In our incident response work, much of the lasting damage is not done by the attacker. It comes from rushed decisions, made by people who had never discussed them before, in the first day or two.

The same patterns appear again and again:

  • Nobody knows who can say yes. Can operations take the network offline mid-trading day? Can finance freeze a payment run? Without pre-agreed authority, these calls stall while the attacker keeps working.
  • Evidence is wiped in good faith. An IT provider rebuilds infected machines to get people working again. That can destroy the evidence you need to show regulators, insurers and customers what was actually taken.
  • The attacker is on the call. Teams coordinate the response over the same email or chat platform the attacker has already compromised.
  • Clocks start without anyone noticing. Where a personal data breach is likely to put people at risk, the ICO expects notification without undue delay and, where feasible, within 72 hours of becoming aware. Cyber insurance policies often carry their own notification conditions and preferred responders.
  • Silence gets filled by someone else. Staff, customers and suppliers hear about the incident from social media, or from the attacker, before they hear from you.

None of these are technical failures. They are decisions that could have been made calmly, months earlier. That is what preparedness buys.

An incident response plan is a living governance document, not a technical manual. Its job is to settle, in advance, who is in charge, who can make which decisions, and who must be told. This should be reviewed at least annually to ensure it is still accurate and fit for purpose.

For a small or medium business it should be short enough to use under pressure. If it runs to 40 pages, nobody will open it at 2am. A workable plan covers:

  • Roles. An incident lead and a deputy, plus owners for decisions, technical response, legal and regulatory matters, and communications. In a 30-person firm one person may hold several roles; that is fine, as long as it is written down.
  • Severity levels. A simple scale that tells people when to escalate. One phishing email is not a leadership matter; a ransom note on every screen is.
  • Contacts. Your IT provider, your insurer’s incident line and policy number, legal counsel, a specialist incident response firm, and your bank’s fraud team. The survey found 22% of businesses didn’t know whether they had any cyber insurance at all.
  • Reporting routes. The national line for live cyber attacks is 0300 123 2040 (NCSC); in Scotland, report to Police Scotland on 101. Personal data breaches go to the ICO.
  • A way to talk that doesn’t depend on your systems. Agree an out-of-band channel, such as personal mobiles and a pre-built messaging group, before you need it.
  • A copy that works when your IT doesn’t. The NCSC advises keeping plans offline or on paper, including how teams will communicate without company email.

The most valuable part of the plan is the set of decisions you agree before anything goes wrong:

DecisionTypical owner in an SMEWhy agree it now
Isolate systems or halt operationsManaging Director, advised by IT providerHesitation lets an attack spread
Notify insurer and engage respondersManaging Director or Financial DirectorPolicy terms may dictate who you use and when
Notify the ICOData protection lead, with legal advice72-hour expectation runs from awareness
Tell staff, customers and suppliersManaging Director with a comms leadPlanned messages beat rumour. Understand contractual requirements for notification as well.
Position on a ransom demandOwners or boardLegal, sanctions and ethical questions shouldn’t be debated live
Report to police or the NCSCIncident lead with legal adviceCrime reference number likely needed for insurance claims. Aids the communications team in providing a standing line of “we cannot comment on a live Police investigation”

You don’t need a blank page. The Federation of Small Businesses publishes a free incident response plan template and guide, and the NCSC’s Small Business Guide: Response and Recovery walks through five steps from preparation to lessons learned. Treat any template as a set of prompts: the value is in the conversations you have while filling it in.

For medium-sized firms with a board, the government’s Cyber Governance Code of Practice makes this explicit. Its incident planning principle asks directors to gain assurance that a response and recovery plan exists and is exercised at least annually.

The plan says who decides. A playbook says what to do when a specific type of incident happens. If the plan is the chain of command, playbooks are the drills.

Start with the scenarios most likely to hit you, not the most dramatic:

  • Email account takeover and payment fraud. Phishing was the most common attack in the latest survey (38% of businesses) and was rated the most disruptive by 69% of those affected. A compromised mailbox followed by a diverted supplier payment is one of the incidents we see most often at SMEs. This playbook belongs to finance as much as to IT: call-back checks on bank detail changes, and how to reach your bank’s fraud team fast enough to recall a payment.
  • Ransomware. Reported by only 1% of businesses in the survey, but the scenario most likely to stop you trading. Write it assuming you have lost access to everything, including email and file shares.
  • Personal data breach. Stolen data, a lost laptop or a misdirected spreadsheet. Its shape is set by the regulatory clock and by what you tell the people affected.
  • Compromise of your IT provider or a key supplier. 64% of small and 70% of medium businesses use an external cyber security provider. If that provider’s access is the way in, who do you call?

Each playbook should fit on a few pages and cover:

  • Triggers: how you would know this is happening.
  • First-hour actions: in order, each with a named owner.
  • Containment options and their business cost: cutting remote access stops the attacker, but it also stops your staff.
  • Evidence to keep: what must be preserved before anyone “cleans up”.
  • Calls and notifications: who to ring, and which reporting duties might apply.
  • When to stand down: the criteria for declaring the incident over.

