Skip to main content
Resource library
Incident readinessSmall-business owners, operations leaders, and technology contacts

Something Happened: Small Business Cyber Incident First Actions

A practical first-hour guide for stopping immediate loss, choosing the right scenario actions, preserving useful facts, and calling the right people.

Working guide

Use the relevant sections, keep the defined outputs, and use the completion checks before moving on.

Start the guide

Author

Trawvid Sec

Published

Last reviewed

Review status

Current

Before you begin

Set up the work

Expected effort: The universal first actions should take less than five minutes to read. Use only the scenario paths that fit the event. A preparation review normally takes about 30 minutes.

Bring these inputs

  • A known-clean phone or communication channel that does not depend on the suspected system.
  • Current leadership, technology-provider, bank, insurer, legal, and critical-vendor contacts.
  • A safe place outside the suspected environment to record times, facts, actions, and case numbers.

Keep these outputs

  • A named incident owner, trusted communication path, and next update time.
  • A short incident timeline with the relevant scenario actions and outside contacts.
  • A business-approved recovery order and open-action handoff.

If something is happening now, start here

Do not wait for a perfect diagnosis. The first job is to protect people, stop immediate loss, keep a useful record, and avoid making the event harder to investigate.

The universal first actions

  1. Protect people and physical operations. Life safety and operational safety come before a computer.
  2. Call the bank if money may have moved. Use a known number and ask for the fraud or wire department. Request a recall or reversal and record the case number.
  3. Limit active spread when it is safe. Disconnect a clearly affected device from wired and wireless networks when malware appears to be spreading. Do not connect backups or random cleanup tools.
  4. Move communication away from suspected systems. If email or chat may be compromised, use a known-clean phone or another trusted channel.
  5. Name one incident owner. That person coordinates actions, times, facts, outside calls, and the next update. They do not need to perform every technical task.
  6. Get qualified help when the business cannot confidently contain, preserve, scope, or recover. A serious event is not the time to learn digital forensics through search results.

Avoid these common mistakes:

  • Do not wipe, reimage, or broadly reset systems before useful evidence needs are understood.
  • Do not delete suspicious messages, logs, or files just because they look dangerous.
  • Do not coordinate through an account that may be compromised.
  • Do not make public or customer statements beyond the supported facts.
  • Do not delay a bank, emergency, insurer, legal, or law-enforcement call while waiting for Trawvid Sec to reply.

Open one simple control record:

Incident or concernDiscovered date and timeIncident ownerLeadership decision-makerTrusted communication channelNext update

Then use every scenario below that may apply. A fraudulent payment may also involve a compromised mailbox. A provider incident may also expose sensitive information.

Choose the scenario actions that fit

Payment, wire, payroll, or invoice fraud

Act quickly. Recovery options get worse as time passes.

  • Call the originating financial institution through a known number.
  • Ask for the fraud or wire department and request a recall or reversal.
  • Record the case number, time, instructions, and next follow-up.
  • Verify the request with the intended vendor, employee, executive, or advisor through a known second channel.
  • Preserve the original request, invoice, message, email headers when available, and transaction confirmation.
  • Review related payments and recent changes during the suspected exposure window.
  • File promptly with IC3 when the event involves internet-enabled fraud.
  • Use the account-compromise path below if a mailbox or identity account may be involved.

Do not continue the suspicious thread to ask whether it is legitimate. Contact the known person another way.

Email, cloud, or identity account compromise

Use a known-clean device and administrative path when available.

  • Move response communication outside the suspected account.
  • Preserve available sign-in history, active sessions, forwarding rules, inbox rules, delegates, recovery changes, multifactor changes, and connected applications.
  • Block or suspend sign-in when the evidence and business impact support it.
  • Revoke active sessions and refresh tokens.
  • Reset the credential to a unique value from a known-clean device.
  • Remove unknown recovery methods, forwarding, delegates, and application permissions.
  • Re-establish the legitimate user and verify known devices.
  • Review which financial, payroll, cloud, customer, domain, social, and password-recovery workflows the account could influence.

Do not assume a password change ends the event. Sessions, forwarding rules, recovery methods, and connected applications may survive it.

Lost or stolen phone or computer

  • Record the device owner, type, identifying information, last known time, and location.
  • Determine whether the device was encrypted, locked, managed, and signed in to important accounts.
  • Preserve management records showing encryption, last check-in, and actions taken.
  • Use trusted locate, lock, or erase controls when the facts support that decision.
  • Revoke high-risk sessions and protect accounts available from the device.
  • For a phone, contact the carrier through a known number and check for a number transfer or SIM change.
  • Record whether sensitive, regulated, confidential, or contract-protected information may have been available.
  • Make a police report when theft is suspected and keep the report number.

