6 Things Every Small-Business Incident Response Plan Needs
When something goes wrong, the first hour decides how bad it gets. The six things a one or two page incident response plan must cover, and how to test it in 30 minutes.

When something goes wrong, a hacked mailbox, a ransomware note, a laptop stolen from a car, the first hour decides how bad it gets. Businesses with a plan make a few calls and follow steps. Businesses without one spend that hour working out who to call, and often make it worse by turning things off, wiping evidence or paying someone they shouldn't. The businesses that recover fastest aren't the ones with the fanciest tools. They're the ones that knew who to call in the first ten minutes.
A small business doesn't need a binder. It needs one or two pages that answer six questions. Cyber insurers increasingly ask whether you have one, and the national standard for incident response, NIST's guidance (revised in April 2025), comes down to the same basics.
1. Who's in charge
Name one person who makes decisions during an incident, and a backup for when they're unreachable. Decisions in a crisis go faster with one voice.
2. Who to call, in what order
Write down the numbers, not just the names, and keep a printed copy, because your email and files may be the thing that's down:
- Your IT provider's emergency line.
- Your cyber insurance carrier's claims or breach hotline. Many policies require you to call them before hiring anyone, or they won't pay.
- Your attorney.
- Your bank, if money may have moved. Speed matters for recalling a wire.
- Law enforcement: the FBI's Internet Crime Complaint Center (ic3.gov) for fraud and ransomware.
3. First steps, and what not to do
- Disconnect affected computers from the network, but don't power them off or wipe them. Evidence matters for insurance and for finding how they got in.
- Change passwords for affected accounts from a clean device, and sign out all sessions.
- Don't contact the attacker or pay anything before talking to your insurer and IT provider.
4. How you'll keep working
Decide in advance how you'll answer phones, take orders and pay staff if systems are down for a few days. A paper fallback for a week is worth thinking through before you need it.
5. Who has to be told, and by when
If personal information was taken, Wisconsin law requires notifying affected residents within 45 days. Other rules may apply: the FTC Safeguards Rule (30 days to notify the FTC if 500 or more customers are affected), HIPAA for patient data, and your contracts with customers. Your attorney and insurer will guide the details. Your plan just needs to say that this step exists.
6. How you'll recover, and learn
Restore from tested backups, confirm the attacker is gone before reconnecting, and afterward write down what happened and what will change. Most of the value of an incident comes from that last step.
Test it once a year
Spend 30 minutes walking through a scenario with the people named in the plan: "Monday morning, every file is encrypted. Who does what?" You'll find the missing phone number or the wrong assumption while it costs nothing. We help our clients write and test this plan as part of how we work.
Not sure where your business stands on this?
We’ll walk through how you handle it today and tell you straight whether it needs attention.