The plan we actually run when something goes wrong — written down, and published, because the moment to find out how your IT partner handles a crisis is before the crisis.
No form, no email required — read it before you need it.
Most IT providers keep their incident process in their heads. We wrote ours down and published it, because the moment to find out how your IT partner handles a crisis is before the crisis, not at 2 a.m. during one.
This is the playbook our team follows when a client is under attack, down, or unsure. It is deliberately calm. Panic skips steps, destroys evidence, and turns a bad hour into a bad week — our job is to already know the next move so you don’t have to.
It is built on the incident-response lifecycle from NIST SP 800-61 — Prepare, Detect & Analyze, Contain, Eradicate & Recover, and Learn — adapted for the real conditions of a small or mid-sized business. Four pages, free, and no email address required.
An incident is any event that threatens the confidentiality, integrity, or availability of your systems or data — something broken, exposed, or under attack that needs a coordinated response, not just a help-desk ticket. We classify every one so the response matches the stakes.
| Severity | What it looks like | Our response |
|---|---|---|
| SEV-1 — Critical | Active ransomware, confirmed breach, full outage of a critical system, funds at risk | Immediate all-hands. Incident Commander assigned. Owner called, not emailed. |
| SEV-2 — High | One compromised account, malware contained to a machine, a key system degraded, targeted phishing | Rapid response, senior engineer engaged, client notified within the hour |
| SEV-3 — Moderate | Suspicious activity, isolated outage, a failed backup, a lost device | Same-day investigation, monitored to resolution |
| SEV-4 — Low | A blocked threat, a single reported phishing email, a minor anomaly | Logged, reviewed, used to tune defenses |
Severity can move in either direction as we learn more. We would rather over-classify for the first thirty minutes than under-react.
In an incident, unclear roles cost time. The playbook assigns them immediately — an Incident Commander who owns the response and keeps the timeline, the Technical Lead(s) doing containment and recovery, a Communications Lead so your team gets one clear voice instead of five fragments, and your decision-maker, looped in from the start for anything touching operations, money, or legal exposure.
The opening hour sets the tone. This is the checklist, in order:
Six specific playbooks, each with the moves that matter and the mistakes that cost the most:
Isolate immediately but do not power machines down — it destroys evidence. Assess recovery options before any thought of payment; with tested backups, paying is usually avoidable.
Reset credentials and revoke sessions, then hunt for attacker-created mailbox rules — auto-forward and auto-delete are the classic hidden footholds. Every payment change is verified by voice.
Disable, revoke tokens, reset, re-enroll MFA. Review what the account could reach and whether it was used to move laterally. Assume the credential is public and rotate what it shared.
Contain the access path first, then determine what data, whose, and how much — that drives the legal and notification obligations. Breach notification has deadlines, not just technical steps.
Establish what’s down and the business impact, then work the restore in priority order — decided in advance, not during. Steady status cadence, so silence never reads as “still broken.”
Remotely lock or wipe, revoke access and sessions, rotate any credentials it held. Assess what data it could reach and whether encryption was enabled — it should have been.
This playbook is a general framework, adapted to each client’s systems, obligations, and risk. It is guidance, not a substitute for a response plan built for your specific environment.
The full playbook — 4 pages, print-ready, no form and no email required.
A straight read on where you’re exposed and what to shore up first — no pitch. Because the best time to meet the team that answers at 2 a.m. is long before you need them.