Your team has no security staff. Someone clicks a phishing link, or ransomware starts encrypting files. What do you do in the first 30 minutes?
Most small teams don't have an incident response plan. They freeze. They Google frantically. They call someone who knows someone. By the time they act, the damage is done.
Here's what actually works in the first 30 minutes — based on real incident response experience with teams of 1–50 people.
Minute 0–5: Contain, Don't Investigate
The instinct is to figure out what happened. Resist it. Your job in the first 5 minutes is to stop the bleeding.
- Disconnect the affected machine from the network (pull the Ethernet cable, turn off Wi-Fi)
- Do NOT turn it off — you'll lose volatile memory that could be evidence
- Note the time — everything that follows depends on an accurate timeline
Minute 5–10: Assess the Blast Radius
Now you need to know: is this one machine, or is it spreading?
- Check if other users are reporting similar symptoms
- Look at your email filter — did the phishing email go to others?
- If ransomware: are other machines showing encryption activity?
- If it's spreading: isolate the network segment, not just one machine
Minute 10–15: Notify (Even If It's Embarrassing)
Tell people who need to know:
- Your IT person or MSP (if you have one)
- Your manager or business owner
- Do NOT notify all staff yet — you don't want to cause panic or tip off the attacker
If you're a solo operator or tiny team, this might just be you writing down what's happening. That's fine. The act of documenting forces clear thinking.
Minute 15–25: Preserve Evidence and Take Initial Action
- Take photos of any error messages, ransom notes, or suspicious screens
- Change passwords for any accounts that were on the affected machine (email, admin panels, cloud services)
- Enable MFA on any accounts that don't have it yet
- Check for data exfiltration: are there large outbound transfers in your firewall logs?
Minute 25–30: Decide — Fight or Flight
You now have enough information to make a critical decision:
- Can you handle this internally? (isolated phishing click, contained malware)
- Do you need external help? (active ransomware, data breach with regulatory implications)
If you need external help, call now. Incident response firms bill by the hour, and the clock is running on your data.
What You Need Before the Bad Day
The teams that survive incidents aren't the ones with the best tools — they're the ones with a plan they've actually read.
Here's what I recommend for small teams (1–50 people):
- A one-page incident response plan — who to call, what to do, in what order
- A severity matrix — SEV1 through SEV4, with clear escalation authority for each
- Communication templates — pre-written messages for staff, customers, and stakeholders
- Containment checklists — OS-specific steps for Linux, macOS, and Windows
- Tabletop exercises — practice runs for ransomware, phishing, insider threats, lost laptops, and data exfiltration
Free Start
If you're a small team without a plan, grab the First 30 Minutes checklist — it's free and covers the essential steps above in a printable format.
For teams that want the full toolkit — incident response plan template, severity matrix, tabletop exercises, comms templates, and containment checklists — the Ops Starter Kit bundles everything for $19.64.
The worst time to write an incident response plan is during an incident. The best time is now, when everything is calm and you can think clearly.
Take 30 minutes today. Your future self will thank you.
What's your team's incident response plan? Have you ever had to use it?
Top comments (0)