Skip to content

Make the first hour less improvised

Prepare a small-business incident card

Create a short offline action card for suspicious access, lost devices, outages, damaged data, scams, and vendor incidents.

TARGET OUTPUT

What this field note should leave behind

The first person who notices a problem knows who leads, what to preserve, which safe contact channel to use, and what not to do.

SEQUENCE / 04

Work the problem in this order

  1. 01

    Name an incident lead, backup lead, technology contact, insurance contact, legal or privacy contact when applicable, and the owner of external communication.

  2. 02

    Write a short sequence: protect people, use a known-safe channel, record what was observed, limit further harm when qualified to do so, preserve evidence, and contact the right support.

  3. 03

    Add verified phone numbers and provider support paths from contracts or official vendor pages. Do not rely only on links or numbers in a suspicious message.

  4. 04

    Store copies where the team can reach them during an account or internet outage. Run a short tabletop scenario and revise the card from what people could not answer.

CHECK BEFORE CLOSE

Evidence worth seeing

  • The card tells staff not to investigate beyond their role or destroy potentially useful evidence.
  • Notification decisions are assigned to qualified people, not guessed in the moment.
  • Customer, employee, regulator, insurer, law-enforcement, and vendor communication paths are separated.
  • The card is dated and reviewed after staff, vendor, insurance, system, or legal changes.
ESCALATION BOUNDARY

Know when general guidance stops

Contact qualified incident response, legal, privacy, insurance, provider, and law-enforcement channels as the facts require. This field note is not an incident response service or breach-notification determination.