top of page

Small Business Incident Response Checklist: Would Your Business Know What to Do?

Aug 26
10 min read

Updated: 7 days ago

Small Business Incident Response Checklist with free downloadable Incident Response Readiness Workbook from SNL-Tech Services.
Free Small Business Incident Response Readiness Workbook to help business owners document emergency contacts, IT responsibilities, Microsoft 365 access, cyber insurance, financial fraud response and recovery planning.

Most small business owners know they should have some kind of plan for a cybersecurity incident. The harder question is whether the business could actually use that plan when something goes wrong.


If an employee thinks their computer has been compromised, who do they call? If nobody answers, what happens next? Who has authority to tell IT to isolate a computer or block an account? Who contacts the cyber insurance carrier? What happens if someone follows fraudulent banking instructions? If Microsoft 365 is part of the incident, can the business still access the administrative accounts it needs to respond?

Those are not questions I want a business owner trying to answer for the first time while an incident is already happening.


That is why I created this small business incident response checklist and readiness workbook. It is a free, fillable and print friendly resource designed to help a small business identify what it already has in place, what still needs to be decided and who needs to be involved.

Download Here:


A Small Business Incident Response Checklist Is Not the Same as an Incident Response Plan

I want to make this distinction clear because downloading a checklist does not mean your business suddenly has an incident response plan.


A checklist can help uncover the questions. A real Incident Response Plan for Small Business needs your business's answers.


That means understanding your employees, technology, Microsoft 365 or other cloud environments, vendors, insurance, locations, regulatory or contractual requirements, financial processes, backups and the people who actually have authority to make decisions during an emergency.


Current NIST small business guidance takes a similar approach. Its 2026 Respond and Recover worksheet recommends identifying the people and outside contacts involved in a response, their responsibilities and authority, and applicable reporting requirements before an incident occurs. NIST also emphasizes customizing the response based on the individual business.


That is exactly how I look at incident response planning. The same template cannot tell a five person law firm, construction company, medical practice, accounting firm or government contractor exactly what its response should look like.


Who Does an Employee Call When Something Happens?

This is one of the first things the workbook asks you to document because it sounds obvious until the person everyone normally calls is unavailable.

  • Who is the primary incident contact? Who is the backup?

  • What happens after hours?

  • How long should someone wait before escalating?

  • Does IT have a separate emergency number?

  • Who has authority to activate the response process?

The workbook gives you space to actually write those answers down rather than simply checking a box that says you have an IT contact.


I do this with my own clients. They know how to reach me normally, but we also discuss what they should do if something is an emergency and they cannot immediately get me. Your business may use a completely different escalation process. The important part is that the people who may need it already know what that process is.


Does IT Know What It Is Authorized to Do?

“Call IT” is not a complete incident response procedure.

Once IT gets the call, what happens next? Can IT immediately isolate a computer that appears to be compromised? Who can authorize taking a critical server or application offline? Can a Microsoft 365 account be blocked if there is evidence that it has been compromised? Who makes the decision if an action could interrupt normal business operations?


Those responsibilities need to be discussed before the emergency.

I also want IT to know what it is responsible for documenting. If an account is blocked, a device is isolated, a firewall rule is changed or a server is taken offline, those actions should become part of the incident timeline. If an outside forensic specialist, cyber insurance carrier or another professional becomes involved later, they should not have to reconstruct the first several hours from everyone's memory.


This is also where current IT documentation becomes extremely important. Responding to an incident is much harder if nobody has an accurate inventory of the computers, servers, network equipment, cloud environments, administrative accounts, backups and vendors involved.

If you are not confident your business could answer those questions today, a Small Business IT Checklist and Systems Inventory or an IT Baseline Assessment can help establish what is actually in the environment before you try to build response procedures around it.


What Happens if Microsoft 365 Is Part of the Incident?

For many small businesses, Microsoft 365 is no longer just email. It may be tied to company identities, SharePoint, OneDrive, Teams, managed computers and security tools.

That makes one question particularly important: What happens if the account that normally administers Microsoft 365 is the account that gets compromised?


This can become an especially difficult situation when the business owner uses the same account for everyday email and Microsoft 365 administration. If an attacker gains control of that identity, the potential problem may extend beyond one mailbox depending on the administrative privileges assigned to the account.


Microsoft currently recommends maintaining two or more cloud only emergency access accounts for situations where normal administrative access cannot be used. These accounts are commonly called emergency access or break glass accounts. Microsoft's current guidance also addresses how those accounts should be protected, monitored and periodically validated.


The workbook therefore asks whether your business knows who has Microsoft 365 administrative privileges, whether everyday user accounts are appropriately separated from privileged administrative access, whether emergency administrative access exists, who investigates Microsoft security alerts and whether the logging, licensing and administrative access needed for an investigation are actually available.