Write them for the people who will use them: the finance team, the office manager, the IT provider. This mirrors the direction of the US standard NIST SP 800-61 Rev. 3 (April 2025), which treats incident response as part of everyday risk management rather than a stand-alone technical process.

A plan that has never been tested is a hypothesis. A tabletop exercise puts your leadership team around a table to work through a realistic scenario, decision by decision, in a couple of hours. No systems are touched.

The NCSC describes exercising as one of the most cost-effective ways to test your response. Its Exercise in a Box is free, needs no specialist knowledge, and offers 20 exercises across 12 topics, including ransomware, phishing and supply chain attacks.

An exercise earns its time when:

  • The real decision makers attend. The owner or Managing Director, finance, operations, HR, whoever handles communications, and your IT provider.
  • The scenario fits your business and escalates. A journalist calls. A key customer asks if their data is safe. The insurer wants answers you don’t have.
  • Someone other than the plan’s author runs it. Authors unconsciously steer around the weak spots.
  • Every gap becomes an action with an owner and a date. An exercise without follow-up is theatre.

In the exercises we run, the same findings surface time after time:

  • The insurer’s incident number is saved in an inbox nobody can reach once systems are down.
  • The IT provider’s contract doesn’t cover incident response, or not out of hours.
  • Backups are administered with the same accounts an attacker would steal first.
  • Nobody is sure they have the authority to take the business offline.
  • The out-of-band communication channel exists only in theory.

Run one at least annually, which is also the Cyber Governance Code’s expectation, and again after significant change: a new core system, a new IT provider, an acquisition, or key people leaving. Start with Exercise in a Box. When you want independent challenge, the NCSC runs an assured scheme for Cyber Incident Exercising providers.

Incident response deals with the attacker. Business continuity keeps the business running while systems are down. Disaster recovery restores the technology. In a serious incident all three run at once and compete for the same people, which is why they need to be planned together.

Only 44% of small businesses and 73% of medium businesses have a continuity plan that covers cyber, according to the 2025/26 survey. Where plans do exist, they were often written for fire, flood or a pandemic, and quietly assume the IT still works.

Plan for total loss, not partial loss. Assume email, files, the finance system and possibly your phones are gone at once. For each critical activity (payroll, taking orders, paying suppliers, production), write down how you would do it manually, and for how long you could keep that up.

Set recovery targets in business terms. For each critical activity, leadership should decide three things:

  • How long can we go without it before the damage becomes serious?
  • How quickly must it be back? (the recovery time objective)
  • How much recent data can we afford to lose? (the recovery point objective)

These are business decisions, not IT ones. Your IT provider’s job is to tell you what meeting them costs; the gap between the two is the conversation worth having.

Assume attackers will go for your backups. The NCSC’s ransomware-resistant backup principles exist because ransomware groups routinely try to destroy backups early to force payment. Backups should be protected from deletion, isolated from everyday systems, and able to restore an older version if recent ones are corrupted. Then test restores, not just backups: time how long a full restore of your most critical system actually takes.

Don’t restore blind. Restoring from backup before you know how the attacker got in can put them straight back into your network. This is where incident response and disaster recovery must work to one plan, with one person deciding when it is safe to rebuild.

Look beyond your own walls. When Jaguar Land Rover shut down after an attack on 31 August 2025, the effects reached a supply chain of around 120,000 jobs made up largely of small and medium businesses (AJ Bell / PA). Some small suppliers told a parliamentary committee they had at most a week of cash left (TimesLIVE). Your continuity plan should ask what happens if your biggest customer, your IT provider or your cloud platform goes down, not only what happens if you do.

The four pieces are one system, not four documents to file and forget.

Exercises test the other three and feed every lesson back

How the four parts fit · 4 parts, 1 feedback loop

The plan sets the decisions, playbooks and continuity plans carry them out, and exercises send every lesson back into all three. None of this needs a large budget. It needs a named owner and about a quarter of focused attention.

Month 1: decide and find

☐ Name an incident lead and a deputy, and agree the pre-authorised decisions in section 1

☐ Find your cyber insurance policy; note the incident line, notification conditions and any required responders

☐ Check what your IT provider’s contract covers during an incident, including out of hours

☐ Set up an out-of-band contact list and messaging group

Month 2: write and verify

☐ Draft the incident response plan from a template, then print it

☐ Write playbooks for payment fraud and ransomware first

☐ Agree recovery targets for your three to five most critical activities

☐ Restore one critical system from backup and time it

Month 3: rehearse and improve

☐ Run your first tabletop exercise, using Exercise in a Box if you have nothing else

☐ Turn every finding into an action with an owner and a date

☐ Book next year’s exercise and a review date for the plan