Practical guide · verified against the real thing
The incident-response plan a small business can actually run at 2am
In one line: You will not remember the right steps during a real breach. A one-page plan, written now, is the difference between a contained incident and a catastrophe.
Small organisations assume incident response is for companies with a SOC. The truth is the opposite: with no security team, the difference between a survivable incident and a disaster is almost entirely whether someone wrote down, in advance, what to do. Under stress nobody improvises well. A one-page plan, agreed beforehand, is the whole game.
The four moves, in order
Every response reduces to contain, assess, notify, recover. Contain first — stop the bleeding: isolate the affected machine or account, revoke the compromised credential, take the exposed service offline. Containment beats forensics when they conflict. Assess what was reached and what data was involved, because that drives everything legal. Notify who must be told and on what clock. Recover from a known-clean state and close the hole that let it in.
Notification is where jurisdiction bites
Who you must tell, and how fast, depends on where the affected people are — this is the part you cannot guess. A breach touching UK/EU residents can trigger a 72-hour GDPR notification to the regulator; Nigerian residents' data engages the NDPA's notification duties; US obligations vary by state and by sector. The compliance map lays out who each regime protects; your plan should name your regulator and the deadline before you need it, not during the panic.
What to write on the one page, now
Who is in charge of an incident and their contact. The containment steps for your most likely scenarios (a compromised email account, ransomware on one machine, a leaked token — the risk behind token hygiene). Who you call: your MDR or provider if you have one (MSSP vs MDR), your insurer, your regulator, your customers. Where your clean backups live and how to restore — the 3-2-1 rule is what makes "recover" real instead of theoretical. Write it before you need it, test it once a year, and the worst night of the business becomes a checklist instead of a catastrophe.
Sources
Next