Make the first hour less improvised
Prepare a small-business incident card
Create a short offline action card for suspicious access, lost devices, outages, damaged data, scams, and vendor incidents.
What this field note should leave behind
The first person who notices a problem knows who leads, what to preserve, which safe contact channel to use, and what not to do.
Work the problem in this order
- 01
Name an incident lead, backup lead, technology contact, insurance contact, legal or privacy contact when applicable, and the owner of external communication.
- 02
Write a short sequence: protect people, use a known-safe channel, record what was observed, limit further harm when qualified to do so, preserve evidence, and contact the right support.
- 03
Add verified phone numbers and provider support paths from contracts or official vendor pages. Do not rely only on links or numbers in a suspicious message.
- 04
Store copies where the team can reach them during an account or internet outage. Run a short tabletop scenario and revise the card from what people could not answer.
Evidence worth seeing
- The card tells staff not to investigate beyond their role or destroy potentially useful evidence.
- Notification decisions are assigned to qualified people, not guessed in the moment.
- Customer, employee, regulator, insurer, law-enforcement, and vendor communication paths are separated.
- The card is dated and reviewed after staff, vendor, insurance, system, or legal changes.
Know when general guidance stops
Contact qualified incident response, legal, privacy, insurance, provider, and law-enforcement channels as the facts require. This field note is not an incident response service or breach-notification determination.