Quantum Technologies — AI in a Box
SecurityOctober 5, 2026Nathan Drager3 min read

6 Things Every Small-Business Incident Response Plan Needs

When something goes wrong, the first hour decides how bad it gets. The six things a one or two page incident response plan must cover, and how to test it in 30 minutes.

Flight attendant demonstrating the use of a yellow life vest inside an airplane cabin.

When something goes wrong, a hacked mailbox, a ransomware note, a laptop stolen from a car, the first hour decides how bad it gets. Businesses with a plan make a few calls and follow steps. Businesses without one spend that hour working out who to call, and often make it worse by turning things off, wiping evidence or paying someone they shouldn't. The businesses that recover fastest aren't the ones with the fanciest tools. They're the ones that knew who to call in the first ten minutes.

A small business doesn't need a binder. It needs one or two pages that answer six questions. Cyber insurers increasingly ask whether you have one, and the national standard for incident response, NIST's guidance (revised in April 2025), comes down to the same basics.

1. Who's in charge

Name one person who makes decisions during an incident, and a backup for when they're unreachable. Decisions in a crisis go faster with one voice.

2. Who to call, in what order

Write down the numbers, not just the names, and keep a printed copy, because your email and files may be the thing that's down:

  • Your IT provider's emergency line.
  • Your cyber insurance carrier's claims or breach hotline. Many policies require you to call them before hiring anyone, or they won't pay.
  • Your attorney.
  • Your bank, if money may have moved. Speed matters for recalling a wire.
  • Law enforcement: the FBI's Internet Crime Complaint Center (ic3.gov) for fraud and ransomware.

3. First steps, and what not to do

  • Disconnect affected computers from the network, but don't power them off or wipe them. Evidence matters for insurance and for finding how they got in.
  • Change passwords for affected accounts from a clean device, and sign out all sessions.
  • Don't contact the attacker or pay anything before talking to your insurer and IT provider.

4. How you'll keep working

Decide in advance how you'll answer phones, take orders and pay staff if systems are down for a few days. A paper fallback for a week is worth thinking through before you need it.

5. Who has to be told, and by when

If personal information was taken, Wisconsin law requires notifying affected residents within 45 days. Other rules may apply: the FTC Safeguards Rule (30 days to notify the FTC if 500 or more customers are affected), HIPAA for patient data, and your contracts with customers. Your attorney and insurer will guide the details. Your plan just needs to say that this step exists.

6. How you'll recover, and learn

Restore from tested backups, confirm the attacker is gone before reconnecting, and afterward write down what happened and what will change. Most of the value of an incident comes from that last step.

Test it once a year

Spend 30 minutes walking through a scenario with the people named in the plan: "Monday morning, every file is encrypted. Who does what?" You'll find the missing phone number or the wrong assumption while it costs nothing. We help our clients write and test this plan as part of how we work.

Not sure where your business stands on this?

We’ll walk through how you handle it today and tell you straight whether it needs attention.

SecurityBusiness Technology

Let's talk about your technology.

A quick conversation about where you are, what's not working, and whether we're the right fit. No pressure, no jargon.

No obligation. No sales pressure. Just an honest conversation.

CallSchedule a Call