Incident Response Planning
When something goes wrong, speed and clarity matter. I help small businesses build a simple incident response plan so you know who to call, what to do first, and how to recover quickly.
What You Get
A written incident response plan, contact list, escalation steps, and a first-hour checklist.
Scenarios Covered
Phishing & mailbox takeover, ransomware, lost device, vendor compromise, and website breach.
Why It Matters
Reduce downtime, protect data, and avoid panic. A basic plan prevents costly mistakes.
First-Hour Checklist (Example)
- Stop the bleed: isolate affected devices/accounts
- Preserve evidence: don’t wipe before we capture what happened
- Reset access: MFA + password resets for impacted users
- Contain email compromise: rules, forwarding, OAuth apps
- Validate backups and recovery path