IT person or an external IT company? Get their 24/7 emergency contact number and add it to your plan.
- Locate your critical data. Know where your most important information is stored. Is it on a local server, in a cloud service like Microsoft 365, or in a specific software application?
- Find your cyber insurance policy. Print a copy of the declaration page. It has the dedicated phone number you must call to report a claim and start the response process. Calling your regular agent is often the wrong first step.
- List your key cloud services. Make a list of essential services like your email provider, accounting software, and customer database. Find the administrator login pages for each.
- Check your backups. Confirm you have backups of your critical data. Know where they are stored and who is responsible for them. Verify they are isolated from the main network to protect them from ransomware.
- Gather legal and compliance contacts. If you handle sensitive data (like medical or financial records), have the contact information for legal counsel ready.
How Do You Create a Basic Incident Response Checklist?
The core of your plan is a set of checklists for different incident types. The most common scenarios for small organizations are ransomware, business email compromise, and data theft. Start with a checklist for ransomware, as the steps often apply to other attacks.
Here is a sample checklist structure. Create a document and fill in the blanks with your organization’s specific details.
Ransomware Incident Checklist
Phase 1: Identification & Initial Assessment (First 30 Minutes)
- Confirm the Incident: The person who discovers the issue immediately calls the Incident Coordinator. Do not use company email.
- Alert the Team: The Incident Coordinator calls the rest of the response team using the contact list. State the known facts clearly.
- Isolate Affected Systems: The Technical Lead immediately disconnects the infected computers from the network. Unplug the network cable; do not just turn the computer off. This prevents the ransomware from spreading.
- Do Not Pay the Ransom: The team agrees that no one will contact the attacker or attempt to pay the ransom. This is a decision for law enforcement and your insurance provider.
Phase 2: Containment & Communication (First 1-4 Hours)
- Call Your Cyber Insurance Provider: The Incident Coordinator calls the 24/7 breach hotline on the policy. They will provide access to legal and forensic experts. This must be your first call after initial containment.
- Call Your IT Support: The Technical Lead engages your IT company (MSP) to begin a technical assessment. Grant them emergency access if needed.
- Secure Backups: The Technical Lead verifies that backups are secure and disconnected from the network. Do not attempt to restore any data yet.
- Draft Internal Communication: The Communications Lead drafts a message for all staff. Instruct them to stop using their computers and wait for further instructions. Emphasize that they should not talk to anyone outside the company about the incident.
- Change Critical Passwords: The Technical Lead changes passwords for all administrative accounts, including network, cloud services (like Microsoft 365), and firewalls.
Phase 3: Eradication & Recovery (Days 1-5+)
- Follow Expert Guidance: Your cyber insurance provider will assign a forensic team. The Technical Lead works directly with them. Do not wipe or rebuild any systems until the forensic team gives approval.
- Determine the Scope: The forensic team and Technical Lead will identify how the attackers got in and what data was accessed. This is critical for legal notification requirements.
- Clean and Restore Systems: Once cleared by the forensic team, the Technical Lead begins wiping affected systems and restoring data from clean backups.
- Manage External Communication: Based on legal and forensic findings, the Communications Lead and Executive Leadership will determine what to communicate to customers or the public. Your insurance provider’s legal counsel will guide this process.
What Steps Should You Take During a Cyber Incident?
When an incident happens, your plan is your guide. The goal is to act deliberately, not hastily. The sequence of your actions matters immensely.
In my experience, the single biggest mistake small organizations make is trying to fix the problem themselves before calling for help. They often destroy critical forensic evidence that is needed to understand the attack and prevent it from happening again.
Follow these priorities during an actual event:
- Contain: Stop the bleeding. Disconnect affected machines from the network to prevent the threat from spreading further. Preserve the evidence; do not wipe machines or delete files. Unplugging the power cord from the wall is effective. If it a laptop or a device that has a battery is involved, long press the power button on the device until it shuts down – usually 4 to 8 seconds.
- Call: Activate your response plan by calling your Incident Coordinator. Then, call your cyber insurance breach hotline. Their experts will guide your next technical and legal steps.
- Communicate: Use your communication plan to inform staff and stakeholders. Control the narrative with clear, factual information.
How Can You Test and Update Your Plan?
An untested plan is just a document. You need to verify that it works and that your team knows how to use it. You don’t need a complex, expensive simulation.
A good starting point is a tabletop exercise. This is a 60-minute meeting where you walk through a scenario, like a ransomware attack. The Incident Coordinator presents the scenario, and each team member explains what actions they would take according to the plan.
This simple exercise reveals gaps immediately. You might find that contact information is outdated, a key person is unavailable, or a technical step is unclear. After the exercise, update the plan with the lessons you learned.
Review and test your plan at least once a year. Also, update the plan whenever there is a major change in your organization, such as a new key employee, a new IT provider, or a new core software system.
Beyond the Plan: Essential Recovery Steps
After the immediate crisis is over, the work is not finished. The post-incident phase is where you learn from the event and strengthen your defenses. This is a critical part of the response process.
First, conduct a post-mortem meeting with the response team. Discuss what went well and what did not. The goal is not to assign blame but to improve the process for next time.
Second, implement the security improvements recommended by the forensic investigators. This might include deploying multi-factor authentication (MFA), improving email filtering, or providing security awareness training for your staff.
Finally, update your incident response plan based on the lessons from the real event. A real incident is the ultimate test of your plan. Incorporate what you learned to make it more effective for the future.
Our Recommendation
Do not wait for a perfect, comprehensive plan. A simple, one-page checklist that you can use today is far better than a detailed plan that never gets finished. Use the ransomware checklist in this article as your starting point.
Fill in the names and contact numbers for your response team. Print several copies and store them in accessible, offline locations. A plan on a server you cannot access during a ransomware attack is useless.
Frequently Asked Questions
What is an incident response plan for a small business?
It is a short checklist detailing the immediate steps to take during a cyber attack. It identifies a response team, provides their contact information, and outlines actions for specific scenarios like ransomware. Its purpose is to guide clear, calm decision-making during a crisis.
Do non-profits need an incident response plan?
Yes. Non-profits handle sensitive donor, member, and financial data, making them targets for cyber attacks. An incident response plan is essential for protecting that data, maintaining donor trust, and ensuring the organization can continue its mission after an attack.
How long does it take to create a basic incident response plan?
You can create a functional first draft in two to four hours. The process involves one meeting with key leaders to assign roles and a second session to fill in the contact details and review the checklists. The initial effort is small compared to the time saved during an actual incident.
What is the first step in an incident response plan?
The first step is always containment. This means isolating the affected systems to stop the attack from spreading. For a workstation, this is as simple as unplugging its network cable. This action preserves evidence and limits the immediate damage.
How often should an incident response plan be reviewed?
Review your plan at least once a year or whenever your organization undergoes a significant change. Changes that should trigger a review include hiring new leadership, changing your primary IT provider, or adopting a new critical software system.
Your next step is to download a copy of your cyber insurance policy and find the 24/7 breach reporting hotline number. Put that number in your phone and at the top of your new plan document.
