Backup & Disaster Recovery

First 24 Hours of a Cyber Incident: SME Playbook

First 24 hours of a cyber incident: step-by-step playbook for 10–25 seat SMEs. What to do, what not to do, who to call. Book a Security Triage Call.

Backup & Disaster Recovery

First 24 Hours of a Cyber Incident: SME Playbook

First 24 hours of a cyber incident: step-by-step playbook for 10–25 seat SMEs. What to do, what not to do, who to call. Book a Security Triage Call.

Published:

You spot something wrong — a file you don't recognise, an email sent from your account that you didn't write, or a colleague reports their computer behaving strangely. Your first instinct might be to shut everything down and call someone.

That instinct is understandable. But the actions you take in the first hour — and the decisions you avoid — will determine whether your business recovers cleanly or spends weeks untangling a mess.

This is not a fear-led alarm. It is a practical sequence: what to do, what not to do, and who needs to be involved — based on guidance from the National Cyber Security Centre and real-world incident response practice.

What Should You Do in the First Hour of a Cyber Incident?

The first hour of a cyber incident is the most consequential. Most SMEs lose more time arguing about what happened than they do containing it. Here is the sequence that actually works:

1. Appoint one decision-maker immediately

When five people each take a different action, evidence gets destroyed and confusion multiplies. Designate one person — ideally the owner, managing director, or the most senior technical contact — as the single point of coordination. Not the most technically skilled person necessarily, but the one who can hold structure while others work.

2. Isolate affected systems — but do not power them off

Disconnect compromised devices from the network: pull the ethernet cable, turn off Wi-Fi, or block at the switch level. This stops the threat from spreading to other machines.

Do not power off the affected devices. Shutting down a computer destroys volatile memory — the RAM — which may hold the only record of what executed, what connections were made, and how the attacker got in. If forensic analysis or insurance investigation is needed later, that evidence disappears when the power cuts.

Leave the machines running but disconnected.

3. Start a timeline — now, before you forget

Open a simple document or notebook. Record what was seen, when it was seen, and by whom. Every action taken — who did what, at what time — goes into this record.

This timeline serves three purposes:

  • It becomes your evidence log for insurers, regulators, or law enforcement.

  • It helps your IT provider understand the scope quickly when you call them.

  • It feeds your post-incident review, so you actually learn from what happened.

4. Call your IT provider — before turning things off

If you have an IT provider or managed service agreement, call them now. Tell them what you know, what you have done so far, and what systems are affected. They may have remote visibility into your environment that helps them assess scope faster.

Do not wait for a written email. This is an urgent situation. A phone call or direct message gets the response you need within minutes, not hours.

5. Change passwords on confirmed compromised accounts

Reset passwords for any accounts you know are affected. Revoke active sessions so an attacker loses current access. If multi-factor authentication is not already enabled on those accounts, enable it now.

Check for mailbox rules or forwarding addresses the attacker may have created — a common way they hide their activity and continue accessing data even after you change the password.

Hours 1–4: Containment and Assessment

6. Move to an out-of-band communication channel

Assume email, Slack, or Microsoft Teams may be compromised. Switch to a phone call, a personal mobile messaging app, or face-to-face conversation for incident discussions. If your primary communication systems are affected, this step is non-negotiable.

7. Assess the scope without over-investigating

Your priority is containment, not deep forensic analysis — unless you have the tools and skills for that. Focus on answering four questions:

  • What systems or accounts are definitely affected?

  • Is the threat still active, or has it moved elsewhere?

  • Could customer or financial data be involved?

  • What evidence must be preserved before any changes are made?

Document your answers in the timeline you started earlier.

8. Preserve logs and evidence

Export relevant logs — firewall activity, VPN connection records, email server alerts, Microsoft 365 audit logs. Log rotation does not pause for incidents. If you do not capture them now, they will be overwritten within days or weeks depending on your retention policy.

