Cyber incident response for small businesses without a security team
Most small and medium businesses do not have a security operations centre, an incident-response retainer or a dedicated IT security lead. What they usually have is an owner or manager, an outsourced IT provider or MSP, an accountant, and a growing sense of urgency the moment something looks wrong.
This page is not about one specific type of attack. It is about the coordination problem that shows up whenever an incident happens without a plan already in place: who decides what, in what order, and how to avoid the mistakes that make a bad day worse. Cyber Crisis Desk exists to turn that coordination into a guided, tracked process.
Why a structured plan matters
Under pressure, the natural instinct is to fix the visible symptom immediately — shut down a server, wipe a laptop, change a password — before anyone has worked out what actually happened. That instinct is understandable and sometimes right, but it can also destroy the evidence you need for an insurance claim, a regulator conversation, or a proper root-cause fix, and it can leave a persistent access point untouched while you deal with the symptom you happened to notice first.
A structured plan does not need to be elaborate. It needs to answer three questions quickly and consistently every time: what do we stop first, what do we keep as evidence, and who needs to know. Businesses that have thought through those answers in advance, even briefly, consistently make calmer and cheaper decisions than those improvising for the first time mid-incident.
What usually goes wrong without one
- Nobody is clearly in charge, so decisions stall or get made twice, differently.
- Systems get wiped, rebooted or reinstalled before anyone captures logs or screenshots.
- The IT provider assumes the owner is handling notifications; the owner assumes the IT provider is.
- Staff hear rumours before they hear facts, and start improvising their own responses to customers.
- Insurance and reporting deadlines are missed simply because nobody checked them early.
- The same gap that allowed the incident is left open because attention moves on once things look normal again.
The first hour: practical coordination
- Name one coordinator. It does not need to be a technical person — it needs to be someone who can make decisions and keep a written record of them.
- Get a plain-language description of what is known. What was noticed, by whom, when, and on which system. Resist the urge to fix anything before this is written down.
- Contain without destroying evidence. Isolating a device from the network is usually safer and just as effective as wiping it.
- Bring in your IT provider or MSP with the facts gathered so far, rather than a vague description of “something's wrong.”
- Check whether money, customer data or continuity of trading is at risk — this shapes how fast the next calls (bank, insurer, authorities) need to happen.
- Decide what staff and customers are told, and by whom, so the message is consistent.
Protecting operations and continuity
For a small business, the practical damage often comes less from the technical breach itself and more from the disruption to trading: an unavailable till system, a locked booking calendar, a supplier unable to reach you, or a customer losing confidence. Alongside the technical response, it is worth actively managing:
- Which systems are essential to keep trading, and whether a manual fallback exists for each.
- Whether backups are intact, recent and, critically, not connected to the affected system.
- How to communicate delays or disruption to customers without over- or under-stating the situation.
- Whether any contractual or service-level obligations to customers or partners are affected.
Who does what
- Owner or manager — makes the final call on containment, communication and spend, and keeps the overall timeline.
- IT provider or MSP — handles technical containment, system checks and restoring from clean backups.
- Accountant or bookkeeper — checks for financial irregularities, unauthorised payments or unusual invoices, and helps assess cost impact.
- Insurer — confirms cover, notification deadlines and any approved suppliers you are expected to use.
- Bank — contacted immediately if any payment or account detail may have been exposed or money has moved.
- Authorities and regulators — for example national fraud-reporting or cyber-reporting channels, and a data-protection authority such as the ICO in the UK, if personal data is involved.
- Staff — briefed with clear, factual guidance on what to say and what not to click, forward or discuss externally.
Evidence and reporting discipline
Keeping a simple, consistent record pays off later, whether for an insurance claim, a regulator query or simply understanding what to fix. Aim to capture, from the start:
- A timeline: what happened, when it was noticed, and every action taken since.
- Screenshots or logs of anything unusual before it is changed or removed.
- Copies of any suspicious messages, invoices or files involved.
- A record of who was told what, and when.
- Confirmation of what was reported to whom, with dates and reference numbers.
How Cyber Crisis Desk helps
A free emergency triage asks what happened and how urgent it is, then selects the relevant playbook and builds an Immediate Rescue Plan — so a business with no security team gets a sensible order of operations instead of a blank page.
- Client Next Action gives the coordinator one clear step at a time, reducing the chance of skipped or duplicated work.
- Role-friendly guidance helps explain to an IT provider, accountant or insurer exactly what is needed from them.
- Evidence requests prompt the right screenshots and logs before they disappear, stored in a private case.
- Structured reports turn the case into something you can hand to an insurer, bank or authority without re-writing it from memory.
- Monitoring and closure keeps the case open until follow-up checks actually pass, rather than assuming the problem is solved once things look calm.
See how the guided workflow fits together or compare the plans and the one-time Emergency Pass.
Clear limitations
- Cyber Crisis Desk does not replace a qualified incident-response team for incidents that are severe, regulated or contested — for example large-scale ransomware, significant regulated-data exposure, or anything likely to involve litigation.
- We do not provide legal advice and do not make legal or regulatory determinations for you.
- We cannot access, change or investigate your systems directly; your IT provider or administrator carries out technical actions.
- We do not guarantee any outcome, and we do not undertake tracing or offensive action of any kind.
Common questions
- We don't have an IT department at all. Can we still use this?
- Yes. The workflow is built for businesses without an internal security team, and it explains each step in plain language, including where you may need to involve an external IT provider.
- Our IT provider is already handling it. What does Cyber Crisis Desk add?
- It helps you coordinate everything around the technical fix: evidence, timeline, who to tell, and reporting deadlines, so nothing falls through the gap between the technical response and the business response.
- How do we know if this is serious enough to need a specialist incident-response firm?
- Signs it may be beyond guided self-service include large volumes of sensitive data, ongoing attacker access you cannot contain, ransomware affecting core systems, or any indication of legal or regulatory exposure. Cyber Crisis Desk will flag when a case looks like it needs that escalation.
- What is the very first thing we should do?
- Name one person to coordinate the response and start a written timeline before making changes. Containing the issue without destroying evidence usually matters more than speed alone.
Related incident help
- Data breach concernsWork out what data was exposed, who to tell and what to document.
- Ransomware responseIsolate, protect backups, assess scope and decide next steps calmly.
- Business email compromiseInvoice and payment fraud through a trusted mailbox — contain it and involve your bank.
- How Cyber Crisis Desk worksTriage, playbooks, rescue plan, evidence, recovery, reporting and closure.
Work through it with a plan
Emergency triage is free and takes a couple of minutes.