These are also some of the areas I evaluate during a Microsoft 365 Audit and Tenant Security Review. The goal is not simply to check whether MFA is turned on. I want to understand whether the environment is configured, monitored and documented in a way that gives the business useful options when something actually goes wrong.


What if the Incident Involves Business Email Compromise or Fraud?

Cybersecurity incidents do not always announce themselves with ransomware or a computer behaving strangely. Sometimes the first obvious sign is a vendor asking why an invoice was never paid, an employee discovering their direct deposit information was changed or accounting realizing that money was sent using fraudulent banking instructions.

That is why Business Email Compromise and financial fraud have their own section in the workbook.


It asks whether employees know how to report a suspicious payment, banking or payroll change, whether financial changes are independently verified, who can delay a payment while something is investigated, who contacts the bank if money has already moved and who handles the technical investigation.


If fraudulent money transfers are involved, time matters. The FBI advises Business Email Compromise victims to contact their financial institution immediately and request that it contact the financial institution where the transfer was sent. The FBI also directs victims to report BEC through the Internet Crime Complaint Center, commonly called IC3.


The financial response may need to happen at the same time as the technical investigation.

A fraudulent email also does not automatically tell us whose account was compromised. The company's Microsoft 365 account could be compromised. The vendor's account could be compromised. The sender could have been spoofed. An attacker could be using a lookalike domain.

That needs to be investigated rather than assumed.


Technology is an important part of BEC prevention and response, but it should not be the only thing protecting a significant financial transaction. Businesses should establish their own procedures for independently verifying changes to banking, payment or payroll information before money moves.


Your Emergency Information Should Not Exist Only on Your Computer

This is one of the reasons I wanted the workbook to be both fillable and print friendly.

Imagine that your incident response information is stored in SharePoint, but Microsoft 365 is involved in the incident. Maybe it is on your server, but the server is unavailable. Maybe ransomware has affected the network. Maybe the office itself cannot be accessed because of a fire, storm, break in or another physical event.


The response information is not very useful if the emergency prevents you from getting to it.

I recommend maintaining a current printed copy in a secure location that designated response people can access even if Microsoft 365, the network or the normal office is unavailable. Depending on the business, controlled copies might be maintained by the owner, office manager, designated manager, after hours contact or another person with a defined role in the response.


I would not leave a completed copy sitting openly around the office. Once filled out, the workbook may contain names, phone numbers, cyber insurance information, vendor contacts, escalation procedures and other operational details. Both the electronic and printed versions should be protected appropriately.

The workbook includes a printed copy control section so the business can document who has each copy and where it is securely stored.


If Email Is Unavailable or Cannot Be Trusted, How Will Everyone Communicate?

This is another question that can easily get overlooked.

If Microsoft 365 or company email is suspected of being compromised, should everyone continue discussing the incident through that same system?


The answer depends on what is happening, which is why the workbook includes a place to document an alternate communication method ahead of time.


That could be phone calls, text messaging or another communication method the business has determined is appropriate. I intentionally do not tell every business what its alternate method must be. The right answer depends on the organization.


What matters is that the people involved know how they will communicate if the normal method becomes unavailable or should not be trusted.


Do You Know Who Calls the Insurance Company, Bank, Attorney or Outside Specialist?

Incident response is not exclusively an IT responsibility.

IT may be investigating accounts, devices, logs, email, Microsoft 365, servers, firewalls and other technical systems. Someone else may need to contact the bank. Cyber insurance may have its own incident reporting procedure. Legal counsel may need to become involved. A regulated business may have specific reporting requirements. A serious incident may require a forensic specialist.


The workbook gives you a place to identify those contacts and, just as importantly, determine who is responsible for making those calls.


That distinction matters. As an IT provider, my role can include investigating the technical environment, documenting findings, performing technical containment and remediation within my scope, preserving relevant technical information and helping restore operations. That does not make me the person who determines whether a particular event creates a legal notification requirement, whether an insurance policy provides coverage or whether a formal forensic examination is necessary.


Those responsibilities need to be understood before the business is in the middle of an emergency.


Could Your Business Continue Operating?

Incident response is only one part of preparing for a serious event.

What happens if Microsoft 365 is unavailable? What if the server needs to remain offline? What if multiple computers cannot be trusted? What if the normal office cannot be used?

That is where incident response begins to intersect with disaster recovery and business continuity.


Your business should know which systems need to be restored first, where critical backups are located, who is responsible for recovery, how employees will communicate and how critical work could continue while the technical investigation or restoration is still underway.

Those priorities are going to look different for every business. An accounting firm during tax season may have very different operational priorities from a construction company, healthcare practice or law firm.


