What to do in the first hour after a breach

Incident response sounds like something with a command centre and a wall of screens. For a small business it's simpler: knowing what to do in the first hour, decided before you need it.

// overview

The plan is the point.

Incident response is just having decided in advance what happens when something goes wrong, so that the decisions get made by a calm person on a Tuesday, rather than a panicking one at 6pm on a Friday.

In practice, most small businesses don't need a document. They need three things written on one page and stuck somewhere findable: who to ring, what to do first, and where the backups are. That's a genuinely useful incident response plan.

The reason it matters is that the first hour disproportionately decides how bad this gets. Ransomware spreads. Fraudulent payments become unrecoverable. Attackers with mailbox access set up forwarding rules and go quiet. Speed is worth more than cleverness.

// the first hour

Six things, in this order.

// who to tell

Reporting, in Australia.

There's a reasonable amount of confusion about who you're obliged to tell. For most small businesses it comes down to this:

// afterwards

The part everyone skips.

Once things are working again there's a strong urge to never speak of it. Resist that for one short conversation: what let this happen, and what would have caught it?

It's almost never a mystery. It's usually a missing MFA, a password reused from home, a backup nobody had tested, or someone who felt they couldn't question a payment request. Each of those has a fix costing very little, but only if somebody names it out loud.

The businesses we've seen handle this best are the ones that treated it as a process problem rather than looking for someone to blame. The ones that went looking for a culprit generally had a second incident, because the actual gap never got closed.

// questions

Good questions, straight answers.

Should we pay a ransomware demand?

The official advice is no, and we'd agree. There's no guarantee of getting your files back, it funds the next attack, and it marks you as someone who pays. This is much easier advice to follow if you have a tested backup, which is the real argument for having one.

How long does recovery take?

With a working, tested backup: often a day or two. Without one: weeks, sometimes never for some data. The gap between those two outcomes is entirely determined by decisions made before the incident.

Do we have to tell customers?

If their personal information was likely exposed and serious harm is likely, yes, that's the Notifiable Data Breaches scheme. Beyond the legal test, telling people early tends to go far better than having them find out later.

Can you help if we're in the middle of one right now?

Yes. Ring (07) 4592 8091. If it's ransomware, disconnect the affected machines from the network first and leave them running. We'll work out what's contained and what needs rebuilding.

$ inspyred --book-a-callout

Got a question about this?
Ask a human.

Give us a call, text or email, we're available by appointment, 7 days a week. A rough idea on the phone is always free.

Hours
By Appointment · 7 days
Service area
Toowoomba & the Darling Downs
Service style
Mobile: we come to you