Most incident response plans in small businesses are one of two things: absent, or a thirty-page template downloaded from somewhere and never read.

What is actually needed is two pages, printed, that answer four questions. Here is how to write it.

Question 1: who decides?

The first failure in almost every incident is hesitation. Somebody notices something odd, is not sure whether it is serious and waits to ask a colleague who is in a meeting.

Name one person who decides that an incident is happening, and one deputy. Give them explicit authority to act — to disconnect systems, to engage suppliers, to spend money — without further approval.

Write down what triggers the decision, in plain terms:

  • Files unexpectedly encrypted or renamed
  • A ransom message
  • Anybody realising they entered credentials into a fake page
  • Unexplained access to a mailbox or account
  • Data appearing somewhere it should not
  • Any supplier telling you they have had a breach affecting you

Any of those, and the plan is invoked. It is far better to invoke it unnecessarily than to spend two hours deciding.

Question 2: who do you call?

A list, with names, direct numbers and mobile numbers. Not "the IT company" — the actual number, including the out-of-hours one.

  1. Your IT support provider. Their emergency number, which is often different from the normal one.
  2. Your cyber insurer. Policy number included. Many policies require notification within a set window and mandate their own incident response provider — engaging somebody else first can affect cover, and this catches businesses out regularly.
  3. Senior people in your own business who need to know.
  4. Your data protection contact if you have one.
  5. Legal advice if the incident involves client data or a contractual notification duty.

Store this printed. A contact list inside the systems that are down is not a contact list.

Question 3: what happens in the first hour?

Short, ordered, unambiguous.

  1. Disconnect affected systems from the network. Do not power them off. Powering off destroys evidence in memory that helps establish what happened and what was taken.
  2. Note the time and what was seen. Start a written log immediately. It will matter for the insurer, the regulator and your own understanding a week later.
  3. Protect the backups. Isolate them. This is what attackers target first.
  4. Make the calls in the order above.
  5. Do not delete anything, and do not restore anything until somebody has established the scope. Restoring into a compromised environment reinfects it.
  6. Do not pay anything or communicate with an attacker without advice.
The single most useful thing in an incident is a written log started in the first five minutes. Nobody ever regrets having one and everybody regrets reconstructing it later.

Question 4: what are the reporting obligations?

These have deadlines and the deadlines are short.

Information Commissioner's Office — 72 hours. A personal data breach posing a risk to individuals must be reported within 72 hours of becoming aware. The clock starts at awareness, not at full understanding, and an incomplete report on time is better than a complete one late.

Affected individuals — without undue delay where the risk to them is high.

Action Fraud and the NCSC. Report cyber crime. The NCSC also provides support for significant incidents.

Your clients. Check your contracts now rather than during an incident. Many supplier agreements now require notification within 24 or 48 hours of an incident affecting the client's data, and this is becoming more common through the supply chain effects described in this article.

Your regulator, if you are in a regulated sector.

The half that gets forgotten: keeping trading

Most plans cover the technical response and stop. Add half a page on continuing to operate:

  • How do customers reach you if email is down?
  • How do you take orders or bookings without your systems?
  • Who tells staff what is happening, and how, if the normal channels are unavailable?
  • What do you say publicly, and who says it?

That last one deserves a prepared holding statement. Writing one under pressure while everything else is happening produces something you will regret.

Test it once a year

An hour, the relevant people in a room, one realistic scenario talked through step by step. No systems involved.

Every business that does this finds at least two things that would not have worked: a phone number that has changed, an assumption that somebody has access they do not, a backup nobody knew was in scope.

Finding those in an hour on a Tuesday is considerably cheaper than finding them during the incident.

Two pages, printed

That is the whole thing. Who decides, who to call, the first hour, the reporting deadlines and how you keep trading. Printed, in more than one place, with a copy at the decision-maker's home.

Our security solutions team writes these with UK businesses and runs the annual tabletop exercise. Get in touch if you would like a hand — it is an afternoon's work and it is the document you will be most glad to have.