HomeBlogCyber Incident Response: Best Practices
All PostsIncident Response & Recovery

Cyber Incident Response: Best Practices

Kevin MabryJuly 19, 2026
Cyber Incident ResponseSmall Business CybersecurityFTC Safeguards Rule 2026Ransomware RecoveryData Breach CostsKevin MabrySentree Systems
Cyber Incident Response: Best Practices

Kevin Mabry shares 2026 best practices for cyber incident response. Learn the 5-step process to protect your small firm from $120k+ breach costs and downtime.

Cyber Incident Response: Why "Wait and See" Is a Strategy for Failure

I’ve been doing this since 1999. In over 26 years of helping small professional service firms protect their client data, I’ve heard every version of the same sentence: "Kevin, why would anyone target us? We’re a 12-person accounting firm, not a global bank."

If you take nothing else away from this article, let it be this: Attackers don't avoid you because you're small; they seek you out because you're small. According to the 2026 Verizon Data Breach Investigations Report (DBIR), small and medium businesses (SMBs) are now being hit with approximately 4 times more confirmed breaches than large organizations (Verizon DBIR 2026). They know you likely have fewer safeguards, limited monitoring, and a team that hasn't been trained on what a modern, AI-enhanced attack looks like.

Cyber incident response isn't about having a thick binder of technical jargon that no one reads. It’s about knowing exactly what to do when your screen goes dark at 4 PM on a Friday and your client files are suddenly renamed with a .locked extension. It’s about survival. In my experience, the firms that walk away from a breach with their reputation intact are the ones that realized long ago that an incident is a "when," not an "if."

Key Takeaways for Small Firm Owners

  • Preparation is the single biggest cost-saver. According to IBM’s latest data, having a tested incident response (IR) plan and a trained team can save your business an average of $2.66 million per breach (IBM Cost of a Data Breach Report 2025).
  • Downtime is your real enemy. For a typical small firm, the cost of the ransom is often dwarfed by the cost of being offline. Industry benchmarks now put average downtime costs at $53,000 per hour for SMBs.
  • Vulnerabilities are the new front door. As of mid-2026, exploitation of software vulnerabilities has overtaken stolen credentials as the #1 initial access vector, rising to 31% of all breaches.
  • The "Human Element" remains the biggest risk. Over 62% of breaches in 2026 still involve a person making a mistake—clicking a link, reusing a password, or being tricked by an AI-generated deepfake voice.
  • Compliance is non-negotiable. Under the updated FTC Safeguards Rule, many small professional firms are now legally required to have a written incident response plan and a designated "Qualified Individual" overseeing their security.

The Hard Reality of Breach Costs in 2026

When I sit down with a business owner, I don't use the global average of $4.44 million for a data breach. That number is skewed by Fortune 500 companies. Instead, we look at what's realistic for a firm under 100 employees. The current data shows a realistic range of $120,000 to $1.24 million for a single incident at a small business (Verizon DBIR 2026).

The "Long Tail" of Breach Expenses

Many owners think the expense ends when the IT guy says the systems are back up. I’ve watched firms lose everything because they didn't account for the "long tail" of costs. IBM found that only about 47% of breach costs happen in the first year. The remaining 53% hit you in years two and three through insurance premium hikes, lost clients, and legal fees. If you're hit today, you'll still be paying for it in 2028.

Cost CategoryEstimated Range (1-50 Employees)Why It Costs This Much
Forensics & Investigation$25,000 – $95,000Determining what was stolen and how they got in.
Downtime & Lost Revenue$50,000 – $200,000+Staff sitting idle while systems are rebuilt.
Legal & Notification$15,000 – $60,000Complying with state and federal disclosure laws.
Remediation & Hardening$20,000 – $80,000Fixing the holes so it doesn't happen again.
Insurance Deductibles$10,000 – $50,000Out-of-pocket costs before coverage kicks in.

Last year, I worked with a 12-person law firm that experienced what they thought was a "small" email hack. Because they didn't have a response plan, they didn't realize the attacker had been in their system for 4 months. By the time we were called in, the forensics alone cost $45,000 because there were no logs to follow. They ended up spending nearly $200,000 when all was said and done—roughly 8% of their annual revenue.

Step 1: Preparation (Beyond the Antivirus)

Preparation is where you win or lose the war. In 2026, "being prepared" means more than just having backups. It means having a Written Information Security Program (WISP). This isn't just my opinion; if you handle consumer financial data (which includes most tax preparers and financial advisors), the FTC Safeguards Rule requires it.

The "Qualified Individual"

One of the biggest mistakes I see is businesses assuming "the IT guy" is handling security. The law now requires you to designate a Qualified Individual to oversee your security program. This doesn't have to be a full-time employee, but it must be someone who knows what they're doing. If that’s you, the owner, and you don't know the difference between EDR and a firewall, you're at risk.

The 3-2-1-1-0 Backup Rule

Backups are your last line of defense, but attackers now spend their first few days in your system looking for your backups to delete them. To be safe in 2026, I recommend the 3-2-1-1-0 rule:

  • 3 copies of your data.
  • 2 different media types.
  • 1 copy offsite.
  • 1 copy offline (immutable/air-gapped).
  • 0 errors after regular testing.

