Technology advice gets complicated fast when every answer starts with a product, a warning, or fifteen settings you do not understand. This guide takes the practical route: identify the real risk or bottleneck, make the safest useful change, and leave yourself a way back.
Define what counts as an incident
List practical triggers: stolen device, business email compromise, ransomware note, exposed customer data, unauthorized administrator, major service outage, or suspicious money transfer. Employees should know where to report concerns without first proving the cause.
Assign decision roles
Name a primary and backup for incident lead, technology, operations, communications, legal/privacy, insurance, and executive decisions. Small businesses may combine roles, but the decisions still exist. Record personal contact methods in case company email is unavailable.
Build an offline contact sheet
Include IT provider, hosting company, bank fraud team, cyber insurer, attorney, key vendors, law enforcement or reporting channels, and critical customers. Store a protected offline copy and review it quarterly.
Write the first-hour checklist
Stop active damage without destroying evidence: isolate affected devices when appropriate, preserve logs and screenshots, disable compromised access, contact the response lead, and record actions with times. Do not wipe systems or negotiate with attackers impulsively.
Prioritize recovery
List the systems needed to operate, acceptable downtime, data owners, backup location, and restore order. Recovery means clean systems, validated credentials, monitored access, and tested business functions—not simply turning servers back on.
Practice one scenario
Run a 45-minute tabletop: an employee approves a fake invoice after an email account is compromised. Ask who notices, who calls the bank, who resets access, what evidence is saved, and who communicates. Turn every confused moment into one plan improvement.
Donna’s bottom line
Use the simplest process that solves the real problem, document the important choices, and verify the result. More software is not automatically more security, more speed, or more control. A small repeatable habit usually beats a complicated setup that nobody maintains.
