Cyber Security Basics · Lesson 9 of 10
Quick answer: How small businesses can prepare for cyber incidents, report problems quickly, contain damage and maintain a clear decision log.
Even a well-protected business can experience a cyber incident. The quality and speed of the response can determine whether the event remains manageable or becomes a prolonged business disruption.
What counts as a cyber incident?
- A compromised email or cloud account.
- Ransomware or malware.
- A stolen or lost business device.
- An employee entering credentials into a phishing site.
- An unauthorised payment.
- A compromised website or domain account.
- Unexpected data loss or exposure.
- A supplier reporting a breach that affects your organisation.
Make reporting easy
Employees should know exactly who to contact. They should report suspicious activity immediately, even if they think they caused the problem. A no-blame reporting culture improves the chance of early containment.
Preserve evidence
Do not automatically wipe devices, delete emails or remove logs before the incident has been assessed. Evidence may be needed to understand the route of compromise, affected accounts and required response.
Contain the problem
Containment may include isolating a device, revoking sessions, resetting credentials, blocking malicious accounts, removing forwarding rules or contacting a bank. The correct action depends on the incident, so follow an agreed response process rather than improvising.
Use a trusted communication route
If company email may be compromised, establish another trusted way for the response team to communicate. Avoid discussing containment plans through a mailbox that an attacker may be reading.
Keep a decision log
Record what was observed, when actions were taken, who authorised them and what systems were affected. This helps technical investigation, recovery, insurance and any later regulatory or contractual review.
Prepare contact information in advance
Keep key details for IT support, cyber security support, insurers, banks, legal advisers, important suppliers and decision-makers somewhere accessible even if normal systems are unavailable.
What to do after this lesson
Create a one-page incident contact sheet and agree who leads the response if a business-critical account is compromised.
Frequently asked questions
Should we immediately reset every password during an incident?
Not automatically. Resetting the right accounts can be important, but the response should be coordinated so evidence is preserved and attackers are removed effectively.
What should an employee do after entering a password into a phishing site?
Report it immediately and follow the incident process. The account should be treated as potentially compromised.
Do small businesses need an incident response plan?
Yes. Even a short plan with contacts, responsibilities, containment steps and recovery priorities is far better than starting from nothing during an attack.
Useful UK guidance
Put the lesson into practice
39Security helps small businesses turn cyber security guidance into practical controls and owned actions.
- Take the free cyber security assessment
- View practical cyber security training dates
- Explore Cyber Essentials readiness support
- See managed cyber security services
- Read the small business cyber security FAQ