How do I write an incident response plan for a small business?

Short answer

A small-business incident response plan names who decides and who acts, lists emergency contacts, sets steps for detecting, containing and recovering from common incidents such as ransomware and email compromise, and defines when to notify customers, insurers and authorities. Base it on NIST SP 800-61 Rev 3, published April 2025, and test it with CISA's free tabletop exercise packages.

What changed in NIST's guidance

NIST published SP 800-61 Rev 3 in April 2025 and withdrew Rev 2, the 2012 Computer Security Incident Handling Guide, on April 3, 2025. Rev 3 is a CSF 2.0 Community Profile: instead of treating incident response as a separate lifecycle, it maps it to the six CSF 2.0 Functions.

Preparation now sits under Govern, Identify and Protect. Response sits under Detect, Respond and Recover, and lessons learned feed Identify's Improvement category. NIST says organizations should use the incident response model that suits them best, so a small business can keep its plan simple.

What the plan should contain

  • Roles: an incident lead, a business decision-maker, IT or your managed IT provider, and whoever handles communications and legal questions
  • Contacts: insurer and broker, outside counsel, IT provider, bank, key vendors, and CISA reporting at cisa.gov/report or 1-844-729-2472
  • Out-of-band communication: phone numbers that work if email and Teams are compromised
  • Severity levels and who must be told at each level
  • Short playbooks for ransomware, business email compromise, lost or stolen devices and data sent to the wrong place
  • Evidence handling: what not to wipe or rebuild before it is preserved
  • Notification duties from contracts, regulations and your insurance policy

Ransomware and email compromise first

Start with the incidents most likely to hit you. CISA's ransomware guidance recommends offline, encrypted backups that are regularly tested, and a basic incident response plan with an associated communications plan that is created, maintained and exercised. It also advises using out-of-band communication, such as phone calls, so attackers are not tipped off.

For email compromise, the playbook should cover resetting passwords and sessions, checking mailbox forwarding rules, and calling your bank immediately if a payment was redirected.

Know your reporting clocks

Some obligations come with deadlines. Defense contractors under DFARS 252.204-7012 must report cyber incidents to DoD within 72 hours of discovery. Insurance policies often require prompt notice, and contracts or state breach laws may impose their own. List every applicable clock in the plan so nobody has to research it mid-incident.

Exercise it

A plan nobody has rehearsed fails on contact. CISA's Tabletop Exercise Packages provide free, customizable scenarios and discussion questions, including ransomware. Run one at least yearly with leadership and your IT provider, then update the plan with what you learned.

Common follow-up questions

Is NIST SP 800-61 Rev 2 still valid?

No. NIST withdrew Rev 2 on April 3, 2025, and replaced it with Rev 3, which aligns incident response with the six CSF 2.0 Functions. Rev 2's four-phase lifecycle maps onto Rev 3, so existing plans can be updated rather than rewritten.

How long should a small-business incident response plan be?

Short enough to use under pressure. A few pages covering roles, contacts, severity levels and notification duties, plus one-page playbooks for your most likely incidents, works better than a long document nobody opens during an incident.

Should my managed IT provider be in the plan?

Yes. Name who at the provider responds, how to reach them after hours, what they do on their own authority and what needs your approval. Agree in advance who preserves evidence and who leads communication with your insurer's response team.

Need help with this?

LAN Service Group writes incident response plans and playbooks for small and mid-size businesses, runs tabletop exercises with leadership, and supports response as their managed IT provider.

Talk to LAN Service Group (888) 281-7243

Sources