Incident Response Basics for Growing Companies
The best time to figure out who calls whom during a breach is not during the breach. A workable incident response plan is shorter and simpler than most companies assume.
The business problem
Many small companies have no incident response plan at all, and the ones that do often have a document too long and too generic to be useful in the moment — written once for a compliance checklist and never touched again. When an actual incident happens, decisions get made in a panic instead of following a plan.
What actually needs to be in place
A workable plan is short: who is the incident lead, who has authority to make the call to involve law enforcement or outside counsel, who talks to customers and when, and a pre-identified contact for outside help (an incident response firm, cyber insurance carrier, legal counsel) with their number already saved, not looked up under pressure. Everything past that is detail that can be figured out during the response, if the core roles are clear.
Why it matters
The cost of an incident is driven heavily by response time and decision quality in the first hours — how fast containment happens, how clearly customers and regulators are informed, whether evidence is preserved instead of accidentally destroyed. A plan that exists only on paper doesn’t help; a plan people have actually walked through does.
“Nobody reads the incident response plan for the first time during the incident and does it well.”
Signs your incident response readiness is thin
- No one can say, without looking it up, who leads the response if an incident happens tonight
- The plan, if it exists, has never been reviewed or practiced since it was written
- There’s no pre-identified outside help — an incident response firm or legal counsel would be found from scratch mid-incident
- Cyber insurance exists but nobody has read what it requires you to do (and not do) in the first hours
- There’s no clear line for who is authorized to communicate publicly or to customers during an incident
Practical guidance
Write a one-to-two page plan with named roles, not just titles, and real contact information kept somewhere accessible even if primary systems are down. Walk through a simple tabletop exercise once a year — a 60-90 minute conversation working through a realistic scenario finds gaps far more effectively than a document review.
See how a fractional or interim CISO builds and tests incident response readiness.
Explore Interim CISOQuestions, answered directly.
Short enough to actually read under pressure — one to two pages covering roles, authority, and key contacts is often more useful in practice than a lengthy document nobody has time to search through mid-incident.
A tabletop exercise is a facilitated walkthrough of a realistic incident scenario with the actual people who’d respond — it surfaces gaps in the plan (an unclear owner, a missing contact) far more reliably than reading the document ever does.
Ideally, the decision criteria and the firm’s contact information are set before an incident happens, not decided during one — cyber insurance policies often specify approved vendors, which is another reason to read the policy in advance.
A single named person or small group, decided in advance — uncoordinated communication during an incident (a well-meaning but premature customer email, a public statement that contradicts what legal counsel is advising) can create as much damage as the incident itself.
Want an incident response plan you could actually execute under pressure?
30 minutes. No obligation. No sales pitch.