5 Essential Steps for a Cyber Incident Response Plan Small Business

Is your firm ready for a hack? Kevin Mabry shares 5 essential steps to build a practical cyber incident response plan for small businesses—no jargon required.
Why Your Business Is a Target (and Why Your Plan Matters)
I’ve spent more than 26 years—since 1999—helping small firms like yours navigate the messy world of cybersecurity. In that time, I’ve noticed a dangerous trend. Most business owners think they’re too small to be noticed. They believe that because they only have 15 or 30 employees, they are 'under the radar.' I’m here to tell you, in plain English: that is exactly what the criminals want you to think.
Being a small firm doesn't make you invisible; it makes you a low-hanging fruit. Criminals expect fewer safeguards, limited monitoring, and employees who have never been shown what to watch for. According to the Verizon Data Breach Investigations Report, nearly half of all cyberattacks target small businesses. Why? Because you are easier to hack than a bank, but you still have bank accounts, client data, and enough money to pay a ransom.
I remember a call I got at 5:30 AM on a Tuesday back in 2024. It was a managing partner at a 12-person law firm. Their entire server was encrypted. Their backups? Also encrypted because they were connected to the same network. They had no plan. They spent the next three weeks in total chaos, lost over $150,000 in billable hours, and nearly lost their biggest client. That is why I’m writing this. You don’t need an enterprise-sized security department, but you do need more than antivirus and a prayer. You need a Cyber Incident Response Plan (CIRP).
Key Takeaways:
- Small is Not Safe: Small firms are targeted specifically because they lack formal response plans and robust monitoring.
- Preparation Saves Money: Having a plan in place can reduce the cost of a breach by an average of $2.32 million compared to those with no plan, according to IBM’s Cost of a Data Breach Report.
- Communication is Critical: Knowing who to call (and what to say to clients) is just as important as the technical fix.
- Testing is Non-Negotiable: A plan on paper that has never been practiced will fail the moment a real crisis hits.
- Insurance Isn't a Safety Net: Most cyber insurance policies now require proof of a response plan before they will pay out a claim.
Step 1: The Preparation Phase (The "Who" and "What")
In my experience, the biggest mistake business owners make is assuming 'the IT guy' will handle everything. Cybersecurity is a business decision, not just a technical one. The preparation phase is about deciding who makes the calls when the world is on fire.
Build Your "War Cabinet"
You don't need a 20-person team. For a firm with under 100 employees, you need four key roles. I’ve seen firms try to manage this by committee, and it’s a disaster. You need clear lines of authority:
| Role | Responsibility | Who Should It Be? |
|---|---|---|
| The Lead | Makes the final call on shutting down systems or paying (or not paying) ransoms. | Owner or CEO |
| The Technician | Handles the actual hands-on work of stopping the attack. | Your MSP or internal IT Lead |
| The Communicator | Talks to clients, employees, and the media (if necessary). | Operations Manager or HR |
| The Legal/Insurance Contact | Coordinates with the insurance carrier and ensures you aren't breaking privacy laws. | Outside Counsel or CFO |
I once worked with a 40-person accounting firm that had a breach during tax season. Because they hadn't designated a 'Communicator,' the staff was telling clients different things. One person said 'the server is down,' another said 'we’ve been hacked.' It created a panic that was ten times worse than the actual technical issue. Identify these people now.
Asset Inventory: Know What You’re Protecting
You can’t protect what you don’t know you have. I tell my clients to sit down and list their 'Crown Jewels.' Where is the sensitive data? Is it in Microsoft 365? A physical server in the closet? A cloud-based CRM? If you don't know where the data lives, you won't know where the criminal went once they got into your network.
Step 2: Identification (Spotting the Smoke)
How do you know you’re being attacked? It’s not always a big red screen saying 'You’ve been hacked.' In fact, according to recent data, the average 'dwell time'—the time a hacker spends in your system before you notice—is still over 15 days. That’s two weeks of them reading your emails and watching your bank accounts.
