Writifi

A Cyber Incident Response Plan for Small Businesses

What a right-sized incident response plan looks like when you don't have a dedicated security team - and where the usual enterprise-style advice doesn't quite apply.

The advice gap

Most published incident response guidance - including a lot of official guidance - is written with at least some assumption of a security or IT team behind it. It talks about security operations centres, dedicated forensic tooling, and 24/7 monitoring. For a business of 5 to 100 people where IT is one person's part-time responsibility, that advice is directionally correct but practically unusable as written.

A small-business-appropriate plan takes the same underlying principles - identify, contain, investigate, recover, review - and translates them into steps someone without security training can actually follow under pressure.

What's realistic to expect from your team

You are not expecting your office manager to perform forensic disk imaging. You are expecting them to know: who to call, what NOT to do (like switching off a machine that might destroy evidence), how to record a timeline, and when a situation has crossed the line into 'we need a specialist now.'

A good SME plan is explicit about that last point - it should tell you clearly when to stop trying to handle something internally and bring in an incident response provider or your cyber insurer, rather than leaving that judgement call to someone under pressure with no reference point.

Microsoft 365 and Google Workspace matter more than firewalls

For most small businesses, the realistic attack surface is email and cloud accounts, not on-premise infrastructure. A plan that spends most of its length on network architecture and very little on 'how do I check for a malicious mailbox forwarding rule in Microsoft 365' is solving the wrong problem for this audience.

Look for practical, product-specific checks - reviewing sign-in logs, checking for forwarding rules and OAuth consent grants, revoking sessions - rather than generic advice to 'review your logs.'

Budget for specialist help before you need it, not during

Cyber insurance and a pre-agreed relationship with an incident response provider are two of the highest-leverage things a small business can put in place. Figuring out your policy's notification requirements, or finding a provider, in the middle of a live ransomware incident costs you hours you don't have.

A ready-made starting point

If you'd rather not draft all of this from scratch, our Cyber Incident Response Plan & Toolkit was written specifically for UK small and medium businesses without a dedicated security function - plain-language playbooks, a workbook for logging what happens, and clear guidance on when to escalate to a specialist.