Incident Response Planning

When something goes wrong, speed and clarity matter. I help small businesses build a simple incident response plan so you know who to call, what to do first, and how to recover quickly.

What You Get

A written incident response plan, contact list, escalation steps, and a first-hour checklist.

Scenarios Covered

Phishing & mailbox takeover, ransomware, lost device, vendor compromise, and website breach.

Why It Matters

Reduce downtime, protect data, and avoid panic. A basic plan prevents costly mistakes.

First-Hour Checklist (Example)

  • Stop the bleed: isolate affected devices/accounts
  • Preserve evidence: don’t wipe before we capture what happened
  • Reset access: MFA + password resets for impacted users
  • Contain email compromise: rules, forwarding, OAuth apps
  • Validate backups and recovery path