Do not rebuild, wipe, or reinstall anything at this stage. Rebuilding a compromised host feels like progress but destroys the record of how far the attacker got — and usually leaves their access route open.

Hours 4–12: External Contacts and Decision-Making

9. Contact your cyber insurance provider

If you have a cyber insurance policy, call the provider's emergency line. Many policies include 24/7 incident response support and approved vendors. The contact number should already be saved in your playbook — if it is not, that is a preparation gap to fix after this incident resolves.

Your insurer may require you to use their approved incident response provider. Follow their instructions, but do so alongside — not instead of — working with your IT provider.

10. Consider legal and regulatory obligations

If personal data may have been accessed or lost, the 72-hour GDPR notification clock may have started. Engage legal advice before you decide whether to notify the Information Commissioner's Office (ICO).

The NCSC guidance on incident response processes recommends that every basic IR plan include "basic guidance on legal or regulatory requirements" — specifically when to engage legal support and what constitutes a reportable incident based on the types and volumes of data your business holds.

11. Notify affected parties only when advised

Do not send broad communications to customers, suppliers, or the press until you have assessed the situation and received advice. Premature communication can:

  • Damage your reputation unnecessarily if the incident was minor.

  • Compromise an ongoing investigation.

  • Create legal exposure by stating facts that are later proven incomplete.

Your IT provider, insurer, or legal adviser can help determine what, when, and how to communicate.

Hours 12–24: Stabilisation and Recovery Planning

12. Segment the network

Once you understand the scope, segment your network to prevent further spread. Block suspicious IP addresses at the firewall, disable compromised remote access points, and restrict admin access to essential personnel only.

13. Confirm your backups are intact and offline

Verify that your backup copies are accessible, unmodified, and stored independently of the compromised environment. If you follow a three-layer backup model — on-site, off-site, and air-gapped — check each layer. Your backups are your exit route from a ransomware incident. But a backup that lives in the same Microsoft 365 tenant, controlled by the same compromised credentials, offers limited protection. If you have not yet reviewed your backup strategy against ransomware-resistant principles, our article on ransomware-resistant backups for SMEs explains what actually keeps your data safe.

14. Plan recovery from tested backups only

Restore systems and data only from clean, verified backups — never from the compromised environment. Before restoring, confirm that the access vector (how the attacker got in) has been identified and closed. Restoring into an environment where the attacker still has access simply repeats the cycle. If you have not recently tested whether your backups actually restore, that gap matters more than you might think. Our guide on restore testing versus backup success explains why a green "backup succeeded" tick does not equal recovery readiness.

What Your Incident Response Plan Should Already Include

The sequence above is what you follow when an incident occurs. But none of it works without preparation — specifically, a written incident response (IR) plan that you have reviewed with your team. The NCSC guidance on cyber incident response processes sets out what a basic plan should include:

  • Key contacts — IR team, IT provider, senior management, legal, insurance. Always include at least two contact methods for each (mobile phone and alternative email, for example), because people may be unreachable during an incident.

  • Escalation criteria — clear thresholds for when an incident moves from "IT handles it" to "this needs leadership involvement."

  • A basic flowchart or process — a simple visual guide covering the full incident life-cycle, from discovery through to close-down.

  • At least one conference number — a phone line always available for urgent incident calls.

  • Basic guidance on legal or regulatory requirements — when to engage legal support, HR, or follow careful evidence capture guidelines.

This is not enterprise-level documentation. It is a practical document — ideally one or two pages — that your team can follow under pressure without improvising.

The NCSC also offers a free resource called Exercise in a Box, which helps organisations rehearse their response to cyber attacks. It is completely free, requires no expertise to use, and covers scenarios relevant to SMEs including ransomware, phishing, and supply chain incidents.

