Cyber incidents do not wait for a convenient time, a full IT team or a larger turnover. A ransomware screen can appear while you are preparing payroll. A compromised Microsoft 365 or Google Workspace inbox can be used to redirect a supplier payment within minutes. A phone left in a taxi may contain access to customer records, accounting apps and password-reset emails.
For a small business, the first hour is about making a few sound decisions quickly: stop further damage, protect people and money, preserve the facts, and bring in the right help. That is exactly why every business needs a short written incident plan that can be used when the owner is stressed, the usual systems are unavailable and an outsourced IT provider is not answering immediately.
This is not a heavyweight corporate disaster-recovery manual. It is a practical, one-page operating plan for a sole trader, agency, shop, trades business, consultancy or growing employer. Print it, store a copy away from your usual computers, save it on a personal device, and review it with anyone who has authority over money, customer data or technology. The National Cyber Security Centre (NCSC) specifically advises small organisations to plan for cyber attacks so they can act quickly, define responsibilities and recover faster.
Why a written plan matters, even when IT is outsourced
Outsourcing IT changes who performs technical work; it does not outsource the decisions only the business can make. Your managed service provider may isolate a device, reset accounts or restore data. But somebody inside the business still needs to decide whether to pause payments, contact the bank, speak to customers, notify insurers, approve recovery priorities and assess a potential personal-data breach.
There is also a simple operational reality: the people who normally hold contact details, administrator access and knowledge of where data lives may be unavailable. If your email is compromised, your provider’s ticketing portal may be inaccessible. If ransomware affects shared files, staff may not be able to find the latest supplier list, insurance policy or phone number. A one-page plan puts the essentials outside the affected environment.
Small firms should avoid assuming that cloud software removes the need for incident response. Cloud services can improve resilience, but an attacker who steals an administrator’s credentials may be able to read mail, create forwarding rules, download records, alter payment details or delete data. The NCSC notes that email compromise can expose private information, enable impersonation and provide a route to reset passwords for other accounts.
A written plan also reduces harmful improvisation. It makes clear that staff should report promptly rather than hide a mistake; that nobody should negotiate with criminals or issue a public statement alone; and that recovery should be based on what keeps the business safe and trading, not simply on restoring the most familiar system first.
The one-page plan: copy this into your business template
Keep the following content to one A4 page where possible. Use plain language, named people and out-of-band contact methods. Do not store the only copy in the same shared drive or email account that could be affected.
1. Incident declaration and immediate rule
Declare an incident when: there is suspected ransomware or malware; an unknown login or email-sending activity; a lost or stolen work device; a misdirected email or file; suspected unauthorised access to customer data; a fraudulent payment request; or an IT supplier warns of compromise.
Rule: Any team member reports it immediately to the Incident Lead. No blame, no deletion, no guesswork and no public messaging without approval.
Incident Lead: [Name, personal mobile, alternative email].
Deputy: [Name, personal mobile].
Technical Lead/MSP: [24/7 phone, contract number, escalation contact].
Finance Lead: [Name, mobile].
Data Protection/Privacy Lead: [Name, mobile].
Customer Communications Lead: [Name, mobile].
In a micro-business, one person may fill several roles. That is fine. The essential point is that there is a named decision-maker and a back-up person. Put the names in the plan, rather than writing “the director” or “IT”.
2. First-hour actions: the universal checklist
- Start an incident log. Record the time the issue was discovered, who found it, what they observed, affected devices/accounts, actions taken and who authorised them. Use paper or a clean personal device if normal systems cannot be trusted.
- Contain without destroying evidence. Disconnect a suspicious computer from Wi-Fi, Ethernet and mobile tethering. Do not keep clicking, rebooting repeatedly, deleting messages or “cleaning up” folders before your IT provider has captured what it needs.
- Protect money. Tell the Finance Lead to pause unusual payments, changes to bank details and payment approvals. If a payment may have been redirected, call your bank using the number independently obtained from its official website or your records, not a number in a suspect email.
- Use a clean channel. Move coordination to phone calls, SMS, Signal or a pre-agreed personal email address. Do not assume the business mailbox, Teams, Slack or shared drive is safe.
- Call technical support. Give the MSP the facts, the incident-log time and your preferred call-back number. Ask it to confirm what it is doing, preserve logs and advise whether systems or identities should be isolated.
