← SecureAZ Blog

Incident Response · 7 min read · Published 8 April 2026 · Reviewed 17 August 2026

Cyber Incident Response for Small Businesses: What to Do When Something Goes Wrong

Most small businesses have no incident response plan. When a breach happens, that absence costs them weeks of chaos and significantly more money. Here's what you actually need.

Something has gone wrong. Maybe an employee clicked a phishing link and their credentials were used to access your systems. Maybe ransomware is encrypting files. Maybe a customer called to say their data appears to be for sale online.

What happens next — in the first hour, the first day, the first week — determines whether this is a bad day or a business-ending event.

Most small businesses haven't thought about this before it happens. Here's what you need to have in place before you need it.

Why Small Businesses Fare Worse in Breaches

It's not that small businesses are targeted more. It's that they recover worse. IBM's Cost of a Data Breach Report consistently shows that organisations without incident response plans pay significantly more to resolve breaches than those with documented procedures — often 30-50% more.

The reasons are practical: without a plan, breaches take longer to contain, more data is exfiltrated, forensic evidence is accidentally destroyed, and notifications happen late (incurring regulatory exposure). With a plan, your team knows what to do before panic sets in.

The Five Phases of Incident Response

1. Identify

How do you know something has happened? Detection is harder than it sounds. Many breaches go undetected for weeks or months. The basics: log monitoring on critical systems, alerts on unusual login activity or data transfers, and — critically — a culture where staff immediately report suspicious activity rather than hoping it'll resolve itself.

2. Contain

The first priority when a breach is confirmed: stop the bleeding. This typically means:

  • Isolating affected systems from the network (disconnect from WiFi/ethernet, don't power off — you want to preserve volatile memory for forensics)
  • Resetting credentials for affected accounts
  • Revoking active sessions on compromised platforms
  • Engaging your IT provider or MSP immediately

The common mistake: trying to clean up the infection before containing it. A ransomware-encrypted system that's still connected to your network can continue spreading. Isolation first.

3. Eradicate

Once contained, remove the threat: malware removal, patching the exploited vulnerability, closing the access vector that was used. This is typically done with IT/MSP support. Document everything — what was found, what was removed, what the entry point was.

4. Notify

Breach notification obligations are triggered by the incident, not by your response. Under both the NZ Privacy Act 2020 and the Australian Privacy Act, if a breach is likely to cause serious harm, notification to the relevant Commissioner and affected individuals is mandatory.

Key points:

  • You can't delay notification while you investigate — if you know a breach has occurred, notify promptly
  • Document the timeline: when you detected it, what you found, what you did
  • Your cyber insurer should be notified immediately — many policies have strict notification timeframes
  • Legal advice before notifying affected individuals is strongly recommended

5. Recover and Review

Restore systems from clean backups. Verify integrity before reconnecting. Brief affected staff. Then — importantly — conduct a post-incident review: what happened, why, what would have caught it earlier, what would have contained it faster.

The review is where most of the long-term value is. Businesses that conduct honest post-incident reviews improve their security posture significantly. Those that just restore and move on get breached again.

What You Need Before an Incident Happens

An incident response contact list. Who do you call? Your IT provider or MSP. Your cyber insurer. Your legal counsel. The relevant regulator (CERT NZ or the OAIC in Australia). Have these numbers somewhere other than your email — which may be inaccessible if your accounts are compromised.

A documented response process. Even a one-page document covering the five phases above is significantly better than nothing. It gives your team something to follow under pressure.

Tested backups. The question isn't whether you have backups — it's whether you've tested restoring from them. A backup you've never tested is a hypothesis, not a safety net.

Staff training on what to report and to whom. The fastest incident responses start with a staff member immediately reporting a suspicious email rather than ignoring it or trying to deal with it themselves.

SecureAZ's incident response module walks your team through detection, reporting, and initial response steps — the things they need to know before they're in the middle of it.