When a security incident hits a small team, the first 30 minutes decide everything. Most small businesses have no security staff, no incident response plan, and no idea what to do first.
I've seen teams lose entire customer databases because nobody knew who to call, what to document, or how to contain the damage. The panic is real. The cost is real. And the fix is simpler than you think.
The First 30 Minutes Framework
Here's what happens in the first 30 minutes of an incident at most small businesses:
- Someone notices something wrong (slow system, locked account, weird email)
- They tell a colleague (not the right person, usually)
- Everyone panics (no clear chain of command)
- Someone Googles "what to do" (loses 15 minutes)
- By minute 30, the damage is done
The teams that survive incidents follow a different pattern. They have a one-page checklist that tells them exactly what to do, in what order, and who to call.
The One-Page Checklist
Here's the framework I give every small team I work with:
Minute 0-5: Detect & Acknowledge
- [ ] Confirm the incident is real (not a false alarm)
- [ ] Note the time, what you observed, and which systems are affected
- [ ] Assign one person as Incident Lead (they own all decisions)
Minute 5-15: Contain
- [ ] Isolate affected systems (disconnect from network, don't power off)
- [ ] Preserve evidence (take screenshots, save logs)
- [ ] Change passwords on affected accounts
- [ ] Disable compromised API keys or access tokens
Minute 15-25: Communicate
- [ ] Notify your team (who needs to know, what they should do)
- [ ] Notify affected customers (if their data is at risk — honesty builds trust)
- [ ] Contact your insurance provider (if you have cyber coverage)
- [ ] Document everything in a timeline (this is your legal record)
Minute 25-30: Decide
- [ ] Is the incident contained? If yes, move to recovery
- [ ] Do you need external help? (Call a security firm if the damage is severe)
- [ ] Schedule a post-incident review within 48 hours
Why Most Teams Skip This (And Regret It)
The #1 reason small teams don't have an incident response plan: they think they're too small to be targeted.
The reality: 43% of cyber attacks target small businesses. The average cost of a data breach for a small business is $200,000. 60% of small businesses that suffer a breach go out of business within 6 months.
You don't need a 50-page runbook. You need a one-page checklist that anyone on your team can follow under pressure.
Get the Free Checklist
I've put together a free, one-page incident quick-start checklist that covers everything above — formatted to print and pin to your wall.
👉 Download the free "First 30 Minutes" checklist here
No email required. No signup. Just download it, print it, and hope you never need it.
What's Next
Once you have the checklist, the next step is to customize it for your team:
- Add your emergency contact numbers
- List your critical systems and who owns each one
- Identify your most sensitive data and where it lives
- Schedule a 30-minute drill with your team to practice
The teams that practice incident response once are 10x more effective when it actually happens.
This article is part of a series on practical operations for small teams. If you found it useful, check out the Ops Starter Kit for a complete incident response template, communication scripts, and post-incident review framework.
Top comments (0)