A cyberattack is not a question of if — it is a question of when. Without a plan, the average business takes 207 days just to identify a breach. With a tested incident response plan, businesses contain incidents 58% faster and spend dramatically less on recovery. The difference is not the size of your IT team; it is whether you have a plan at all.

What Happens Without a Plan
A dental practice in Ohio was hit with ransomware on a Monday morning. No IR plan, no designated contact list, no backups tested in over a year. By the time they reached their IT provider, three days had passed. Recovery took six weeks and cost $180,000 — including ransom, forensics, and lost revenue. A written response plan with current contacts could have saved months of pain. 60% of small businesses never reopen after a major cyber incident.
Assign These Five Roles Before You Need Them
- Incident Commander — leads the response, makes final decisions, usually the owner or senior manager
- Technical Lead — investigates, isolates systems, coordinates with IT or your MSP
- Communications Lead — handles internal and external communication, notifies clients, regulators, and insurers
- Documentation Keeper — records a timeline of every action taken and preserves evidence
- Business Continuity Lead — keeps critical operations running or restores them as quickly as possible
The biggest incident response mistake small businesses make is assuming someone else will lead. Assign these roles now, in writing, and post the contact list somewhere accessible even when your systems are down.
The Six Phases of Incident Response
- Preparation — the only phase entirely in your control before an incident happens: written plan, assigned roles, tested backups, enabled logging
- Detection & Analysis — determine whether you have a real incident and how serious it is; do not start fixing things yet or you may destroy evidence
- Containment — stop the spread, like isolating a patient with a contagious disease; disconnect affected devices, do not power them off, change passwords
- Eradication — remove every trace of the attacker, including backdoors; reset all passwords and patch every exploited vulnerability
- Recovery — restore systems from clean, verified backups and resume normal operations, only once the environment is confirmed clean
- Post-Incident Review — the lessons-learned session to understand what happened, how it was handled, and how to prevent recurrence
The Rule That Saves Evidence
Never restore from backup into a compromised environment. Eradicate the threat completely, verify the environment is clean, then restore — restoring into a still-compromised system can immediately reinfect your recovered data.
Get the Free Incident Response Playbook
Our full playbook includes a ready-to-use incident response checklist, communication templates, the five most common incident types and how to respond to each, and the mistakes to avoid.
No Dedicated Security Staff? This Is For You
You do not need a security operations center to respond well — you need a plan, assigned roles, and a tested backup. See how we help small businesses build an incident response plan that actually works when it counts.