Incident Response for a Business Without a Security Team

Incident response sounds like something with a war room and a hotline. For a business of fifteen people it is much simpler, and the version that actually helps fits on two pages.

What it does is remove the first hour of confusion. Most of the damage in a small business incident comes from nobody being sure who is in charge, whether to tell anyone, or what to do first.

Decide what counts before it happens

If everything is an incident, nothing gets escalated. If nothing is, problems get absorbed quietly by whoever noticed.

Write a short definition. Something is an incident if customer or employee data may have been exposed, if money may have gone to the wrong place, if a system the business depends on is unavailable, or if somebody has lost control of an account.

Everything else is a support issue. That single line saves an enormous amount of hesitation.

One place to report, and a fast human response

The single most valuable control you have is somebody speaking up quickly. It is also the most fragile.

Give people one route, an address or a person, and make sure it is answered within the hour during working time. Say out loud, more than once, that nobody gets in trouble for reporting something that turns out to be nothing, and that reporting late is the only real mistake.

The first time somebody is made to feel foolish for reporting, you lose the control entirely.

The businesses that come out of these things well are not the ones that never got caught. They are the ones where somebody said something within the hour.

Name the three roles

You do not need a structure. You need three names, and a deputy for each.

Somebody who decides. They confirm it is an incident, authorise spending, and make the call on what gets said externally. Somebody who coordinates. They keep the log, chase the actions and stop three people doing the same thing. Somebody who communicates. Staff, customers, and any third party who needs to know.

In a small business two people often cover all three, which is fine as long as it is decided in advance rather than during.

Write the first hour down

People do not improvise well under pressure, so the first steps should be written and boring.

  1. Contain what you can. Change the password, revoke the sessions, take the affected account offline, stop the payment run.
  2. Do not delete anything. Move the email to a folder rather than the bin. Keep the logs. You may need them.
  3. Write down what you know, with times. A plain running note. It will be the most useful document you have.
  4. Call the decision maker. Even if you think you have it handled.
  5. Check whether money moved. If it did, the bank call comes before anything else.

Know who you would call

Have the numbers before you need them. Your bank's fraud line. Your IT provider, with an out of hours route if you have one. Your insurer, because many policies require prompt notification. Whoever handles legal for you. And the main contact at any customer whose data might be involved.

Keep that list somewhere reachable when the systems are not. Printed, or on a phone.

Decide the communication position early

The instinct is to say nothing until everything is known, which usually means saying nothing for a week while rumours fill the gap.

A better default is early and honest, with limits. Here is what we know, here is what we are doing, here is when we will update you again. Then meet that next update time even if the answer is that there is nothing new.

Be careful about speculating on cause or scale before you know, because early guesses are usually wrong and they are remembered.

Check the obligations

Depending on your industry and where your customers are, there may be a duty to notify someone within a set period. Find out which of those apply to you now, while it is an academic question. It is a much worse conversation to be having on day two of an incident.

Write it up afterwards

A week later, sit down for half an hour and write one page. What happened, in sequence. What we did well. What was slower than it should have been. What we are changing, with names and dates.

Almost every small business incident traces back to something ordinary. An account that should have been closed, a payment change nobody verified, a backup that was never tested, a shared login. The write up is what turns the experience into those fixes rather than just relief.

Where we fit

We are a business consulting firm rather than a security vendor, and this is the process half of the problem. Writing the definition, naming the roles, building the contact list, documenting the first hour, and running the short exercise that shows you where the gaps are.

Two pages and one hour of practice is not much. It is also considerably more than most businesses of this size have.

We work with businesses in Pompano Beach, across South Florida and remotely to write this down and run the short exercise. Book a consultation, or visit www.expertechsolution.com.

Related reading

Previous
Previous

The Handover Document That Survives a Departure

Next
Next

Saying No to the Wrong Client