INTRODUCTION
The question every leader should be able to answer
If your IT disappeared tomorrow, could you still pay staff, serve customers and ship orders? In October 2025 the NCSC’s chief executive asked every UK business leader what they would do “if your IT infrastructure was crippled tomorrow and all your screens went blank” (NCSC Annual Review 2025 launch). For most small and medium-sized businesses, the honest answer is “we don’t know”.
The government’s Cyber Security Breaches Survey 2025/26 shows why. 43% of UK businesses identified a breach or attack in the past year, rising to 65% of medium-sized firms. Yet only 25% of businesses have a formal incident response plan (57% of medium firms, 21% of micro firms), and among small businesses, continuity plans covering cyber fell from 53% to 44% in a single year.
There is a fair counterpoint in the same survey. The median cost of a business’s most disruptive incident was £0, because most incidents are phishing attempts that are caught early or cause little harm. Preparedness isn’t about the typical incident. It is about the rare one that stops you trading for weeks, and the time to decide how you would handle it is not while it is happening.
This guide covers the four things that separate a bad week from a business-threatening month: an incident response plan, scenario playbooks, tabletop exercises, and business continuity and disaster recovery plans. None of them needs an in-house security team. All of them need leadership.
Why the first 48 hours decide the outcome
In our incident response work, much of the lasting damage is not done by the attacker. It comes from rushed decisions, made by people who had never discussed them before, in the first day or two.
The same patterns appear again and again:
- Nobody knows who can say yes. Can operations take the network offline mid-trading day? Can finance freeze a payment run? Without pre-agreed authority, these calls stall while the attacker keeps working.
- Evidence is wiped in good faith. An IT provider rebuilds infected machines to get people working again. That can destroy the evidence you need to show regulators, insurers and customers what was actually taken.
- The attacker is on the call. Teams coordinate the response over the same email or chat platform the attacker has already compromised.
- Clocks start without anyone noticing. Where a personal data breach is likely to put people at risk, the ICO expects notification without undue delay and, where feasible, within 72 hours of becoming aware. Cyber insurance policies often carry their own notification conditions and preferred responders.
- Silence gets filled by someone else. Staff, customers and suppliers hear about the incident from social media, or from the attacker, before they hear from you.
None of these are technical failures. They are decisions that could have been made calmly, months earlier. That is what preparedness buys.
1. The incident response plan: who decides what
An incident response plan is a living governance document, not a technical manual. Its job is to settle, in advance, who is in charge, who can make which decisions, and who must be told. This should be reviewed at least annually to ensure it is still accurate and fit for purpose.
For a small or medium business it should be short enough to use under pressure. If it runs to 40 pages, nobody will open it at 2am. A workable plan covers:
- Roles. An incident lead and a deputy, plus owners for decisions, technical response, legal and regulatory matters, and communications. In a 30-person firm one person may hold several roles; that is fine, as long as it is written down.
- Severity levels. A simple scale that tells people when to escalate. One phishing email is not a leadership matter; a ransom note on every screen is.
- Contacts. Your IT provider, your insurer’s incident line and policy number, legal counsel, a specialist incident response firm, and your bank’s fraud team. The survey found 22% of businesses didn’t know whether they had any cyber insurance at all.
- Reporting routes. The national line for live cyber attacks is 0300 123 2040 (NCSC); in Scotland, report to Police Scotland on 101. Personal data breaches go to the ICO.
- A way to talk that doesn’t depend on your systems. Agree an out-of-band channel, such as personal mobiles and a pre-built messaging group, before you need it.
- A copy that works when your IT doesn’t. The NCSC advises keeping plans offline or on paper, including how teams will communicate without company email.