Malware, ransomware, or spreading unusual activity

  • Disconnect confirmed or strongly suspected devices from networks when safe.
  • Coordinate broader isolation through network controls when many systems are involved.
  • Protect backup administration and known-good recovery points. Do not connect offline backups to test them.
  • Preserve ransom notes, screenshots, filenames, alerts, logs, and a representative affected-system list.
  • Contact qualified response support when the business cannot confidently contain or preserve the event.
  • Contact the cyber insurer according to the policy and confirm any vendor requirements before major expense when time permits.
  • Record who can stop operations, approve workarounds, and decide recovery order.
  • Report ransomware to a local FBI field office or IC3 and consider reporting to CISA.

Do not download a decryptor or cleanup utility from a random search result. Do not treat an extortion payment like an ordinary purchase. The FBI does not support paying ransom, and payment does not guarantee recovery or deletion.

Sensitive information may have been exposed

  • Stop additional access by restricting the folder, disabling the public link, removing the page, or isolating the source.
  • Preserve screenshots, settings, access history, logs, message headers, and timestamps before changing more than necessary.
  • Record what information was involved, whose information it was, and the likely exposure period.
  • Determine whether information was viewed, downloaded, altered, or only potentially available.
  • Identify affected systems, providers, contracts, customers, and business relationships.
  • Engage qualified counsel before making legal-notification conclusions or definitive external statements.
  • Assign someone to check for copies in recipient systems, search results, caches, or other locations.

Do not say "no data was accessed" merely because access has not yet been proven.

A vendor or technology provider reported an incident

  • Identify what the provider can access, administer, reset, export, delete, or interrupt.
  • Preserve the provider notice and your own relevant logs before retention periods close.
  • Ask for dates, affected services, customer impact, required actions, containment status, and the next update time.
  • Narrow unnecessary access or rotate affected credentials when the facts support it.
  • Verify remediation that matters to your environment rather than relying only on a general assurance.
  • Assign the customer, contract, insurance, legal, and regulatory questions to the appropriate people.
  • Record any decision to keep access active because immediate removal would create a larger safety or continuity problem.

Keep one running record

Do not create a different worksheet for every thought. Keep one timeline that separates facts, assumptions, actions, decisions, and open questions.

TimeFact, assumption, action, or decisionSource or personResult or reasonOwnerNext action or update

Preserve original records before forwarding, editing, wiping, or reimaging. Store the incident record outside the suspected environment and limit access to people who have a role in the response.

A new responder should be able to read the timeline and understand what is known, what remains uncertain, what has been done, and what decision comes next.

Decide who needs to be called

Not every event needs every outside party. Every material call should have an owner and a next follow-up.

PartyCall whenTrusted contactOwnerCase number or next follow-up
Bank or payment providerMoney moved or payment details may be fraudulent
Technology or incident-response providerThe business cannot confidently contain, preserve, scope, or recover
Insurer or brokerThe policy may require notice or approved response vendors
Qualified counselPersonal, regulated, contract-protected, extortion, employee, or material notice questions may exist
Law enforcement or governmentFraud, ransomware, theft, or another reportable crime may be involved
Critical customer or partnerSupported facts show a material operational or contractual impact requiring coordinated communication

Give leadership the known business impact, uncertainty, decisions required, and next update time. Give technical responders the systems, accounts, indicators, evidence, actions, and dependencies. Give employees only the instructions they need to avoid more harm and continue approved work.

Technical staff should not guess legal duties. Legal reviewers should not guess technical facts. Keep the handoff explicit.

Recover in business order

Containment is not the finish line. Restore services according to business need, not whichever system is easiest to turn back on.

Service or processBusiness priorityWorkaroundTechnical ownerBusiness approverReturn criteria or remaining concern

Before returning an affected service:

  • Address the suspected access path enough to avoid immediate recurrence.
  • Review affected credentials, sessions, keys, integrations, and administrator paths.
  • Confirm the restore source is appropriate.
  • Confirm required updates, logging, and monitoring are operating.
  • Test that the service performs the business function expected.
  • Record who approved the return, what remains uncertain, and how long heightened monitoring will continue.

Keep a service offline when the return criteria are not met and an approved workaround is safer.

Prepare before the first hour

Do this section when no incident is active.

  1. Name the incident owner, leadership decision-maker, and backups.
  2. Save known-clean contact methods for the technology provider, bank fraud team, insurer or broker, counsel, and critical vendors.
  3. Decide where the incident timeline can be kept when company email or cloud storage is unavailable.
  4. Record where asset, account, log, backup, insurance, and recovery information can be reached.
  5. Choose a communication method outside company email.
  6. List the business processes that must return first.
  7. Walk through one realistic scenario for 20 minutes.
  8. Fix the largest assumption the exercise exposes.

The preparation is usable when:

  • The contact information works without company email.
  • Decision authority is clear.
  • The business knows where its basic records and recovery information live.
  • One scenario has been discussed.
  • Every discovered gap has an owner and date.

If the event is active and material, use the email and booking options on this page only as an additional advisory path. Do not delay emergency services, a financial institution, the phone carrier, an existing response provider, the insurer, qualified counsel, or law enforcement while waiting for a reply.

Keep working

Practical next step

If the contact list, decision owners, evidence sources, or recovery order are unclear, build those answers before an incident forces the conversation.

Prepare for the first hour

Reference baseline

Sources