Cyber Incident Response: What a Small Business Should Do First

How small businesses can prepare for cyber incidents, report problems quickly, contain damage and maintain a clear decision log.

Cyber Security Basics · Lesson 9 of 10

Quick answer: How small businesses can prepare for cyber incidents, report problems quickly, contain damage and maintain a clear decision log.

Even a well-protected business can experience a cyber incident. The quality and speed of the response can determine whether the event remains manageable or becomes a prolonged business disruption.

What counts as a cyber incident?

  • A compromised email or cloud account.
  • Ransomware or malware.
  • A stolen or lost business device.
  • An employee entering credentials into a phishing site.
  • An unauthorised payment.
  • A compromised website or domain account.
  • Unexpected data loss or exposure.
  • A supplier reporting a breach that affects your organisation.

Make reporting easy

Employees should know exactly who to contact. They should report suspicious activity immediately, even if they think they caused the problem. A no-blame reporting culture improves the chance of early containment.

Preserve evidence

Do not automatically wipe devices, delete emails or remove logs before the incident has been assessed. Evidence may be needed to understand the route of compromise, affected accounts and required response.

Contain the problem

Containment may include isolating a device, revoking sessions, resetting credentials, blocking malicious accounts, removing forwarding rules or contacting a bank. The correct action depends on the incident, so follow an agreed response process rather than improvising.

Use a trusted communication route

If company email may be compromised, establish another trusted way for the response team to communicate. Avoid discussing containment plans through a mailbox that an attacker may be reading.

Keep a decision log

Record what was observed, when actions were taken, who authorised them and what systems were affected. This helps technical investigation, recovery, insurance and any later regulatory or contractual review.

Prepare contact information in advance

Keep key details for IT support, cyber security support, insurers, banks, legal advisers, important suppliers and decision-makers somewhere accessible even if normal systems are unavailable.

What to do after this lesson

Create a one-page incident contact sheet and agree who leads the response if a business-critical account is compromised.

Frequently asked questions

Should we immediately reset every password during an incident?

Not automatically. Resetting the right accounts can be important, but the response should be coordinated so evidence is preserved and attackers are removed effectively.

What should an employee do after entering a password into a phishing site?

Report it immediately and follow the incident process. The account should be treated as potentially compromised.

Do small businesses need an incident response plan?

Yes. Even a short plan with contacts, responsibilities, containment steps and recovery priorities is far better than starting from nothing during an attack.

Useful UK guidance

Put the lesson into practice

39Security helps small businesses turn cyber security guidance into practical controls and owned actions.

Course overview ← Previous lesson Next lesson →