Someone calls you at 8am. Files will not open, there is a message on the screen demanding payment, and three people are asking what they should do. What happens in the next hour will matter more than anything you do in the following week, and an incident response plan is simply those decisions made before the phone rang.
It is also the easiest hour in which to make things permanently worse. Powering off the wrong machine, deleting the ransom note, replying from an email account the attacker is already reading. Each of those is an instinctive response and each destroys something you will need. An incident response plan exists so nobody has to make those calls under pressure. If you do not have one yet, this is the order to work in.
Your incident response plan starts in the first ten minutes
Three actions, in this order, before anything else. A good incident response plan reduces these to a card someone can follow without thinking.
- Disconnect, do not power off. Unplug the network cable and switch off Wi-Fi on anything affected. This stops the spread to other machines and to your backups. Shutting a machine down destroys memory-resident evidence that determines how the attackers got in, so power off only if you genuinely cannot isolate it any other way.
- Move the conversation off email. If someone is in your mailbox they are reading your response in real time, including the message where you tell everyone what you have found. Switch to phone calls or a channel on a different system.
- Call your IT provider by phone. Not email. This is the point at which a good incident response plan has already told you which number to ring and who rings it.
Four things that make it worse
Every one of these is a natural reaction, and every one costs you something. They are worth listing explicitly in an incident response plan for that reason.
- Tidying up. Do not wipe, reinstall, or clean the affected machines. It feels productive and it destroys the evidence your investigators and your insurer both need.
- Deleting the ransom note or the suspicious email. Leave the originals exactly where they are. Screenshots are useful additions, not replacements.
- Paying immediately. Nothing about that decision improves by being made in the first panicked hour.
- Telling everyone before you know anything. Staff need to know to stop working on affected systems. Customers and suppliers need accurate information, which you do not have yet.
Who to call, and why the order matters
This is the part most businesses get wrong, and it is the part an incident response plan is genuinely useful for.
Call your cyber insurer early, before you engage anyone. Many policies require you to use their nominated incident response team, and engaging your own forensics firm first can reduce or void what they pay. Businesses discover this at the worst possible moment. If you are unsure what your policy demands, the questions worth answering are the same ones on the renewal form, and we went through them in our guide to answering cyber insurance renewal questions.
Then your IT provider or incident response team, if the insurer has not appointed one. Your incident response plan should record which of those two applies.
Then your bank, if money moved. Immediately, and by phone.
Then legal counsel, before you notify anyone externally. Breach notification carries deadlines and getting the wording wrong creates a second problem on top of the first.
Writing those four numbers down in advance, with names against them, is most of what an incident response plan does. The rest is detail.
If money was wired, the clock is different
Business email compromise runs on a much shorter timescale than ransomware, and an incident response plan that treats both the same will cost you money here.
Call the bank first and ask them to recall the transfer and freeze what they can. Then file with the FBI’s Internet Crime Complaint Center. The timing is the critical part: the FBI’s Recovery Asset Team has the best chance of clawing funds back when wire fraud is reported within 72 hours, and it succeeds in roughly 70% of cases reported inside that window.
Seventy percent is a genuinely good outcome in a field that rarely offers one, and it depends almost entirely on speed. Whoever notices the missing money needs to know that calling the bank comes before working out how it happened, before telling the client, and before anyone starts assigning blame. That is a line worth putting in the incident response plan in plain language.
The ransom decision
If it is ransomware, this becomes the question everyone focuses on, usually too early, and usually because no incident response plan said who decides it.
The FBI does not recommend paying. Payment does not guarantee your files come back, it marks your business as one that pays, and the money funds the next attack. It is still ultimately your decision, but it is one to make with law enforcement, your incident response team, and your insurer, not alone at 9am with a countdown timer on screen.
Two things are worth checking before the question even arises. A free decryption tool already exists for a number of ransomware families, so it is worth confirming which one you are dealing with. And the real answer to the ransom question is usually decided months earlier, by whether your backups are isolated and tested. Understanding how small business ransomware attacks actually work makes it clearer why attackers go after backups first, and why tested disaster recovery is what turns a business-ending event into a bad two weeks.
