Small Business Guide: Response & Recovery
Guidance that helps small to medium sized organisations prepare their response to and plan their recovery from a cyber incident.
Page 2 of 7
Step 1: Prepare for incidents
How to prepare for the most common threats to your business.
Unforeseen events, both malicious and accidental, can occur in many ways. So it is impractical to develop detailed step-by-step instructions to manage every type of incident, as the list could be endless. Instead you should prepare your business for the most common threats you face by developing plans to handle those incidents most likely to occur.
Identify critical systems and assets
Identify what electronic information is essential to keep your organisation running, such as contact details, emails, calendars, and essential documents. Find out where this information is stored. Is it on single machine in your office? Is it on a remote server? Is it stored in the cloud, by a third party?
Action point: Make a regular daily/weekly back up copy of essential information. Regularly test that the backup is working to ensure you can restore information from it.
Next, identify what business processes and systems are critical to keep your organisation running. For example, the website where your customers place orders, or the computer-controlled manufacturing equipment you use. If you've not already done so, identify these key systems and processes as soon as possible, and record where they are stored (or how they are accessed).
Action point: Assign joint (or shared) responsibility with another person to ensure there's cover when you aren’t available (for instance when on holiday, or away with business). Ensure key documents are made available and are up to date so that in the event of your absence they can be shared/learnt by other relevant people.
Finally, think in advance about how you could minimise reputational damage in an event of an incident. Which key partners do you need to talk to? Building a good relationship with your partners, where you talk regularly beforean event has even occurred, will make things a lot smoother in the event of an incident.
Action point: Make a list of which key partners (customers, suppliers, third parties, etc) that you would need to contact as a result of different types of incident.
Prioritise the risk, and manage it
Consider what would happen if you no longer had access to the critical systems or assets you've identified above. By understanding:
- what's important to your business
- why it's important, and
- what you are doing to protect them
- you can prioritise where you need the most protection. If you need more help with identifying your 'crown jewels' (i.e. the things most valuable to your organisation), please refer to our guidance on Establishing your baseline and identifying what you care about most.
Put risk on the agenda
Discussions about organisational risk (what you value, and what you're doing to protect it) should be part of normal business. Make time to discuss these at your management meetings or weekly catch-ups. Find out where cyber security threats sit in the priority list when compared to physical threats (like burglary and stock theft), flood, legal action, and health and safety. The steps you choose to take to reduce the risk to your business have got to be proportionate to the risks you take, and of course affordable.
Organisations that are considering cyber insurance should understand that it will not protect you from an attack, but it may provide you with additional resources during and after an incident. So cyber insurance can be considered as an additional risk management tool, but do take time to:
- understand the scope and scale of the cover provided
- ensure that you are able to meet any operational requirements placed on you by the insurer
Make an incident plan
Make sure you keep the important information you identified above in a safe place so that you can use it if your equipment is stolen or damaged by a cyber attack. Ensure you know how to restore a backup in the event of any type of data loss, such as a ransomware attack, and train the relevant people in your organisation so they can do the same. Assign roles to members of staff, and document who owns each responsibility in the event of an incident, and how can they be contacted.
Action point: The best way to test your staff's understanding of what's required during an incident is through exercising. Consider using the NCSC's Exercise in a Box resource to test your organisations resilience and preparedness.
Understand and document possible incident ‘trigger points’ such as when ownership of an action or decision transfers between people. For example, an employee may own the action to identify when there's an issue with the website, but once that has been done, who decides if the website should be shut down? Your plan should identify at what point senior management needs to be involved.
Create a list of external people you need to contact who can help you identify an incident. For example, your web hosting provider, IT support services or cloud service provider. Document the details of the contract, including what is covered, how they can help you, and at what point do you need to engage with them. Being prepared and having relevant documents accessible and up to date could save you time post incident.
Action point: Have you got the most up to date contact information for those you need to contact? Is it stored in the right place and easy to access, keeping in mind that your normal means of communication may be disrupted during an incident? Schedule in time to check these details every couple of months or as necessary.
If you have Cyber Insurance, have your insurer's details documented including policy number and any specific information your provider asks for. Understand any legal or regulatory compliance you must adhere to and implement any guidelines/policies/rules they set out for you. You should check if your trade association has any help or advice lines that you can contact to help you in this situation.


