Know who calls whom
Write a first-hour incident plan before the first hour
Prepare a short contact and decision card for lost devices, compromised email, suspicious payments, malware, outages, exposed records, and ransomware.
What this guide should leave behind
A safe offline card identifies the internal lead, technology help, financial contacts, insurer, counsel, reporting routes, communication owner, and first evidence-preserving actions.
Work the routine in this order
- 01
Choose an incident lead and backup. Record safe contact routes for technology support, bank and payment providers, insurer, counsel, key vendors, law enforcement or government reporting, and important business owners.
- 02
Write the first decisions: how to report, when to disconnect a device, when not to wipe or restore, who can disable accounts, how to preserve messages and logs, and how to keep operating safely.
- 03
Define communication authority. Do not guess at legal notice duties, attacker claims, root cause, affected people, payment decisions, or recovery status.
- 04
Store the card where it remains available during an email or cloud outage and run a short tabletop exercise using a fictional scenario.
Foundations worth seeing
- The plan works when normal email or a primary administrator is unavailable.
- Financial fraud, account compromise, lost devices, outages, and ransomware have clear first contacts.
- People know not to destroy evidence or improvise public statements.
- A dated exercise produced at least one correction to contacts, access, backups, or decisions.
Terms behind this routine
Know when general guidance stops
During a suspected incident, use qualified incident response, legal, privacy, insurance, financial, communications, and sector support appropriate to the facts. This guide is not an active-response service.