How This Connects to Your Business Continuity Plan

An incident response plan is one half of your resilience strategy. The other is your business continuity plan — the documented framework that lets a small business keep operating, or recover quickly, when something goes wrong. The business continuity hub covers both incident response and continuity planning in one place. As our business continuity guide for Kent SMEs explains, continuity planning covers what the other half looks like: critical functions ranked, named owners, recovery targets, and communication contacts. Together, incident response and continuity planning give you both the immediate playbook and the longer-term recovery framework your business needs.

Preparing Before an Incident Happens

The best incident response is one you rehearse before you need it. Here are three practical steps any 10–25 person business can take this week:

1. Write a one-page incident response plan

Use the NCSC's ingredient list above as your template. List your key contacts, escalation triggers, a simple process flowchart, a conference number, and a note on legal/regulatory obligations. Keep it somewhere accessible — not buried in shared drives that may be compromised during an incident.

2. Run a tabletop exercise

You do not need a consultant or expensive tools. Gather your decision-makers and walk through a realistic scenario: "A finance team member reports an unusual email with an invoice attachment. They clicked it." Work through the sequence — who calls whom, what gets isolated, when you contact your provider. The NCSC's Exercise in a Box provides structured scenarios for this purpose at no cost.

3. Review your backup and recovery posture

Confirm that your backups are independent of your primary environment, that you can actually restore from them, and that your team knows the recovery procedure. If you have not tested a restore in the last 12 months, schedule one now.

Common Questions

Should I turn everything off during a cyber incident?

Disconnect affected devices from the network immediately — but leave them powered on. Powering off destroys volatile memory that may hold critical evidence. Only power down systems if your incident response provider or a forensic expert advises it as part of your containment strategy.

Do I call my insurer or the police first?

Call your IT provider first — they can help assess scope and may have existing relationships with incident response specialists. Then call your cyber insurance provider; many policies include 24/7 incident support and approved vendors. For fraud-related losses (such as payment diversion), report to the police via Action Fraud to obtain a crime reference number, which your insurer will likely require. For significant cyber incidents affecting personal data, the NCSC recommends reporting to them as well.

What evidence should we not touch?

Do not rebuild, wipe, or reinstall compromised machines. Do not overwrite logs or clear browser history on affected devices. Preserve screenshots of suspicious activity, export relevant logs (firewall, VPN, email server, audit logs), and document everything in a timeline. If the incident involves financial fraud, preserve copies of any fraudulent invoices or communications.

Can my IT provider handle the incident for us?

An IT provider can manage technical containment, investigation, and recovery — but they are one part of the response. You still need to involve your insurer (if you have cyber insurance), consider legal obligations (especially if personal data is involved), and make business decisions such as whether to take systems offline. The best approach is for your IT provider to coordinate technical actions while you manage the broader business response — using your incident response plan as the shared reference point.

Your Next Step

If you do not yet have a written incident response plan, or if your existing one has never been reviewed with your team, this is a preparation gap — not a failure. Every business can be disrupted. The difference between a manageable incident and a crisis is often whether you had a plan before the clock started ticking.

A Book a Security Triage Call covers your incident preparedness as part of our baseline assessment, and we can help you build a practical, one-page response plan that fits your business — no commitments, no pressure, just clarity.

More resources

Keep reading

Browse the latest practical guides across Managed IT, Cyber Security, Modern Workplace, and Backup

More resources

Keep reading

Browse the latest practical guides across Managed IT, Cyber Security, Modern Workplace, and Backup

More resources

Keep reading

Browse the latest practical guides across Managed IT, Cyber Security, Modern Workplace, and Backup

For 10-15 seat

Owner-managed SMEs in Sussex & Kent

Who want clarity, stability, and a proper security baseline — start with the free Security Triage Call.

For 10-15 seat

Owner-managed SMEs in Sussex & Kent

Who want clarity, stability, and a proper security baseline — start with the free Security Triage Call.

For 10-15 seat

Owner-managed SMEs in Sussex & Kent

Who want clarity, stability, and a proper security baseline — start with the free Security Triage Call.