The important part is having the conversation before you need the answer.


Keep a Timeline While the Incident Is Happening

I also added an Incident Timeline and Action Log to the workbook.

If the workbook ever has to come out of the drawer during a real incident, the business can start recording what was observed, when it happened, who was contacted, which users, devices or systems appear to be involved and what actions were taken.

Start with facts rather than assumptions.


If an employee says their mouse moved on its own at 2:13 PM, document that. If IT blocked an account at 2:28 PM, document that. If you do not yet know whether another account was affected, write that it is unknown rather than guessing.


That timeline can become extremely useful as IT investigates the incident and if an insurer, attorney, forensic specialist, law enforcement agency, regulator or another outside resource later needs an accurate account of what happened.


“I Don't Know” Is a Useful Answer

One thing you will notice in the workbook is that I did not make this a simple Yes or No checklist.

For the readiness questions, you can select:

Yes | No | I Don't Know | Needs Review

I specifically wanted I Don't Know included.

If you ask, “Do we have emergency administrative access to Microsoft 365?” and nobody in the business knows the answer, that is useful information.

If you ask, “Who contacts our cyber insurance carrier?” and three managers give you three different answers, that is useful information too.


The purpose of the workbook is not to give your business a cybersecurity score. You do not reach the bottom, count the boxes and decide that you are 87 percent prepared.

An unanswered question is a finding.


Maybe nobody knows the cyber insurance claims number. Maybe the owner is the only Microsoft 365 administrator. Maybe there is no backup emergency contact for IT. Maybe the business has never discussed what happens if fraudulent banking instructions are followed. Maybe backups exist, but nobody knows which systems should be restored first.

Those are useful things to discover on a normal business day instead of during an actual emergency.


Download the Free Small Business Incident Response Readiness Workbook

The Small Business Incident Response Readiness Workbook is a five page fillable PDF that you can complete electronically and print for secure offline storage.

It covers:

  • Business and primary response information

  • Incident leadership and escalation

  • Critical outside contacts

  • IT responsibilities and response authority

  • Microsoft 365 and cloud administrative readiness

  • Business Email Compromise and financial fraud

  • Cyber insurance contacts

  • Evidence and documentation

  • Legal, regulatory and contractual considerations

  • Recovery and business continuity

  • Testing and periodic review

  • Incident timeline and action logging

  • Priority follow up items

  • Printed copy control

DOWNLOAD THE FREE SMALL BUSINESS INCIDENT RESPONSE READINESS WORKBOOK Here:

This workbook is a readiness tool, not a completed Incident Response Plan. Checking every box does not establish that your business is secure, compliant, insurable or prepared for every possible incident. The purpose is to identify the questions your business has already answered and the ones that still need attention.


If working through the workbook leaves you with a lot of No, I Don't Know or Needs Review answers, my Incident Response Plan for Small Business: How to Build One That Actually Fits Your Business goes deeper into how I approach building the actual response around the people, technology, vendors, insurance, financial processes, regulatory requirements and operations of the individual business.


The goal is not to predict every possible incident. It is to make sure that when something does happen, your employees are not starting with the question, “What are we supposed to do now?”


ADDITIONAL RESOURCES

National Institute of Standards and Technology: Small Business Cybersecurity, Non Employer Firms, CSWP 50 Initial Public Draft, April 2026

NIST's 2026 small business cybersecurity draft includes a Respond and Recover worksheet covering response contacts, responsibilities, authority and reporting considerations. NIST notes that response planning should be customized based on the individual business. This publication remains an Initial Public Draft as of August 2026.https://csrc.nist.gov/pubs/cswp/50/small-business-cybersecurity-non-employer-firms/ipd


Microsoft Learn: Manage Emergency Access Admin Accounts

Microsoft's current guidance recommends maintaining two or more cloud only emergency access accounts and explains how those accounts should be protected, monitored and periodically validated.https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/security-emergency-access


Federal Bureau of Investigation: Business Email Compromise

The FBI provides current information about Business Email Compromise, steps to take following fraudulent transfers and reporting through the Internet Crime Complaint Center.https://www.fbi.gov/how-we-can-help-you/common-frauds-and-scams/business-email-compromise


Federal Trade Commission: Cybersecurity for Small Business

FTC resources cover cybersecurity planning for small businesses, including incident response, business continuity and recovery considerations.https://www.ftc.gov/business-guidance/small-businesses/cybersecurity


Cybersecurity and Infrastructure Security Agency: Cyber Guidance for Small Businesses

CISA provides cybersecurity resources and guidance designed for small and medium sized businesses.https://www.cisa.gov/audiences/small-and-medium-businesses

Comments


bottom of page