The most valuable part of the plan is the set of decisions you agree before anything goes wrong:
| Decision | Typical owner in an SME | Why agree it now |
| Isolate systems or halt operations | Managing Director, advised by IT provider | Hesitation lets an attack spread |
| Notify insurer and engage responders | Managing Director or Financial Director | Policy terms may dictate who you use and when |
| Notify the ICO | Data protection lead, with legal advice | 72-hour expectation runs from awareness |
| Tell staff, customers and suppliers | Managing Director with a comms lead | Planned messages beat rumour. Understand contractual requirements for notification as well. |
| Position on a ransom demand | Owners or board | Legal, sanctions and ethical questions shouldn’t be debated live |
| Report to police or the NCSC | Incident lead with legal advice | Crime reference number likely needed for insurance claims. Aids the communications team in providing a standing line of “we cannot comment on a live Police investigation” |
You don’t need a blank page. The Federation of Small Businesses publishes a free incident response plan template and guide, and the NCSC’s Small Business Guide: Response and Recovery walks through five steps from preparation to lessons learned. Treat any template as a set of prompts: the value is in the conversations you have while filling it in.
For medium-sized firms with a board, the government’s Cyber Governance Code of Practice makes this explicit. Its incident planning principle asks directors to gain assurance that a response and recovery plan exists and is exercised at least annually.
2. Playbooks: what to do for this kind of incident
The plan says who decides. A playbook says what to do when a specific type of incident happens. If the plan is the chain of command, playbooks are the drills.
Start with the scenarios most likely to hit you, not the most dramatic:
- Email account takeover and payment fraud. Phishing was the most common attack in the latest survey (38% of businesses) and was rated the most disruptive by 69% of those affected. A compromised mailbox followed by a diverted supplier payment is one of the incidents we see most often at SMEs. This playbook belongs to finance as much as to IT: call-back checks on bank detail changes, and how to reach your bank’s fraud team fast enough to recall a payment.
- Ransomware. Reported by only 1% of businesses in the survey, but the scenario most likely to stop you trading. Write it assuming you have lost access to everything, including email and file shares.
- Personal data breach. Stolen data, a lost laptop or a misdirected spreadsheet. Its shape is set by the regulatory clock and by what you tell the people affected.
- Compromise of your IT provider or a key supplier. 64% of small and 70% of medium businesses use an external cyber security provider. If that provider’s access is the way in, who do you call?
Each playbook should fit on a few pages and cover:
- Triggers: how you would know this is happening.
- First-hour actions: in order, each with a named owner.
- Containment options and their business cost: cutting remote access stops the attacker, but it also stops your staff.
- Evidence to keep: what must be preserved before anyone “cleans up”.
- Calls and notifications: who to ring, and which reporting duties might apply.
- When to stand down: the criteria for declaring the incident over.
Write them for the people who will use them: the finance team, the office manager, the IT provider. This mirrors the direction of the US standard NIST SP 800-61 Rev. 3 (April 2025), which treats incident response as part of everyday risk management rather than a stand-alone technical process.
3. Tabletop exercises: find the gaps while it’s still cheap
A plan that has never been tested is a hypothesis. A tabletop exercise puts your leadership team around a table to work through a realistic scenario, decision by decision, in a couple of hours. No systems are touched.
The NCSC describes exercising as one of the most cost-effective ways to test your response. Its Exercise in a Box is free, needs no specialist knowledge, and offers 20 exercises across 12 topics, including ransomware, phishing and supply chain attacks.
An exercise earns its time when:
- The real decision makers attend. The owner or Managing Director, finance, operations, HR, whoever handles communications, and your IT provider.
- The scenario fits your business and escalates. A journalist calls. A key customer asks if their data is safe. The insurer wants answers you don’t have.
- Someone other than the plan’s author runs it. Authors unconsciously steer around the weak spots.
- Every gap becomes an action with an owner and a date. An exercise without follow-up is theatre.
In the exercises we run, the same findings surface time after time:
- The insurer’s incident number is saved in an inbox nobody can reach once systems are down.
- The IT provider’s contract doesn’t cover incident response, or not out of hours.
- Backups are administered with the same accounts an attacker would steal first.
- Nobody is sure they have the authority to take the business offline.
- The out-of-band communication channel exists only in theory.
Run one at least annually, which is also the Cyber Governance Code’s expectation, and again after significant change: a new core system, a new IT provider, an acquisition, or key people leaving. Start with Exercise in a Box. When you want independent challenge, the NCSC runs an assured scheme for Cyber Incident Exercising providers.
4. Business continuity and disaster recovery: keep trading, then rebuild
Incident response deals with the attacker. Business continuity keeps the business running while systems are down. Disaster recovery restores the technology. In a serious incident all three run at once and compete for the same people, which is why they need to be planned together.
