Nobody plans well at 2am. If ransomware hit tonight, could your team say who takes charge, who calls the insurer, and which machines to pull offline first? An incident response plan answers those questions before the panic starts, and this guide gives you a skeleton you can copy this afternoon, plus real pricing for outside help.
The Short Answer
An incident response plan is essential for small businesses, with the global average cost of a data breach being $4.4 million, making a plan the cheapest way to improve response speed. The plan should be concise, fit on a few pages, and include roles, contact information, severity levels, first-hour steps, communication rules, and retainer decisions. It should be tested twice a year and based on NIST’s four-phase framework for effective incident handling.
What goes in an incident response plan
An incident response plan is a short written playbook that names who takes charge when something breaks, how to reach that person at 2am, what happens in the first hour, and who may speak to the outside world. It exists so nobody improvises during the worst week your company will have.
Most versions I see fail for one reason: length. A 40 page binder built for an auditor helps nobody at midnight. The plan that works fits on a few pages, lives in print as well as on a shared drive, and comes out for a practice run twice a year.
Cost is the other reason to bother. IBM’s Cost of a Data Breach report puts the global average at about $4.4 million across companies of all sizes, and response speed is one of the few levers that moves the number. A plan is the cheapest speed you can buy.
Steal the structure from NIST
You do not need to invent a framework. NIST SP 800-61, the standard incident handling guide, breaks response into four phases: preparation; detection and analysis; containment, eradication, and recovery; and post-incident activity. A 2025 refresh, revision 3, lines the guide up with CSF 2.0, but the four phase loop is still the part worth stealing.
Read those phases as a budget, not a timeline. Preparation is where small companies underspend, and where this article spends most of its time, because every dollar there pays off double later. Detection is where most owners quietly rely on luck, and containment is where the plan either exists or turns into guesswork.
The plan skeleton you can copy
Here is the six part skeleton I hand to owners. Fill it in over one afternoon with your leadership team and you will have something better than most binders.
- Roles. Name an incident commander who makes the calls, a technical lead who works the problem, a communications lead who handles staff and customers, and a scribe who logs every action with a timestamp. One person can hold two roles in a ten person shop, and every role needs a named backup.
- Contact tree. Cell numbers for every role, plus your IT provider, your cyber insurer’s breach hotline, your lawyer, and your bank. Print it, because a contact list that lives only on a server can vanish with the server.
- Severity levels. Three or four tiers with plain definitions, so nobody debates at midnight whether this counts as an emergency. The table below gives you a starting set.
- First hour steps. A short numbered list per scenario: ransomware, a compromised email account, a lost laptop, a vendor breach. Ten lines each, verbs first.
- Communication rules. Who talks to staff, who talks to customers, and the rule that nobody posts, emails, or admits anything externally until the commander, your insurer, and your lawyer agree. Wrong words in hour one create liability in month six.
- Retainer decision. Decide now, in writing, whether outside responders come in and at what severity level. Shopping for forensics help while your servers sit encrypted is the most expensive procurement you will ever do.
Severity levels that end the midnight debate
Severity tiers exist to remove one decision: whether to wake people up. Argue about the definitions now, in daylight, so the on call person just matches the situation to a row.
| Level | Sounds like | Who wakes up | Clock |
|---|---|---|---|
| SEV 1 | Ransomware note, systems down, active intruder, money moving | Everyone on the tree, plus insurer and retainer | Now, any hour |
| SEV 2 | One compromised account or machine, contained but real | Commander and technical lead | Within the hour |
| SEV 3 | Phishing reported, suspicious login already blocked | Technical lead | Same business day |
| SEV 4 | Policy slip, scanner noise, no data touched | Nobody, log it | Weekly review |
One warning from experience: teams under pressure downgrade. A frightened employee wants the incident to be a SEV 3, because a SEV 1 means waking the boss. So put escalation in writing: when in doubt, call the next tier up, and a false alarm never earns a reprimand.
The first hour, step by step
Print this list and staple it to the plan. It assumes ransomware or an active intrusion, the SEV 1 case, since lower tiers are gentler versions of the same moves.
- Confirm and classify. One person checks that the alarm is real and assigns a severity. Five minutes, not thirty.
- Start the log. The scribe opens a notebook or a clean laptop and records every action with the time. Your insurer and any regulator will ask for this.
- Contain, do not clean. Pull affected machines off the network. Leave them powered on, because wiping or rebooting destroys the evidence a forensics team needs.
- Call the tree. Commander first, then your insurer’s breach hotline, then your retainer firm or IT provider. Insurers can refuse claims when you bring in responders they never approved, so call them before you hire anyone.
- Freeze credentials. Reset passwords on admin and finance accounts, revoke active sessions, and switch off anything internet facing that does not need to run.
- Say nothing outside. Staff get one line, we have an IT issue, and they route questions to the communications lead. Customers, press, and social media wait for legal.
