Blog / Practical controls
Practical controls
The One-Page Incident Response Plan a 25-Person Company Can Actually Follow
An incident response plan for a small business on one page: who calls whom in the first hour, the regulator clocks, and what to do when your IT provider is hit.
The plan was a phone number
The owner of a 25-person accounting practice is at his daughter's soccer game on a Saturday morning when the office manager texts: "Can't open anything on the server. Files have a weird name. Calling IT."
He is not alarmed. The practice has an IT provider, a good one, on a monthly contract, and the incident response plan, such as it is, consists of that provider's number on a sticky note by the front desk. He tells her to keep calling.
By noon nobody has answered. At 1:15 the provider's owner finally calls back, and he sounds worse than she does. The attack came in through the provider's own remote-management tool, the one it uses to look after 40 clients. All 40 were hit overnight. The provider has three technicians, no spare hands, and its own servers are encrypted too. "We'll get to you," he says. "I can't tell you when."
The practice is 17 days from a filing deadline for 300 clients. Nobody knows where the backups are, whether the insurer must be told before anyone touches anything, which clients have to be notified, or who is allowed to decide any of it. The owner is standing on a soccer field holding a phone number that has stopped being a plan.
What the heck does this mean
An incident response plan is a written answer to one question: when something goes wrong with our systems, who does what, in what order, and who decides? It is not a 40-page binder. For a business of 25 people it is one page, taped somewhere, that a frightened office manager can follow on a Saturday.
An incident is anything that might have exposed data or stopped the business: ransomware, a stolen laptop, a wire that went to the wrong account, a login from a country where you have nobody. Containment means stopping it getting worse, usually by pulling a computer off the network. Notification means telling the people the law says you must tell, inside the clock the law sets.
The part the accounting practice missed is dependency. Your IT provider is a vendor, and vendors get hit. If your whole plan is their phone number, their bad day is your bad day, and you will be at the back of a queue of 40.
The numbers that matter
Speed of detection and reporting is the biggest factor in recovering a fraudulent transfer, and Coalition reports clawing back $158 million for policyholders in its 2026 Cyber Claims Report. The money moves faster than the paperwork, so the paperwork has to be ready.
Breaches contained in under 200 days cost $1.33 million less than those that ran longer, according to the IBM 2026 Cost of a Data Breach Report. Every step skipped on Saturday is paid for in the weeks after.
Regulators now set the clock for you: 72 hours under the UAE PDPL, 24 hours to the Department of Health under Abu Dhabi's ADHICS v2, 30 days to the FTC under the Safeguards Rule and to customers under SEC Regulation S-P, and 60 days under HIPAA. The hours do not pause while you look for the backup.
What to do this week
- Write the one page. Section one: who is in charge (the owner), who runs the technical response (IT provider, plus a backup contact who is not the IT provider), who talks to the insurer, who talks to clients. Names and mobile numbers, not roles. (CIS 17 Incident Response Management)
- Section two: the first hour. Disconnect affected machines from the network but do not power them off. Call the insurer's hotline before anyone starts rebuilding; most policies require it. Start a written timeline with the first odd thing anyone saw. (CIS 17 Incident Response Management)
- Section three: where the backups are, who holds the credentials, and how long a restore of the main server takes, measured in the last test rather than guessed. If you cannot fill in that number, it is this week's other job. (CIS 11 Data Recovery)
- Ask your IT provider, in writing, what happens to you if they are breached: how they would tell you, how fast, and who covers your restore when their technicians are busy with 39 other clients. Then line up a second responder who is independent of them. (CIS 15 Service Provider Management)
- Section four: the notification clocks that apply to you, the regulator's name, the deadline, and the lawyer or breach coach who decides whether an incident is reportable. Write that phone number down today. (CIS 17 Incident Response Management)
- Run the page once. Thirty minutes on a Friday: read the scenario above aloud and walk the steps. Whatever nobody can answer goes back on the page. (CIS 17 Incident Response Management)
Where AccuSights fits
Our assessment checks whether a plan exists, whether the people named in it know they are named, whether the restore has ever been timed, and what your IT provider has promised in writing for the day they are the victim. The Cyber Hygiene Test takes three minutes and asks who you would call first. A 15-minute call with an engineer turns your answers into the one page.
Our assessment is mapped to your regulators and their notification clocks, and the read-only compliance agent shows whether the controls your plan relies on, backups, logging, access, are in place and stay in place. We have no access and do not remediate; you or your IT partner respond, we show you where the plan has a hole.
Questions people ask
Who should be on an incident response team in a small business? Four roles, some of which may be the same person: the decision maker, usually the owner; the technical lead, usually the IT provider plus one independent backup; the communicator who handles clients and staff; and the adviser, a lawyer or breach coach from your insurer who decides what must be reported. Add the bookkeeper if money can move. Write names and mobile numbers, not job titles.
When do I have to notify customers? It depends on which regulator covers you, and the clocks are short: 72 hours under the UAE PDPL, 24 hours to the Department of Health under ADHICS v2, 30 days under the FTC Safeguards Rule and SEC Regulation S-P, 60 days under HIPAA. The clock usually starts when you become aware, not when you finish investigating. Decide with counsel on day one whether it has started, and write down the date and the reasoning.
Should I call the police or the FBI after a cyber attack? Yes, and quickly, for any incident involving money or stolen data. In the US, file with the FBI's Internet Crime Complaint Center and call the local field office for a live fraudulent transfer; recalls work best in the first hours. In the UAE, report through the police eCrime channel. Your insurer will expect a report either way, and the report number becomes part of your evidence.
A phone number is a plan right up until the person who answers it is having the same day you are.
Questions people ask
Who should be on an incident response team in a small business?
Four roles, some of which may be the same person: the decision maker, usually the owner; the technical lead, usually the IT provider plus one independent backup; the communicator who handles clients and staff; and the adviser, a lawyer or breach coach from your insurer who decides what must be reported. Add the bookkeeper if money can move. Write names and mobile numbers, not job titles.
When do I have to notify customers?
It depends on which regulator covers you, and the clocks are short: 72 hours under the UAE PDPL, 24 hours to the Department of Health under ADHICS v2, 30 days under the FTC Safeguards Rule and SEC Regulation S-P, 60 days under HIPAA. The clock usually starts when you become aware, not when you finish investigating. Decide with counsel on day one whether it has started, and write down the date and the reasoning.
Should I call the police or the FBI after a cyber attack?
Yes, and quickly, for any incident involving money or stolen data. In the US, file with the FBI's Internet Crime Complaint Center and call the local field office for a live fraudulent transfer; recalls work best in the first hours. In the UAE, report through the police eCrime channel. Your insurer will expect a report either way, and the report number becomes part of your evidence.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
Security Awareness Training for a Small Business: Why the Report Button Beats the Delete Key
Security awareness training for small business that works: short, monthly, scored per person and team, tied to real threats, judged by who reports.
Practical controlsAudit Logging for a Small Business: What to Keep, for How Long, and How to Stop Your Data Walking Out the Door
Audit logging for a small business: which logs to keep, for how long, and the DLP settings that stop a departing employee taking the whole database with them.
Practical controlsMulti-Factor Authentication for a Small Business: Where It Belongs, Which Kind Works, and Why Outlook Alone Is Not Enough
Multi-factor authentication for a small business: the five doors it must be on, which kind survives a fake login page, and why Outlook alone is not enough.