Only 44% of small businesses and 73% of medium businesses have a continuity plan that covers cyber, according to the 2025/26 survey. Where plans do exist, they were often written for fire, flood or a pandemic, and quietly assume the IT still works.
Plan for total loss, not partial loss. Assume email, files, the finance system and possibly your phones are gone at once. For each critical activity (payroll, taking orders, paying suppliers, production), write down how you would do it manually, and for how long you could keep that up.
Set recovery targets in business terms. For each critical activity, leadership should decide three things:
- How long can we go without it before the damage becomes serious?
- How quickly must it be back? (the recovery time objective)
- How much recent data can we afford to lose? (the recovery point objective)
These are business decisions, not IT ones. Your IT provider’s job is to tell you what meeting them costs; the gap between the two is the conversation worth having.
Assume attackers will go for your backups. The NCSC’s ransomware-resistant backup principles exist because ransomware groups routinely try to destroy backups early to force payment. Backups should be protected from deletion, isolated from everyday systems, and able to restore an older version if recent ones are corrupted. Then test restores, not just backups: time how long a full restore of your most critical system actually takes.
Don’t restore blind. Restoring from backup before you know how the attacker got in can put them straight back into your network. This is where incident response and disaster recovery must work to one plan, with one person deciding when it is safe to rebuild.
Look beyond your own walls. When Jaguar Land Rover shut down after an attack on 31 August 2025, the effects reached a supply chain of around 120,000 jobs made up largely of small and medium businesses (AJ Bell / PA). Some small suppliers told a parliamentary committee they had at most a week of cash left (TimesLIVE). Your continuity plan should ask what happens if your biggest customer, your IT provider or your cloud platform goes down, not only what happens if you do.
Bringing it together: a 90-day starting point
The four pieces are one system, not four documents to file and forget.
Exercises test the other three and feed every lesson back

How the four parts fit · 4 parts, 1 feedback loop
The plan sets the decisions, playbooks and continuity plans carry them out, and exercises send every lesson back into all three. None of this needs a large budget. It needs a named owner and about a quarter of focused attention.
Month 1: decide and find
☐ Name an incident lead and a deputy, and agree the pre-authorised decisions in section 1
☐ Find your cyber insurance policy; note the incident line, notification conditions and any required responders
☐ Check what your IT provider’s contract covers during an incident, including out of hours
☐ Set up an out-of-band contact list and messaging group
Month 2: write and verify
☐ Draft the incident response plan from a template, then print it
☐ Write playbooks for payment fraud and ransomware first
☐ Agree recovery targets for your three to five most critical activities
☐ Restore one critical system from backup and time it
Month 3: rehearse and improve
☐ Run your first tabletop exercise, using Exercise in a Box if you have nothing else
☐ Turn every finding into an action with an owner and a date
☐ Book next year’s exercise and a review date for the plan

Six questions to ask your leadership team this week
- If our systems went dark at 9am tomorrow, who is in charge, and does everyone know it?
- Who can authorise taking systems offline, and have we agreed when they should?
- Could we pay staff and suppliers next week without our IT?
- When did we last restore from backup, and how long did it take?
- What does our insurer need from us in the first hours, and where is that written down offline?
- Have we ever rehearsed any of this?

Further reading and sources
Free UK guidance and tools
- NCSC Small Business Guide: Response and Recovery: five steps from preparing to learning lessons
- NCSC Exercise in a Box: free tabletop and micro exercises
- NCSC Cyber Action Toolkit: personalised first steps for sole traders and small firms
- NCSC ransomware-resistant backups
- NCSC Cyber Governance Code of Practice: board responsibilities, including incident planning
- NCSC Cyber Incident Exercising scheme: information for buyers
- FSB: Cyber incident response plan, free template and guide
- ICO: UK GDPR data breach reporting
Data and context
- DSIT and Home Office: Cyber Security Breaches Survey 2025/26 (published 30 April 2026)
- NCSC Annual Review 2025 launch speech, Dr Richard Horne (14 October 2025)
- SC Media UK: the NCSC’s advice on offline incident plans
- AJ Bell / PA: JLR restart and supply chain impact
Standards

