Blog · Incident Response · July 13, 2026 · By Mike Parker

Your Business Just Got Hacked. Now What? An SMB Incident-Response Guide

It's 7:40 AM. Files won't open, there's a ransom note on the file server, and four employees are asking what to do. The next hour decides whether this is a rough week or an existential event. Here's the hour, minute by minute — and the short list that makes it survivable.

The first hour

  1. Contain — without destroying evidence. Disconnect affected machines from the network: pull the cable, kill the Wi-Fi, isolate the switch port. Do not power anything off — memory holds the forensic evidence that shutdown erases, and some ransomware corrupts irreversibly on reboot. If lateral spread is visible and you must choose, cutting the internet uplink beats powering down servers.
  2. Protect the backups — this minute. Attackers routinely linger before detonating, and the backup console is their first stop. Verify the offsite/immutable copy is intact and that its credentials aren't the same ones that just got compromised. Whatever you still have at minute ten, you keep. (With attacker breakout times now under an hour, minutes are the actual unit here.)
  3. Start the timeline. One person writes everything down: what was noticed when, what was disconnected, who was called. Insurers, forensics, and — if it comes to it — regulators will all ask. Memory under adrenaline is fiction; notes are evidence.
  4. Make the calls, in order. Your IT/security provider's emergency line first — containment at machine speed is their job. Then the cyber-insurance hotline: policies carry approval requirements and preferred forensics/legal panels, and acting without them can jeopardize coverage. Then counsel. Not yet: mass emails to staff or clients — communicate on a plan, not on panic, and assume email itself may be compromised; phones and text are safer channels for the first hours.
  5. Freeze the money paths. If there's any chance finance systems or email were touched, call the bank, hold pending wires, and warn whoever approves payments — BEC follow-on fraud loves the chaos right after an incident.
Infographic timeline of the first hour after a breach: contain in the first ten minutes, protect backups, keep a written timeline, make calls in order, freeze money paths
The first hour, minute by minute. The version worth printing is the one your team has seen before the morning it matters.

The communications hour (the one everyone gets wrong)

Somewhere between minute 60 and the end of day one, the pressure to say something becomes unbearable — staff are speculating, a client heard a rumor, someone drafts an all-hands email. Resist the improvisation. Internal first: a short, factual holding note — systems issue, being handled, don't touch affected machines, route questions to one named person. External: nothing beyond operational necessity until counsel weighs in, because early statements harden into legal facts, and "we have no evidence data was accessed" written at noon can be false by Friday and quoted forever. And deliver it by phone or text if email is in scope — announcing your response plan inside the attacker's mailbox is handing over the defense playbook. One voice, short sentences, no adjectives. Companies rarely get judged for having an incident; they get judged for the week of communication that follows it.

The first week, compressed

Forensics establishes what happened and what data was touched — resist the urge to wipe and reimage before scope is known, because rebuilding on an unknown foothold restarts the incident. Counsel drives notification: state laws (California's among the strictest), contractual duties to clients, sometimes regulators; timelines run in days. Recovery then works tier by tier from clean, verified backups onto verified-clean systems — with credentials rotated everywhere, MFA enforced, and monitoring watching for the attacker's return visit, which is common enough to plan for.

The version with a SOC

Contained at 2 a.m. beats discovered at 7:40

The scenario above assumes the attack announced itself. With a 24/7 SOC and MDR, the more common story is quieter: the anomaly gets isolated at machine speed overnight, and the morning email says "contained" instead of "ransom." That's the product, in one sentence.

The six-item preparation list (do this quarter)

  • A paper contact list. Provider emergency line, insurer hotline, counsel, leadership cell numbers. On paper and in phones — the incident may own your email and file shares.
  • A one-page containment playbook. The first-hour steps above, adapted to your systems, readable by a non-technical manager — because the person who spots it first may be in accounting, at 7:40, alone.
  • Immutable, geo-separate, restored-recently backups. The single strongest predictor of whether ransomware is an inconvenience or a catastrophe. (Details in the continuity guide.)
  • MFA everywhere + monitored EDR/MDR. Prevention and early detection compress every later step; they're also what your insurer already requires.
  • The insurance policy, read in advance. Know the hotline, the approval rules, the panel, and what voids coverage — at 7:40 AM is a bad time to learn your policy requires pre-approval for forensics spend.
  • One tabletop a year. Two hours, one scenario, leadership in the room. IBM’s breach-cost research consistently ranks tested response plans among the largest cost reducers — with US averages at $11.5M per breach, with a global 247-day identify-and-contain cycle, the rehearsal is the cheapest security control you’ll ever buy.

Incidents don’t reward brilliance; they reward preparation and calm. The companies that come through cleanly aren’t the ones that never get attacked — 88% of breaches at small and midsize businesses involve ransomware or extortion (Verizon DBIR 2026) — they’re the ones for whom the worst morning of the year was, in the end, a rehearsed procedure.

The first hour, as a printable wall card

Checklist + fill-in contact lines. Print it before the morning it matters.

Download the PDF

Incident-response FAQ

What are the first three things to do after discovering a breach?

Contain, preserve, call. Contain: disconnect affected machines from the network — pull the cable, disable Wi-Fi — but do NOT power them off; memory holds evidence that shutdown destroys. Preserve: start a timeline note of what was seen and done, with times. Call: your incident-response contact — your IT/security provider's emergency line, then (per your plan) your cyber insurer's hotline, because insurers have approval requirements and panels that affect coverage.

Should we pay a ransomware demand?

Law enforcement advises against it: payment funds the next attack, marks you as a payer, and roughly a third of organizations that have backups still fail to recover data — payment doesn't fix that either, since decryptors are slow and sometimes broken. The honest answer is that it's a business decision made under duress, with legal counsel and your insurer, and sometimes sanctions law makes it illegal. Every alternative you build in advance — immutable backups above all — is leverage you keep.

Do we have to report a breach, and to whom?

Usually, and to more parties than most owners expect: state breach-notification laws (California's among the strictest), your cyber-insurance carrier (promptly — late notice can jeopardize coverage), sometimes regulators or federal agencies depending on industry, and affected individuals. Timelines run in days, not months. This is exactly why legal counsel goes on the contact list before anything happens.

What should a small business prepare before any incident?

Six things fit on a few pages: a contact list (IT/security provider, insurer hotline, counsel, leadership) that exists on paper; a one-page containment playbook; immutable offsite backups someone has actually restored; MFA and EDR/MDR coverage so the incident is caught early; the insurance policy's IR requirements read in advance; and a two-hour tabletop exercise once a year. IBM's breach research has consistently ranked tested response plans among the biggest cost reducers — and with US breach costs averaging $11.5M, and a global average of 247 days to identify and contain a breach, "tested" is the operative word.

Could your team run the first hour today?

The free assessment walks your current readiness — backups, monitoring, response — in one 30-minute call.

Book a Free 30-Minute IT Assessment