Step 2: Identification (The 6 AM Phone Call)

I once got a call from a client at 6 AM. He was at the office early and noticed his mouse moving on its own. An attacker was actively dragging files into a zip folder. Because we had a plan, he knew exactly what to do: he didn't turn the computer off (which could destroy evidence), he simply unplugged the network cable and called us.

Identification is the hardest part. On average, it takes 181 days to identify a breach and another 60 days to contain it (IBM 2025). That’s over seven months where a criminal has access to your client’s social security numbers, bank details, and private communications.

Watch for These Red Flags:

  • AI-Driven Phishing: Emails that look and sound exactly like you. Deepfake audio calls from "the boss" asking for an urgent wire transfer are no longer science fiction—they are a daily reality in 2026.
  • Shadow AI: Employees using unauthorized AI tools to process client data. If your staff is pasting sensitive contracts into a free AI tool to "summarize" them, that data is now in the public domain.
  • Strange Login Times: If your office manager is logging in from a foreign country at 2 AM, and she isn't on vacation, you have a problem.

Step 3: Containment (Stopping the Bleed)

The goal of containment is simple: stop the attack from spreading without destroying the clues we need to find out how it started. I've seen business owners panic and wipe their entire server the moment they see a ransom note. Don't do this. If you wipe the server before the forensics team arrives, you might invalidate your cyber insurance claim and you definitely won't know if the attacker still has a backdoor into your cloud accounts.

Immediate Actions:

  1. Isolate: Disconnect the affected devices from the internet. Disable the Wi-Fi. Unplug the Ethernet.
  2. Change Passwords: From a known clean device, change all administrative passwords, especially for your email (Office 365/Google Workspace) and your cloud backups.
  3. Enable MFA: If you don't have Multi-Factor Authentication (MFA) on every single account, turn it on now. 80% of breaches could be prevented by properly implemented MFA.

Step 4: Eradication and Recovery

Eradication is the "deep clean." This is where we remove the malicious code and, more importantly, close the hole they used to get in. If you just restore your files but don't patch the vulnerability or change the compromised password, the attacker will be back in your system within 48 hours. I’ve seen it happen, and the second time is always more expensive.

The Recovery Timeline

Recovery is not a "one-click" process. You have to prioritize. What do you need first? Usually, it's email and your line-of-business software. I tell my clients to expect a 7 to 14-day window for full recovery after a major ransomware event. If your business can't survive two weeks of no revenue, you need to invest more in the "Preparation" phase.

Step 5: Post-Incident and Lessons Learned

After the dust settles, you have one more job: the Post-Mortem. This is where we look at the Lessons Learned. Why did it happen? Was it a technical failure or a human one? Use this time to update your response plan. If your staff was tricked by a phishing link, it's time for better training. If your IT provider missed a patch for six months, it might be time for a new IT provider.

"Cybersecurity should help you make better decisions—not bury you in technical noise. The best plan is the one your team actually knows how to execute when the pressure is on." — Kevin Mabry

Frequently Asked Questions

Does my small business really need a written response plan?

Yes. Beyond the tactical benefits, it is now a regulatory requirement for many industries under the FTC Safeguards Rule and various state laws. In 2026, if you have a breach and cannot produce a written plan, you are much more likely to face heavy fines and denied insurance claims.

Should we pay the ransom?

In 2026, the trend has shifted. According to the latest data, 64% of victims now refuse to pay. Paying a ransom doesn't guarantee you get your data back, and it marks you as a "payer" in criminal databases, making you a target for future attacks. My advice: invest that money in better recovery systems instead.

How often should we update our incident response plan?

At least once a year, or whenever you make a significant change to your technology (like moving to a new cloud platform). I recommend a Tabletop Exercise—a one-hour meeting where you walk through a "what if" scenario with your leadership team.

Will my current IT provider handle this automatically?

Don't assume. Most generic IT support is focused on functionality, not security. Ask them specifically for your Incident Response Plan and your WISP. If they look at you blankly, you have a major gap in your protection.

Conclusion: The Choice Is Yours

You can continue to treat cybersecurity as a generic IT expense, or you can see it for what it is in 2026: a core component of your business's resilience. Protecting your client's data is part of the professional service you provide. It’s no different than locking your office door at night—it’s just that the door is now digital and the burglars are using AI to pick the lock.

If you're feeling overwhelmed, start small. Identify your most sensitive client data and make sure it's behind MFA and a solid backup. Then, write down who you would call first if everything went sideways. That’s the beginning of a plan. If you need help building the rest, that’s what we’re here for. Don't wait for the 6 AM phone call to find out your strategy isn't working.

Watch: Ransomware Attack Response Small Medical Practice Playbook

13 viewsJul 7, 2026Watch on YouTube →
KM

Kevin Mabry

Founder & CEO, Sentree Systems

Kevin Mabry is the founder and CEO of Sentree Systems, a cybersecurity company serving small professional service firms with under 100 employees. Since starting his business in 1999, Kevin has spent more than 26 years helping organizations protect sensitive information and make smarter technology and security decisions.

His work focuses on helping business owners protect client data, reduce cyber risk, and avoid the operational disruption caused by ransomware, account takeovers, phishing, and other preventable threats. Kevin is known for explaining cybersecurity in plain English without vendor hype, unnecessary jargon, or treating cybersecurity like generic IT support.

Take Action

Is your business protected?

Get a free security assessment. We'll identify your biggest risks and give you a clear, plain-English action plan — no obligation.

Schedule Your Free Assessment