Detection deserves one honest note. None of these steps run if nobody notices the intrusion, and most small companies notice late. If nobody watches your alerts overnight, a managed detection and response service is the piece that makes this plan fire at 2am instead of Monday at 9.
What a fair quote looks like
Two kinds of outside help show up on incident response quotes: a retainer with a response firm, and the monitoring layer that spots trouble early. Here are the bands I see on real small business quotes right now.
- Zero dollar retainer: you sign the contract and NDA in advance, pay nothing until an incident, then pay emergency hourly rates, typically $300 to $600 per hour.
- Prepaid retainer: roughly $10,000 to $30,000 per year for a small business, which buys a guaranteed response time, a block of hours, and usually a plan review or tabletop exercise. Unused hours often convert to proactive work, and you should ask for that in writing.
- MDR monitoring: $15 to $25 per device per month for 24/7 eyes on your endpoints, with containment as part of the service.
- EDR software alone: $8 to $15 per device per month, if you have someone who will actually watch it.
Watch for two traps. Retainer hours that expire with no rollover turn your prepaid money into a donation. And a guaranteed response that means a phone call within four hours, rather than a responder working your systems, is a guarantee of very little. Get the definition of response, in hours and in actions, into the contract before you sign.
How to choose an incident response provider
Pick the responder before the incident, on a calm Tuesday, using questions like these.
- What is your guaranteed remote response time, in hours, and will you put it in the agreement?
- Who actually shows up, your own analysts or a subcontractor I have never vetted?
- Do you work with my cyber insurer, and are you on their approved panel?
- What do unused retainer hours convert into?
- Will you run one tabletop exercise with my team each year?
- Can you handle forensics, notification support, and rebuild, or only containment?
Also decide how much of the year round work to hand off. Some owners keep detection in house and retain a firm only for emergencies. Others bundle monitoring, response, and recovery into one contract, and it pays to understand the components of a managed security service before a salesperson bundles them for you. If your sticking point is tooling versus staffing, sort out whether MDR or EDR fits your team first, because that choice sets the monthly number more than any logo does.
Here is my broker card on the table. Our network includes 58 providers that offer incident response, 60 that run managed SIEM, and 57 that provide disaster recovery as a service, and we honestly do not care which one you pick. Vendors pay us, you never do, so our only incentive is a match that still looks smart a year later. The cheap option is fine, by the way, when you are small, hold no regulated data, and pair a zero dollar retainer with monitored endpoints underneath it. Just choose that on purpose, in daylight, with the paperwork signed.
Frequently Asked Questions
What should an incident response plan include?
Six things: named roles with backups, a printed contact tree, severity definitions, first hour checklists for your likely scenarios, communication rules, and a decision about outside help. Keep the whole document under ten pages, and put your cyber insurer’s hotline and policy number on page one, because that call shapes everything after it. Anything longer turns into a binder nobody opens at 2am.
How often should we test an incident response plan?
Twice a year, and one of those can be a 90 minute tabletop exercise. Walk through a scenario out loud: who notices, who calls whom, what breaks. You will find dead phone numbers, departed employees still holding roles, and steps that only made sense to the person who wrote them. Update the plan that same week, while the gaps are fresh.
Do small businesses need an incident response plan?
Yes, and increasingly you have no choice, because many cyber insurance applications now ask whether a written plan exists and price the premium on the answer. Attackers automate their targeting, so a 15 person firm sees the same phishing and ransomware as a 500 person firm, with fewer people to absorb the hit. An afternoon of planning is the cheapest protection you will buy this year.
What is an incident response retainer?
A contract signed before any incident that guarantees a response firm will answer when you call. Zero dollar versions cost nothing up front and bill hourly during an emergency. Prepaid versions, roughly $10,000 to $30,000 a year for a small business, add a guaranteed response time and a block of hours. The real value is speed, since the firm settles paperwork, NDAs, and access questions in advance instead of during hour one.
Who should be on the incident response team?
Four roles at minimum: an incident commander with authority to spend money, a technical lead, a communications lead, and a scribe. Add your lawyer and insurer as external members of the contact tree. In a very small company one person may hold two roles, but the commander and the scribe should differ, because the person making decisions never keeps a good log.
Written by Russ Herman, founder of Defend My Business. We are a technology broker, like a mortgage broker but for business security, internet, and voice. We hold agreements with 400+ vetted providers. Vendors pay us, you never do. See exactly how we make money. Questions: 1-877-453-8759 or [email protected].
Get a Tailored Incident Response Shortlist
3 vetted vendors matched to your size, industry, and budget. Free, vendor-neutral, 24-hour turnaround.
Get a Quote →Want help getting your security solution right?
Defend My Business helps SMBs cut through the marketing and get their security solution right for their environment, budget, and compliance needs — then deploy and manage it. Through our 400+ vendor network we can often secure better pricing and terms than buying direct, and we stay vendor-neutral, so the recommendation fits you, not a sales quota. Want a second opinion? Pair this with our cybersecurity consulting or talk it through with an advisor.
Book a free call with a DMB advisor →