Signs of Trouble
I’ve taught hundreds of employees how to spot these signs. You should, too:
- Unexpected MFA prompts: If your phone buzzes with a login request while you’re eating dinner, someone has your password.
- Sent items you didn't send: Check your 'Sent' folder in Outlook. If there are emails there you don't recognize, your account is compromised.
- Extreme slowness: If your computer is suddenly running like it’s 1995, it might be busy encrypting your files or mining cryptocurrency for a hacker.
- Locked accounts: If multiple employees are suddenly 'locked out' of their Windows accounts, someone is likely brute-forcing your passwords.
One of my clients—a small engineering firm—noticed that their internet was incredibly slow on a Thursday. They ignored it. By Monday, their entire database had been exfiltrated to a server in Eastern Europe. If they had investigated that 'slow internet' on Thursday, we could have stopped the theft before it finished. Identification is about listening to your gut and your hardware.
Step 3: Containment (Stop the Bleeding)
Once you know you’re under attack, the instinct is to panic and start deleting things. Don’t do that. You might delete the evidence your insurance company needs to pay your claim. Containment is about isolation.
The Short-Term Strategy
Your goal is to stop the attack from spreading. If one computer is acting weird, unplug it from the network. If your whole network is under fire, you might need to 'pull the plug' on the internet router. This is a business decision I help owners make: what is the cost of being offline for 4 hours versus the cost of losing every file you own?
The Long-Term Strategy
This involves changing every single password in the company. Not just the 'admin' passwords—everyone’s. I’ve seen attackers hide in a low-level employee's email account just to jump back in after the IT team thought the 'cleanup' was done. You must reset the perimeter.
"If you find yourself in a hole, the first thing to do is stop digging." - This applies perfectly to cyber incidents. Stop the spread before you try to fix the damage.
Step 4: Eradication and Recovery (Back to Business)
This is where the 'plain English' becomes very important. Eradication means getting the bad guy out for good. Recovery means getting your team back to work. These are two different things.
Don't Just Restore—Rebuild
I’ve seen firms get hit by ransomware, restore from a backup, and get hit again 24 hours later. Why? Because the hacker was in the system *before* the backup was taken. You have to ensure the 'malware' isn't sitting inside your backup files. This is where you need a professional to scan your backups before you flip the switch to go live.
The ROI of Recovery
Let’s talk numbers. For a 20-person professional service firm, the cost of downtime is roughly $1,500 to $2,500 per hour in lost productivity and overhead. If your recovery takes three days because you didn't have a plan, you’ve lost $40,000+ before you even pay a single repair bill. A solid plan usually cuts recovery time by 50% or more. That is a massive return on investment for a document that only takes a few hours to create.
Step 5: Post-Incident Review (The "Lessons Learned")
I hate to say it, but the best time to build a better security system is right after you’ve been kicked in the teeth. You will be more motivated than ever. But don't just move on—sit down with your 'War Cabinet' and ask the hard questions.
- How did they get in? (Usually a phishing email or an unpatched VPN).
- What part of our plan failed? (Maybe the 'Communicator' didn't have the client list at home).
- What do we need to change in our daily habits?
I worked with a real estate office that lost $60,000 to a wire transfer fraud. During the post-incident review, we realized the owner was the one who approved the wire because she was in a rush and didn't follow her own 'double-check' policy. We changed the process so that *no* wire over $5,000 could be sent without a verbal phone call to a known number. They haven't lost a dime since.
The Modern Threat: AI and "The Human Hack"
As we head into late 2026, the threats have changed. Hackers are now using AI to create 'Deepfake' audio. I recently heard about a small firm where the office manager got a phone call from the 'Owner.' The voice sounded exactly like him, telling her to 'pay this urgent invoice immediately.' It was a fake.
