Your First Hour After a Breach: An Incident Response Plan That Works
The first hour after a breach often decides the total cost. Here is a practical incident response plan that a small business can actually follow under pressure.
When a breach hits, the most expensive decisions are made in the first hour, often by people who are frightened and improvising. The cost of an incident is shaped less by the attack itself than by how the first sixty minutes are handled.
A good incident response plan is not a thick binder. It is a short, practical guide that tells specific people what to do the moment something goes wrong. Here is what that plan needs to cover.
Decide who declares an incident
Many incidents drag on because no one is sure whether what they are seeing is a real emergency. Name a specific person, and a backup, who has the authority to declare an incident and start the response. That single decision unlocks everything else.
The declaration threshold should be generous. It is far better to activate the plan and stand down than to spend the first hour debating whether the situation qualifies.
Give that person the authority to act, not just the title. If declaring an incident means shutting down a critical system, sending staff home, or spending money on outside help, they need to know in advance that those decisions are theirs to make. Authority without hesitation is what keeps the first hour moving.
Know who to call, and in what order
Once an incident is declared, the right calls need to happen quickly. Waiting to figure out who to contact wastes the time that matters most. Your plan should list the contacts and the order to reach them:
- Your cyber insurance carrier, since many policies require prompt notice and provide a response team.
- Legal counsel, who can guide obligations and preserve privilege from the start.
- A forensics or incident response provider who can investigate and contain the intrusion.
- Internal leadership, so decisions about operations and communication are made by the right people.
Put names, phone numbers, and policy numbers directly in the plan. In a real event, no one should be searching their inbox for who to call.
Isolate, but do not wipe evidence
A natural instinct is to power off the affected machines. Resist it. Shutting a system down can destroy the very evidence a forensics team needs to understand what happened and prove the scope of the breach.
The better move is to isolate. Disconnect affected systems from the network to stop the spread, but leave them running so investigators can examine them. Your plan should make the difference between isolating and powering off explicit, because in the moment people forget.
Communicate through an out-of-band channel
If your network and email are compromised, they are the last places you want to coordinate your response. Attackers may be reading along, and the systems may be unavailable anyway. Establish an out-of-band channel in advance, such as a designated phone tree or a separate messaging method, so your team can talk securely.
Define a simple communication tree as well, so each person knows who they report to and who they inform. Clear lines prevent both silence and chaos.
Print it, and practice it
The most common failure of an incident response plan is that it lives only on the network that just went down. Print it. Keep copies where key people can reach them without a computer. A plan you cannot open during an incident is not a plan.
Then walk through it before you need it. A brief tabletop discussion reveals the gaps, from missing phone numbers to unclear authority, that you would otherwise discover at the worst possible time. Fixing them on a calm afternoon costs almost nothing, while fixing them mid-incident costs far more. A managed services partner can help you build and rehearse a plan sized for your business.