Reporting is not optional, and not only for you
Your incident response plan should name the reporting destinations in advance. In the United States, file with IC3 and report to CISA. Reporting helps your own recovery, feeds intelligence that protects other businesses, and is sometimes legally required.
Separately, if personal data about customers or staff was exposed, you may be legally obliged to notify a regulator and the affected people, sometimes within 72 hours. In the US that means state breach-notification laws, which vary considerably and can apply based on where your customers live rather than where you are. A Texas business with clients in several states may face several different deadlines simultaneously. This is precisely why legal counsel comes before external notification, and why the incident response plan should name the lawyer rather than leaving it to a search at the time.
The three conversations you will have to manage
Technical recovery gets the attention. Communication is what people actually remember, and it is the part most likely to be handled badly because nobody rehearsed it.
- Staff, immediately. They need to know to stop using affected systems and to route questions to one person. They do not need speculation. Say what is known, say what is not, and say when you will update them next. Silence gets filled by guesswork, and guesswork reaches customers.
- Customers, once you know something. Accurate and slightly late beats fast and wrong, because a correction is a second incident. One named spokesperson, one approved holding statement, and no side conversations from other staff. If a client’s data was involved, that conversation is a phone call rather than an email.
- Suppliers and partners, if they are exposed. Anyone connected to your systems, and anyone whose credentials might have been in a compromised mailbox. This one gets forgotten and it is how an incident spreads beyond your business.
Each of those has a named owner in a working incident response plan, because during an incident the person best placed to talk to customers is usually the person most needed elsewhere. Deciding that in advance costs nothing.
Writing an incident response plan before you need one
Everything above is easier if the decisions were made in advance. An incident response plan does not need to be a document anyone would enjoy reading, and for a small business it fits on two pages.
- The call list. Insurer, IT provider, bank, lawyer. Names, direct numbers, policy number. Printed, because the network may be down.
- Who decides. One named person who can authorize disconnecting systems and spending money, plus a deputy for when they are unreachable.
- The out-of-band channel. Where the team communicates when email is compromised. Agree it now, because agreeing it during an incident means using the channel you are trying to avoid.
- What matters most. Which three systems, if unavailable, stop the business trading. Recovery effort goes there first.
- Where the backups are and when they were last tested. A backup nobody has restored from is a hypothesis, not a plan.
- Who talks to customers. One person, one approved holding statement written in advance.
For businesses around League City and Webster serving clients under contract, such as engineering firms, accounting practices, and medical offices, there is usually a contractual notification obligation buried in a client agreement that nobody reads until it matters. Check what your own contracts commit you to before an incident forces you to find out, and put those obligations in the incident response plan alongside the regulatory ones. Your cyber insurance position should be reviewed at the same time, since the two interact more than most businesses expect.
Review the incident response plan annually, and after any near miss. A plan describing systems you no longer run is worse than no plan, because it produces confident wrong decisions.
Frequently Asked Questions
What is the very first thing to do in a cyberattack? Disconnect the affected devices from the network without powering them off, then call your IT provider by phone rather than email. Isolation stops the spread; staying powered on preserves the evidence that explains how it happened.
Should I turn the computer off if I see a ransom note? Preferably not. Unplug it from the network instead. Powering down wipes memory-resident evidence that investigators use to determine the entry point. Shut it down only if you cannot isolate it any other way.
We wired money to a scammer. What do we do right now? Call the bank immediately and ask for a recall, then file with IC3. Reporting within 72 hours gives the FBI’s Recovery Asset Team its best chance, and it recovers funds in about 70% of cases reported in time. Everything else waits.
Do we have to tell our customers? Possibly, and possibly within a deadline. It depends on whether personal data was exposed and which state breach-notification laws apply, which may be several if your clients are spread across states. Speak to legal counsel before notifying anyone.
How long does an incident response plan take to write? The two-page incident response plan above takes an afternoon. The value is almost entirely in the call list and the named decision-maker, so if you only do one part, do that one.
Nobody assembles an incident response plan during an incident. The businesses that come through these events well are the ones who spent an afternoon on it while nothing was wrong, and the ones that struggle are rarely the ones with the weakest technology. They are the ones where nobody knew who to call first. If you want to know where the gaps in your own response would show up, a cyber shield review covers detection and recovery together.
Featured Image Credit: Unsplash
