By J. Mesa
October is Cybersecurity Awareness Month, and most of the advice you will read this month covers prevention. This post covers the other half: the morning your screens show a ransom note, or your bank calls about a wire you never approved. The decisions you make in the first 24 hours set the cost of the whole event.
What is an incident response plan?
An incident response plan is a written document that tells your team who does what when a security incident occurs. It names the people in charge, lists the phone numbers, and lays out the steps to contain the damage, recover, and meet your legal duties.
A small business plan fits on a few pages. It needs to exist on paper, because the computer that stores it may be the one under attack.
What counts as a security incident?
Any event that threatens your data or your systems. Common examples:
- Ransomware or other malware
- A hacked email account
- A fraudulent wire or changed vendor bank details
- A lost or stolen laptop or phone
- An employee who clicked a phishing link and entered a password
- Customer records sent to the wrong person
- A hacked website
- A vendor that tells you it suffered a breach involving your data
A breach is a narrower legal term. It means someone accessed or took protected information without authorization, and it triggers notification laws. Do not call an event a breach in writing until your attorney says it is one.
What should I do in the first hour?
- Stay calm and stop the spread. Disconnect affected computers from the network. Pull the network cable and turn off Wi-Fi.
- Leave the machines powered on. Shutting down erases evidence held in memory, and investigators may need it. Disconnect, do not power off, unless your responder tells you otherwise.
- Do not wipe, reinstall, or “clean” anything. You will destroy the evidence that shows what the attacker took.
- Start a log. Write down the time, what you saw, who reported it, and each action taken. Use paper or a phone that sits outside the affected network.
- Take photos of ransom notes and error messages with a phone.
- Tell your incident lead. One named person runs the response and makes the calls.
- Switch channels. If email may be compromised, stop using it to discuss the incident. The attacker may be reading along. Use phone calls or a messaging app on personal devices.
Who should I call first?
Call in this order:
- Your cyber insurance carrier’s breach hotline. The policy pays for forensic and legal help only when you use approved vendors and report on time. See our guide to cyber insurance.
- A breach attorney, often supplied by the carrier. The attorney directs the investigation so that communications stay privileged.
- Your IT provider or security consultant.
- Your bank, if money moved or banking credentials were exposed. Ask for a wire recall and a hold on the accounts.
- Law enforcement. File a report at ic3.gov. For a fraudulent wire, call your local FBI field office as well, because fast reports give the best chance of freezing the funds.
No insurance? Call an attorney and an incident response firm yourself. Keep both numbers in the plan before you need them.
What should I do in hours 1 through 4?
Contain the attack.
- Isolate affected systems from the rest of the network.
- Disable or reset compromised accounts. Start with administrator accounts and email.
- Revoke active sessions in Microsoft 365 or Google Workspace, so a stolen login stops working.
- Check email accounts for forwarding rules and inbox rules the attacker created.
- Block the attacker’s known addresses at the firewall.
- Disconnect your backups from the network to protect them.
- Preserve the logs: firewall, email, server, and cloud. Many systems overwrite logs within days.
What should I do in hours 4 through 12?
Work out what you are dealing with.
- Which systems and accounts did the attacker reach?
- When did the first sign of entry appear? The visible attack often comes weeks after the break-in.
- What data sits on the affected systems? Customer records, patient charts, card numbers, employee files, and tax documents each carry different legal duties.
- Are the backups intact, and what is the date of the last clean copy?
- Is the attacker still inside?
Let the forensic team answer these with evidence. Guesses made in the first few hours often turn out wrong.
What should I do in hours 12 through 24?
- Brief the staff. Tell employees what happened in plain terms, what they should do, and who speaks for the company. Instruct them to send press, customer, and vendor questions to one person.
- Decide how to operate. Can you run on paper, on phones, or from clean laptops for a week?
- Plan the recovery. Rebuild from clean backups in a set order: identity and email first, then the systems that bring in revenue.
- Review notification duties with your attorney.
- Prepare a holding statement for customers. Keep it factual and short. Do not speculate about causes or promise that no data was taken.
Should I pay the ransom?
The FBI advises against it. Payment funds the next attack, gives no guarantee that the decryption tool works, and gives no guarantee that the criminals delete the stolen data. Paying a group under US sanctions is illegal.
Some businesses with no working backups face a choice between paying and closing. Make that decision with your attorney, your insurer, and a professional negotiator. Never contact the attacker on your own, and never pay before the carrier approves.
Do I have to notify customers or regulators?
It depends on what data the attacker accessed and where the affected people live. All 50 states have breach notification laws, and the deadlines differ. Industry rules add their own clocks:
- HIPAA. Notify affected patients within 60 days of discovery, and notify the Department of Health and Human Services.
- FTC Safeguards Rule. Covered financial businesses notify the FTC within 30 days when an event involves the unencrypted data of 500 or more consumers.
- PCI DSS. Notify your acquiring bank and the card brands at once when card data may be involved.
- Contracts. Many customer agreements require notice within 24 to 72 hours.
Your attorney makes the call. Your job is to supply accurate facts fast.
What mistakes make an incident worse?
- Wiping the infected computers before anyone investigates
- Restoring from backup while the attacker still has access
- Discussing the incident over the compromised email system
- Announcing “no customer data was affected” on day one
- Letting the staff post about it on social media
- Waiting days to call the insurer or the bank
- Negotiating with the attacker yourself
- Skipping the password resets because they are inconvenient
What goes into a small business incident response plan?
- The incident lead and a backup person
- A printed contact list: insurer hotline and policy number, attorney, IT provider, bank fraud line, FBI field office, key vendors, and staff cell numbers
- Definitions of what staff must report and how
- Step-by-step checklists for the likely events: ransomware, email compromise, wire fraud, lost device
- An inventory of systems and where sensitive data lives
- Backup locations and restore instructions
- Notification requirements that apply to your industry
- Templates for staff and customer messages
- The date of the last test
How do I test the plan?
Run a tabletop exercise once a year. Gather the owner, the office manager, your IT provider, and whoever handles money. Spend 90 minutes walking through a scenario: it is Friday at 4 p.m. and a ransom note appears on the front desk computer. Who do you call? Where is the phone number? How do you make payroll on Monday? Each gap you find in a conference room is one you will not find during a real attack.
What happens after the first 24 hours?
Recovery continues for days or weeks. Remove the attacker’s access, rebuild, restore, and watch closely for a return. When the dust settles, hold a review. Identify how the attacker got in, fix that weakness, and update the plan and your staff training with what you learned.
Your next step
Print a one-page contact list today and tape it inside a cabinet door. Then set a date to write the rest. Cerberus Cybersecurity writes incident response plans for small businesses and runs the tabletop exercises that test them. See our services or contact us.