Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call
HomeBlogCybersecurity

Incident Response Plan for Small Business: 6 Steps

Cybersecurity operations center at night with wall monitors showing network maps and one red breach alert screen

An incident response plan is a short written playbook that says who does what in the first hours of a cyberattack: who gets called, who can shut systems down, who talks to customers, and in what order. Most small businesses do not have one, so when a breach hits they lose the first critical hours arguing about what to do. This guide walks through the six steps that matter, in plain language, so you can write a plan your team will actually use.

The stakes are not abstract. IBM put the global average cost of a data breach at USD 4.44 million in its 2025 report, and found organizations took an average of 241 days to identify and contain a breach. A small business will not lose millions, but the pattern holds: the longer an attacker sits undetected and the more scattered your response, the more it costs you.

What is an incident response plan, exactly?

An incident response plan is a documented, step-by-step process for detecting, containing, and recovering from a security incident. It names the people responsible, defines what counts as an incident worth acting on, and lists the exact actions for the first hour, the first day, and the week after. Good plans fit on a few pages and live somewhere you can reach without your network.

Why does a small business need one?

Because attacks do not wait for business hours, and panic makes bad decisions. Ransomware crews and business email compromise scammers count on confusion. When nobody knows who has authority to disconnect a server or freeze a wire, the attacker gets more time. A plan replaces "what do we do now?" with "we are on step three." That difference is measured in dollars and downtime.

The six steps of a small business incident response plan

1. Prepare before anything happens

Preparation is the work that pays off during a crisis. Write down your response team and their phone numbers, including your IT provider, your cyber insurance carrier, and outside counsel. Confirm you have working, tested backups. Keep a printed or offline copy of the plan, because if your network is locked, a plan stored only on that network is useless.

2. Detect and confirm the incident

Decide in advance what triggers the plan: a ransomware note, a vendor telling you they were breached, a bank flagging a fraudulent transfer, or an employee reporting a stolen laptop. Someone has to make the call that "this is an incident." Give one or two people that authority so the plan starts moving instead of sitting in someone's inbox.

3. Contain the damage

Containment is about stopping the spread without destroying evidence. Isolate affected machines from the network rather than wiping them. Disable compromised accounts and reset the passwords tied to them. If money is moving, call the bank immediately to try to recall the transfer. Speed matters most here, which is why the authority question in step two cannot wait for the crisis.

4. Eradicate the threat

Once the incident is contained, find and remove what caused it: the malware, the rogue account, the mail rule an attacker set up to hide their tracks. This is where an experienced hand matters. Missing a single hidden foothold means the attacker walks right back in a week later. If your team is thin, this is the moment to lean on a security partner.

5. Recover and restore operations

Bring systems back in a deliberate order, restoring from clean backups you have verified are not themselves infected. Watch restored systems closely for signs the problem returns. Our backup and disaster recovery FAQ covers how to make sure the backups you are counting on will actually work when you need them.

6. Review what happened and fix the gap

Within a week or two, walk through what happened while it is fresh. What let the attacker in? What slowed your response? Update the plan with the answers. Every incident, even a near miss, is a free lesson in where your defenses are thin.

Who should be on the response team?

For most small businesses it is a small group: an owner or manager who can authorize decisions and spending, whoever handles IT, someone for customer and staff communication, and outside experts on call. You do not need a large security department. You need clear roles, current phone numbers, and one person empowered to act when minutes count. A virtual CISO can fill the security-leadership seat without a full-time hire.

By The NetSys Group Team. The NetSys Group has delivered managed IT, cybersecurity, and cloud services since 1998. Our engineers hold degrees in electrical and computer engineering and are certified Microsoft and Cisco instructors, serving businesses across NY, NJ, CT, PA, and Southwest Florida.

Frequently asked questions

How long should an incident response plan be?

Short enough to use under pressure. A few pages is plenty for most small businesses: a contact list, the definition of an incident, and the actions for the first hour, first day, and first week. A 40-page document nobody reads is worse than a one-page checklist people actually follow.

Do we legally have to report a data breach?

Often yes. Every US state has breach-notification laws, and rules vary by industry and the type of data exposed. Healthcare, financial, and firms handling personal data face specific timelines. Build the reporting question into your plan and confirm the details with counsel and your insurer before an incident, not during one.

Should we pay a ransomware demand?

Paying is a last resort with no guarantee you get your data back, and it can carry legal risk. The better answer is tested, offline backups that let you restore without paying. Decide your position ahead of time, in writing, so the choice is not made in a panic at 2 a.m.

How often should we test the plan?

At least once a year, and after any major change to your systems or staff. A short tabletop exercise, where you talk through a realistic scenario for an hour, surfaces gaps like out-of-date phone numbers or unclear authority long before a real attacker finds them.

What is the difference between an incident response plan and disaster recovery?

Incident response handles the security event itself: detecting, containing, and removing the threat. Disaster recovery handles getting operations back after any disruption, including fires and outages, mostly through backups and restore procedures. They overlap during a cyberattack and work best written together.

Get help before you need it

The worst time to write your first incident response plan is during an attack. If you do not have one, or you are not sure the one you have would hold up, contact The NetSys Group for a complimentary risk assessment. We will walk your systems, pressure-test your response, and help you put a plan in place while things are quiet. Learn more about our cybersecurity services.

Reading is free. So is knowing where you stand.

Turn insight into action.

Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.