Cybersecurity
What to Do in the First Hour of a Security Incident
A one-page plan for the situations that actually happen to small businesses — compromised email, ransomware, a fraudulent payment, a lost device — written before you need it.
Security incidents are survivable and mostly recoverable. What makes them expensive is the first hour spent working out what to do while the situation gets worse.
Write the plan now, on one page, while you're calm.
The order: contain, then investigate
The instinct is to understand what happened. That's second.
Containment first — stop it spreading, stop money moving, lock out whoever is in there. Investigation can happen once nothing further is at risk.
The one exception: don't destroy evidence while containing. Disconnecting a machine from the network is containment. Wiping and reinstalling it is destroying the record of what happened, which you may need for insurance, for legal reasons, or simply to know whether the problem is actually gone.
Compromised email account
The most common, and the most consequential because email resets everything else.
First fifteen minutes:
- Change the password — from a different, known-clean device
- Sign out all sessions — most providers have "sign out everywhere". A password change alone doesn't always kill active sessions
- Check two-factor settings. Attackers commonly add their own device or a backup number
- Check forwarding rules and filters. This is the classic persistence trick — a rule quietly forwarding everything, or auto-deleting security alerts so you don't notice
- Check the recovery email and phone haven't been changed
Then:
- Review sent items for what was sent from the account
- Warn anyone who received something, especially payment-related — the account may have been used to run invoice fraud on your contacts
- Change passwords on anything whose reset goes to that mailbox
- Check login history for where and when
Ransomware
First ten minutes:
- Disconnect affected machines from the network — unplug or turn off Wi-Fi. Don't shut down yet; that can destroy useful evidence
- Disconnect backups immediately if any are attached. This is the thing that determines whether you recover
- Identify what's affected and what isn't
- Don't pay anything yet. It's a decision to make with advice, not in the first hour
Then:
- Verify your backups are intact and disconnected
- Report it to the relevant authority in your jurisdiction
- Get help if you don't have the expertise — this is a reasonable place to pay for it
- Restore from a known-good backup rather than trusting a cleaned machine
Fraudulent payment
Call the bank first. Before anything else.
Recovery odds fall by the hour and are much better in the first few. Say clearly it's a fraudulent payment and ask for a recall.
Only then: identify the receiving bank, report to the relevant fraud body, check whether email was compromised, and warn the supplier whose account may have been the entry point.
Full detail: how payment fraud reaches small businesses.
Lost or stolen device
- Remotely lock or wipe it if you have that capability — which is a reason to set it up in advance
- Change passwords for anything saved on it or logged in
- Sign out sessions on key services
- Report it if it held client data — that may trigger notification obligations
The one-page plan
INCIDENT RESPONSE — [BUSINESS NAME] Last reviewed: ______
FIRST: CONTAIN. Then investigate. Don't wipe anything yet.
COMPROMISED EMAIL
Password from a clean device → sign out all sessions →
check 2FA devices, forwarding rules, recovery details →
review sent items → warn recipients
RANSOMWARE
Disconnect from network (don't shut down) → DISCONNECT BACKUPS →
assess scope → don't pay → verify backups → get help
FRAUDULENT PAYMENT
CALL THE BANK FIRST — recall request → then everything else
LOST DEVICE
Remote lock/wipe → change passwords → sign out sessions
WHO TO CALL
Bank fraud line: ______________
IT support: ______________
Insurer / broker: ______________
Legal / compliance: ______________
Accountant: ______________
NOTIFICATION
If client or personal data may be affected, obligations and deadlines
depend on jurisdiction and data type. Call [advisor] the same day.
WHERE THIS LIVES
Printed copy: ______________
Second location: ______________ (not on the systems it covers)
Notification obligations
If personal or client data may have been exposed, there are frequently legal obligations to notify — sometimes within a short and specific window.
What applies depends on your jurisdiction, your sector, and what data was involved. Those rules vary considerably and change, so this isn't something to work out from a general article during an incident.
Know who you'd call — a lawyer, a compliance advisor, your insurer — and put the number in the plan now. The one thing that's universally true is that the deadlines are short and they start when you become aware.
Store it where it survives
A recovery plan on the encrypted server is not a recovery plan.
Print it. Put a copy somewhere separate from the systems it covers. Make sure more than one person knows where it is.
Afterward
Once it's resolved, two things:
Write down what happened while it's fresh — timeline, what worked, what took too long, what you didn't have.
Fix the gap, not the person. These attacks are designed to defeat careful people. If someone clicked something or approved something, the finding is about the control, not their judgement — and treating it otherwise guarantees the next incident gets reported late, which is the thing that actually costs you.
The mistakes
- Investigating before containing. It's still spreading.
- Wiping a machine immediately. Destroys evidence you may need.
- Not disconnecting backups in a ransomware event. The recoverable copy gets encrypted.
- Delaying the bank call. Recovery odds fall fast.
- Missing email forwarding rules. The classic persistence mechanism.
- The plan stored only on the affected system.
- Blaming the individual. Guarantees late reporting next time.
What to do next
Fill in the "who to call" section today — bank fraud line, IT support, insurer, legal. Five phone numbers.
Print it, and put a copy somewhere that isn't your computer. That's fifteen minutes, and it's the part of this you'll be most grateful for.
The Newsletter
WealthLink Weekly
Business. Money. Marketing. Real Estate. Technology. One email.
One email a week. Unsubscribe anytime.