- Assess data exposure. Identify what personal data, commercial data and credentials may be involved. Start with the most sensitive material: identity documents, bank details, payroll, health or safeguarding information, passwords and customer contact lists.
- Escalate externally where necessary. For a live cyber attack affecting a UK business, the NCSC directs organisations to call 0300 123 2040. If fraud or financial loss is involved, make an appropriate report to Action Fraud and retain the reference number.
The aim is stabilisation, not a complete investigation. You can update the picture later. In fact, the ICO tells small organisations to start their breach log as soon as they discover an issue, even where it may turn out not to be reportable.
Scenario playbooks for the four incidents most small firms face
Ransomware: isolate first, then recover safely
Typical signs include files with unfamiliar extensions, inaccessible documents, a ransom message, unusual activity across shared folders or staff reporting that their files have changed at the same time. Treat it as a wider incident until proven otherwise.
- Immediately disconnect affected computers, laptops and tablets from wired, wireless and mobile networks.
- Tell staff not to connect external drives or USB backup devices. Disconnect backup media that is permanently attached where this can be done safely.
- Ask the MSP to determine the scope, preserve relevant logs, disable affected accounts where appropriate and check whether data may have been copied out as well as encrypted.
- Reset administrator and other relevant credentials in a controlled order, ensuring you retain access to recovery systems.
- Do not restore hastily. The NCSC advises checking both the backup and the device used for restoration are clean before restoring data.
- Record the ransom note, payment demand, cryptocurrency wallet address, filenames and time stamps. Do not engage from a personal account or make a payment decision in the first hour.
The UK authorities do not encourage, endorse or condone paying a ransom. Payment does not guarantee access to data, may leave systems infected and can make future targeting more likely. Your immediate recovery question should be: “What clean, verified data and systems do we need to operate safely?” rather than “How do we get every file back today?”
Compromised email: stop impersonation and payment fraud
A compromised inbox is a business-continuity problem, not merely a password-reset task. Attackers may read confidential correspondence, impersonate directors or suppliers, search for invoices and silently forward mail to themselves.
- From a clean device, contact the email provider or MSP and suspend active sessions, then secure the account.
- Check sign-in history, registered recovery methods, delegated mailbox access, connected applications, inbox rules and forwarding rules. The NCSC warns that criminals commonly use forwarding rules to obtain copies of messages and reset other passwords.
- Change the password for the compromised account and every account that reused it. Enable multi-factor authentication or passkeys where available.
- Review sent mail, deleted items, drafts, auto-replies and contacts for fraudulent messages or altered payment instructions.
- Warn internal staff and high-risk contacts through a verified channel: say that payment-detail changes must be confirmed by a known telephone number, and that messages from the account during the stated period may be unsafe.
- Check finance, accounting, payroll, domain registrar, cloud storage and social-media administrator accounts, because email may have been used to reset them.
Do not send a vague all-contacts warning unless there is a reason to do so. Start with people who received suspect messages, have invoices due, or could be tricked into sending money or personal information. Keep a list of who was warned and when.
Lost or stolen device: act before it reconnects
Report the loss immediately, even if you believe the screen lock is strong. The NCSC advises users to contact their IT helpdesk promptly because speed increases the options for preventing access to information.
- Record the device type, serial number, phone number, last known location, time last seen, user, installed business apps and whether storage encryption and screen lock were enabled.
- Ask the MSP to revoke sessions and tokens, remove the device from trusted access lists and use mobile-device-management or the relevant cloud account to locate or remotely wipe it where available.
- Change passwords or revoke credentials where there is a realistic possibility the device was unlocked, malware-infected or holding active sessions.
- Notify the mobile provider to block a missing SIM or eSIM if relevant.
- Consider a police report for theft, especially where insurance requires it. Preserve the crime reference and insurer notification details.
- Assess the data on the device and accessible through it, not only files saved locally. A logged-in mailbox or CRM can make a lost phone a data incident.
A remote wipe is valuable, but it may not complete until the device powers on and connects to a network. Do not treat the command as proof that data is safe; record whether it was sent and whether completion was confirmed.
Customer-data exposure: contain, assess, document and communicate
A personal-data breach can be accidental or malicious. It may involve an emailed spreadsheet sent to the wrong recipient, a stolen laptop, an exposed cloud folder, ransomware, unauthorised access or the loss of records. Your first job is to stop access or recover the data where possible, then understand the likely impact on people.
