Skip to content

Security

An incident response plan that fits on one page

Nobody reads a thirty-page document under pressure. One sheet by the desk changes the first hour more than anything else.

6 min read · checked: August 2026

An incident response plan in a small company usually does not exist, because “nothing ever happens here”. When one does get written, it is usually a document of several dozen pages that nobody will open at the moment it is needed.

The first hour decides most of the cost. Not because everything has to be fixed in it — because the first hour is when it is easiest to make things irreversibly worse.

Three things to know before an incident

What not to delete

This is the most important point and the one most often broken. The instinct is always the same: delete the suspicious file, clear the mailbox, reformat the machine, “get rid of the problem”.

The consequence: the only material from which anyone could establish what happened, and whether it is still happening, disappears. Without it you cannot know whether the incident is closed or merely invisible.

We do not delete: logs, suspicious files, message contents, the contents of the affected machine’s disk. We also do not switch off event collection to “stop it filling up the disk”.

What to disconnect, and what not to switch off

Disconnect from the network — yes. The cable, or turning off the wireless adapter. That stops the spread and the communication outward.

Switching the machine off — carefully. Shutting down wipes memory, and memory sometimes holds the only trace of what was running. Where a serious incident is suspected, it is better to disconnect from the network and leave it powered on.

The exception: if file encryption is visibly in progress, cutting the power limits the damage and is the right call. That is the only case where acting faster beats acting carefully.

Who to notify and in what order

The list needs names and phone numbers, not roles. “IT department” is not a phone number.

A skeleton to fill in

One page, printed, at the desk of whoever is on duty and in the server room. A copy in the cloud is not enough — during a serious incident the cloud may be unavailable or untrusted.

THE FIRST HOUR — WHAT I DO

1. I DELETE NOTHING
   No files, messages or logs. No formatting. No „cleaning up”.

2. I DISCONNECT FROM THE NETWORK
   Cable out, Wi-Fi off. I do NOT switch the machine off,
   unless I can see file encryption in progress.

3. I WRITE DOWN WHAT I SAW
   Time, message, what I was doing just before. A photo of the screen.

4. I CALL — in this order:
   [ ] IT support ......................... name, phone
   [ ] Decision-maker at the company ...... name, phone
   [ ] Vendor of the key system ........... name, phone, contract no.

5. I DO NOT RESPOND TO A RANSOM DEMAND
   and I do not contact the attacker on my own.

WHAT I DO NOT DO ALONE
- I do not restore from backup before somebody establishes the cause is gone
- I do not change passwords on the affected machine
- I do not inform customers before we know what happened

Easy things to miss

Backups. If ransomware is suspected, check whether the backups are reachable from the affected machine — and disconnect them before they are caught. That is often the single most urgent task in the whole first hour.

Passwords. Changing passwords from the affected machine means typing new passwords where somebody may be reading them. Changes are made from a clean machine.

Restoring from backup without establishing the cause usually ends in a repeat of the same event within days.

The breach notification deadline. If the incident involves personal data, the law allows a limited time to notify the supervisory authority. Write into the plan who takes that decision and on what basis — because the clock starts when the breach is established, not when the details are.

What this plan does not replace

It does not replace a forensic investigation. In a serious incident, establishing how they got in, what they took and whether they are still inside is work for a specialist team with the right tools.

This plan has one job: to get the company to the point where such a team has something to work with — preserved traces, halted spread and untouched backups.

That is quite enough for one sheet of paper.

← All notes

NEXT STEP

Describe the problem.
You get a straight answer.

No specification required. A few sentences about your company and what currently does not work is enough to start.

Go to contact