Skip to content
WealthLink

Cybersecurity

What to Do in the First Hour of a Security Incident

A one-page plan for the situations that actually happen to small businesses — compromised email, ransomware, a fraudulent payment, a lost device — written before you need it.

Written by WealthLink EditorialUpdated September 4, 20265 min read

Security incidents are survivable and mostly recoverable. What makes them expensive is the first hour spent working out what to do while the situation gets worse.

Write the plan now, on one page, while you're calm.

The order: contain, then investigate

The instinct is to understand what happened. That's second.

Containment first — stop it spreading, stop money moving, lock out whoever is in there. Investigation can happen once nothing further is at risk.

The one exception: don't destroy evidence while containing. Disconnecting a machine from the network is containment. Wiping and reinstalling it is destroying the record of what happened, which you may need for insurance, for legal reasons, or simply to know whether the problem is actually gone.

Compromised email account

The most common, and the most consequential because email resets everything else.

First fifteen minutes:

  1. Change the password — from a different, known-clean device
  2. Sign out all sessions — most providers have "sign out everywhere". A password change alone doesn't always kill active sessions
  3. Check two-factor settings. Attackers commonly add their own device or a backup number
  4. Check forwarding rules and filters. This is the classic persistence trick — a rule quietly forwarding everything, or auto-deleting security alerts so you don't notice
  5. Check the recovery email and phone haven't been changed

Then:

  • Review sent items for what was sent from the account
  • Warn anyone who received something, especially payment-related — the account may have been used to run invoice fraud on your contacts
  • Change passwords on anything whose reset goes to that mailbox
  • Check login history for where and when

Ransomware

First ten minutes:

  1. Disconnect affected machines from the network — unplug or turn off Wi-Fi. Don't shut down yet; that can destroy useful evidence
  2. Disconnect backups immediately if any are attached. This is the thing that determines whether you recover
  3. Identify what's affected and what isn't
  4. Don't pay anything yet. It's a decision to make with advice, not in the first hour

Then:

  • Verify your backups are intact and disconnected
  • Report it to the relevant authority in your jurisdiction
  • Get help if you don't have the expertise — this is a reasonable place to pay for it
  • Restore from a known-good backup rather than trusting a cleaned machine

Fraudulent payment

Call the bank first. Before anything else.

Recovery odds fall by the hour and are much better in the first few. Say clearly it's a fraudulent payment and ask for a recall.

Only then: identify the receiving bank, report to the relevant fraud body, check whether email was compromised, and warn the supplier whose account may have been the entry point.

Full detail: how payment fraud reaches small businesses.

Lost or stolen device

  1. Remotely lock or wipe it if you have that capability — which is a reason to set it up in advance
  2. Change passwords for anything saved on it or logged in
  3. Sign out sessions on key services
  4. Report it if it held client data — that may trigger notification obligations

The one-page plan

INCIDENT RESPONSE — [BUSINESS NAME]        Last reviewed: ______

FIRST: CONTAIN. Then investigate. Don't wipe anything yet.

COMPROMISED EMAIL
  Password from a clean device → sign out all sessions →
  check 2FA devices, forwarding rules, recovery details →
  review sent items → warn recipients

RANSOMWARE
  Disconnect from network (don't shut down) → DISCONNECT BACKUPS →
  assess scope → don't pay → verify backups → get help

FRAUDULENT PAYMENT
  CALL THE BANK FIRST — recall request → then everything else

LOST DEVICE
  Remote lock/wipe → change passwords → sign out sessions

WHO TO CALL
  Bank fraud line:        ______________
  IT support:             ______________
  Insurer / broker:       ______________
  Legal / compliance:     ______________
  Accountant:             ______________

NOTIFICATION
  If client or personal data may be affected, obligations and deadlines
  depend on jurisdiction and data type. Call [advisor] the same day.

WHERE THIS LIVES
  Printed copy: ______________
  Second location: ______________ (not on the systems it covers)

Notification obligations

If personal or client data may have been exposed, there are frequently legal obligations to notify — sometimes within a short and specific window.

What applies depends on your jurisdiction, your sector, and what data was involved. Those rules vary considerably and change, so this isn't something to work out from a general article during an incident.

Know who you'd call — a lawyer, a compliance advisor, your insurer — and put the number in the plan now. The one thing that's universally true is that the deadlines are short and they start when you become aware.

Store it where it survives

A recovery plan on the encrypted server is not a recovery plan.

Print it. Put a copy somewhere separate from the systems it covers. Make sure more than one person knows where it is.

Afterward

Once it's resolved, two things:

Write down what happened while it's fresh — timeline, what worked, what took too long, what you didn't have.

Fix the gap, not the person. These attacks are designed to defeat careful people. If someone clicked something or approved something, the finding is about the control, not their judgement — and treating it otherwise guarantees the next incident gets reported late, which is the thing that actually costs you.

The mistakes

  1. Investigating before containing. It's still spreading.
  2. Wiping a machine immediately. Destroys evidence you may need.
  3. Not disconnecting backups in a ransomware event. The recoverable copy gets encrypted.
  4. Delaying the bank call. Recovery odds fall fast.
  5. Missing email forwarding rules. The classic persistence mechanism.
  6. The plan stored only on the affected system.
  7. Blaming the individual. Guarantees late reporting next time.

What to do next

Fill in the "who to call" section today — bank fraud line, IT support, insurer, legal. Five phone numbers.

Print it, and put a copy somewhere that isn't your computer. That's fifteen minutes, and it's the part of this you'll be most grateful for.

The Newsletter

WealthLink Weekly

Business. Money. Marketing. Real Estate. Technology. One email.

One email a week. Unsubscribe anytime.

Keep reading