A cyber incident does not have to become a business-ending crisis. A calm, prepared response can limit downtime, protect customers and make recovery faster. The first goal is not to investigate everything yourself; it is to contain immediate harm, preserve evidence and bring in the right help.
Before anything happens
Write down who can make decisions if the owner is unavailable. Keep an offline copy of essential contacts: your IT provider, bank, insurer, legal adviser, payment processor and relevant regulators. Know where backups are, who controls administrator accounts, and how to reach staff if email is unavailable. A short plan that people can find is more useful than a long document nobody has rehearsed.
The first hour: contain, do not erase
If a device appears compromised, disconnect it from Wi-Fi and wired networks, but do not switch it off unless a qualified responder advises you to. Do not delete messages, wipe devices or reinstall systems: those actions can destroy evidence. From a clean device, contact your IT or security provider and use known-good phone numbers to contact banks or payment providers if financial accounts may be exposed.
Disable or reset affected accounts from a clean device. Prioritize email, administrator, cloud storage, payroll and banking access. Revoke active sessions and suspicious application permissions, enable multifactor authentication, and do not reuse a compromised password. If the incident involves a vendor, ask them to preserve logs and tell you what data and systems may be affected.
First 4–8 hours: establish facts
Assign one incident lead and keep a simple timeline: what was noticed, when, by whom, what actions were taken and which systems are affected. Record facts rather than guesses. Identify whether customer or employee information, payment details, or operational systems may be involved. Preserve relevant emails, alerts and access logs in a secure location. Restrict access to the response channel so unverified details are not widely circulated.
Use a separate, trusted communication method to update staff. Give practical instructions—such as not opening a certain attachment or not resetting passwords through a suspicious link—and explain where to report new signs of compromise. Avoid promising that data is safe until the investigation supports that conclusion.
First 24 hours: communicate and recover safely
Work with qualified technical and legal advisers to determine notification duties in the jurisdictions where you operate. Requirements and deadlines vary; do not assume that a single rule applies everywhere. Notify your insurer and relevant service providers promptly, following policy terms. If customers need to act, provide clear steps using a channel they can verify independently.
Restore only from backups that have been checked for integrity and are believed clean. Change credentials before reconnecting systems, patch the entry point, and monitor accounts for suspicious activity. Keep essential operations running with a safe manual process if possible, rather than rushing infected systems back online.
A practical tabletop exercise
Once a quarter, spend 30 minutes walking through a scenario: the owner’s email is taken over, a staff laptop is stolen, or the booking system becomes unavailable. Ask who decides, how the team communicates without email, where backups and contacts are, and who handles customer updates. Fix gaps while the exercise is still hypothetical.
Bottom line: prepare contacts and backups in advance, isolate affected systems carefully, preserve evidence, secure critical accounts from a clean device, and get qualified help early. A clear first-day plan protects both the technology and the trust your business depends on.