- Identify the categories and approximate volume of data: names, emails, addresses, account details, identity documents, special-category data, children’s data, passwords or payment information.
- Identify affected people and the practical harm that could follow, such as fraud, identity theft, discrimination, distress, physical risk or targeted phishing.
- Take containment steps: recall an email if possible, remove public sharing, revoke links and access, ask an unintended recipient to delete material and confirm deletion, or secure the affected account.
- Document the facts, the risk assessment, all decisions and mitigations. Keep this record even if you conclude notification is not required.
- Contact your privacy adviser, insurer or legal adviser if the facts are complex, but do not wait for a perfect investigation before starting the assessment.
Under UK GDPR, a controller must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of a personal-data breach where it is likely to create a risk to individuals’ rights and freedoms. If the likely risk is high, affected individuals must also be informed without undue delay. The ICO’s current guidance emphasises “report early, update later”: an initial report can be followed with additional verified detail. Use the ICO’s breach guidance and self-assessment resources rather than relying on assumptions.
Evidence preservation: what to keep and what not to do
Evidence is not just for police or insurers. It helps your IT provider establish entry points, supports an ICO assessment, enables accurate customer communications and makes insurance claims less painful. Preserve a copy of suspicious emails with full headers where practical; screenshots of ransom messages, login alerts and unusual settings; account sign-in logs; file names and time stamps; affected device details; bank correspondence; and the incident log itself.
Keep originals intact wherever possible. Take photographs or screenshots rather than altering the material. Do not wipe, factory-reset or reinstall an affected device until your technical lead has advised on evidence capture, unless immediate containment requires it. Do not download a “decryptor”, run unapproved cleanup software, plug in a backup drive or forward a malicious attachment around the team for inspection.
Give one person ownership of the log. Each entry should say who did what, at what time, based on whose instruction, and what result followed. Separate known facts from assumptions. “Three files were found in a public folder at 10:20” is useful; “the attacker stole everything” is not a fact unless evidence supports it.
Recovery priorities: restore safe trading, not just technology
Before an incident, agree the order in which you will restore services. A useful priority list normally starts with: customer and staff safety; banking and payment controls; primary email and identity systems; phones and customer contact routes; the data needed to deliver current work; accounting and payroll; your website or booking system; then historic archives and lower-priority tools.
For example, a five-person design studio may be able to work temporarily from a clean laptop, a verified phone number and a restored list of active projects. It should restore banking controls and the director’s email before trying to rebuild every old project folder. A retailer may prioritise card-processing alternatives, point-of-sale access and supplier communications. A care-related business should elevate availability and confidentiality of service-user information.
Every recovery action needs an owner and a safety check. Confirm that systems are patched, accounts use strong unique credentials and multi-factor authentication, former access routes have been removed, and backups have been scanned or validated. The NCSC recommends keeping backup media separate from the network and ensuring cloud backup services retain earlier versions, because ransomware can encrypt synchronised files or attackers can delete backups.
Key contacts and preparation to complete this week
Your plan is only useful if its contact fields are complete. Add your MSP’s emergency number and contract reference; cyber-insurance claims line and policy number; bank fraud number; accountant or payroll provider; software and cloud account owners; data-protection adviser; legal contact; and a specialist incident-response firm if your insurer specifies one. Keep the list on paper and in a secure offline location. Review it after staff, supplier, bank or insurance changes.
Then test the plan in 20 minutes. Ask: “The director’s email account has sent fake invoice messages at 09:15. What happens by 10:15?” Walk through who declares the incident, who calls the MSP, who pauses payments, how the business communicates without email, what evidence is retained, and who checks whether customer data is involved. Fix every hesitation you uncover.
Finally, make prevention part of the plan: maintain tested backups, patch devices and software, use multi-factor authentication, remove access promptly when people leave, and train staff to report suspicious messages quickly. Those basics will not eliminate risk, but they make the one-page plan far more likely to work when you need it.
Conclusion: write it before the pressure arrives
A cyber incident plan is not a sign that your business expects to fail. It is a practical way to protect customers, cash flow and your ability to make clear decisions. For a micro-business, one page is enough to define the first hour, put the right numbers within reach and turn a panicked response into a controlled one.
Set aside one hour this week. Copy the template, fill in the names and numbers, print it, share it with your IT provider and run one short exercise. If an incident happens in 2026, you will not need to invent your response while the clock is already running.





