This is why your Incident Response Plan cannot just be technical. It has to include human processes. If your plan says 'verify all urgent financial requests with a pre-arranged code word,' you just defeated a multi-million dollar AI attack with a piece of paper and a conversation. That’s what I mean by making 'smarter security decisions.'
Cyber Insurance: The Fine Print
In my 26 years, I’ve seen insurance evolve from a 'nice to have' to a 'must have.' But there’s a catch. In 2026, insurance companies are much stricter. If you tell them on your application that you have a response plan and MFA on everything, and then you get hacked and they find out you *didn't* have those things? They will deny the claim. I’ve seen it happen. Your plan isn't just for your team; it’s your 'proof of due diligence' for the insurance company.
Frequently Asked Questions
Do I really need a written plan if I only have 5 employees?
Yes. In fact, you need it more. Large companies have layers of people to figure things out. In a 5-person firm, if the owner is the one whose email is hacked, who is in charge? A simple two-page document that says 'If X happens, call Y and do Z' is enough to save your business.
How much does it cost to create a response plan?
If you do it yourself using a framework like NIST, it costs you nothing but time. If you hire a consultant like me, it might cost a few thousand dollars to get it right. Compared to the $150,000+ cost of a typical breach for an SMB, it’s the cheapest insurance you’ll ever buy.
Should we pay the ransom?
As a general rule, I advise against it. The FBI recommends not paying because it marks you as a 'payer,' and they will likely hit you again. Plus, there is no guarantee you’ll get your data back. A good response plan focuses on restoring from backups so you never have to even consider paying a criminal.
How often should we update the plan?
At least once a year, or whenever you change a major piece of software. If you move from an on-premise server to the cloud, your 'Identification' and 'Containment' steps will change completely. I suggest doing a 'tabletop exercise' (a practice run) once a year over lunch.
Final Thoughts
Cybersecurity doesn't have to be a dark art. It’s about risk management. You wouldn't run your firm without fire insurance or a lock on the front door. A Cyber Incident Response Plan is just a digital lock and a fire drill combined. Start today by identifying your 'War Cabinet.' Don't wait for the 5:30 AM phone call that I hope you never have to receive. If you need a hand translating this 'tech talk' into a plan that actually fits your business, I'm here to help. We've been doing this since 1999, and we aren't stopping anytime soon.
Related Articles in Incident Response & Recovery
- Ultimate Guide to Creating a Cyber Incident Response Plan
- Ultimate Guide: Creating an Incident Response Plan in 6 Steps
- Complete Guide: Notifying Stakeholders Post-Breach in 2024
- Ultimate SOC Services Buyer's Guide — Complete guide on Incident Response & Recovery
- 5 Essential Benefits of Affordable SOC-as-a-Service Providers
- Incident Response Planning: 5 Proven Tips to Strengthen Your SMB
- Power of SOC: 5 Proven Strategies to Boost Business Security
- Computer Forensics: Unveiling the Hidden 5 Advantages
- Hire a Computer Forensic Expert: Your Network Security Breached?
- Using a SOC in Incident Response: 10 reasons Why
- Cyber Incident Response: Best Practices
- Critical Steps After a Data Breach Occurs: 24-Hour Guide
Watch: What should small medical practices do after a data theft incident?
Kevin Mabry
Founder & CEO, Sentree Systems
Kevin Mabry is the founder and CEO of Sentree Systems, a cybersecurity company serving small professional service firms with under 100 employees. Since starting his business in 1999, Kevin has spent more than 26 years helping organizations protect sensitive information and make smarter technology and security decisions.
His work focuses on helping business owners protect client data, reduce cyber risk, and avoid the operational disruption caused by ransomware, account takeovers, phishing, and other preventable threats. Kevin is known for explaining cybersecurity in plain English without vendor hype, unnecessary jargon, or treating cybersecurity like generic IT support.
Is your business protected?
Get a free security assessment. We'll identify your biggest risks and give you a clear, plain-English action plan — no obligation.
Schedule Your Free Assessment