Resilience

A small-business cyber incident plan people can actually use

A short, decision-led plan and tabletop exercise for common cyber incidents.

First response

An incident plan should help named people make the first decisions under pressure. Keep the initial plan short: reporting, authority, safe communications, containment contacts, payment escalation, evidence, legal and insurance escalation, recovery priorities and stakeholder communication. Test it with a plausible scenario before relying on it.

Work through it in this order

  1. 01

    Choose plausible scenarios

    Use email compromise, ransomware, lost device, supplier compromise or cloud outage according to the business.

  2. 02

    Name decisions and owners

    Record who can isolate systems, stop payments, engage help, communicate and approve recovery trade-offs.

  3. 03

    Build the first-hour card

    Include safe contact channels, actions to avoid, evidence notes and essential external contacts.

  4. 04

    Run a facilitated exercise

    Reveal information in stages, capture assumptions and avoid turning it into a technical quiz.

  5. 05

    Fund the improvements

    Assign owners and dates to the access, backup, supplier, communication and recovery gaps found.

  6. 06

    Retest the hard decisions

    Run a shorter follow-up once corrective actions are complete, focusing on the hand-offs and decisions that failed in the first exercise.

Keep these points in view

  • Technical containment and business continuity decisions must run together.
  • Keep essential contacts and a clean copy of the plan available outside the affected environment.
  • A tabletop is valuable when it exposes ownership and information gaps; a perfect script proves very little.

Before closing the issue

  • Incident lead named
  • Safe contacts available
  • Payment escalation defined
  • Evidence guidance included
  • Recovery priorities approved
  • Tabletop completed
  • Actions funded and tracked

Easy mistakes under pressure

  • Keeping the only plan inside the system that may be unavailable
  • Assuming the IT provider owns legal, payment and communication decisions
  • Running an exercise without tracking corrective actions

Official guidance to keep nearby

  1. Australian Signals Directorate, Australian Cyber Security Centre — Annual Cyber Threat Report 2024–25
  2. Australian Signals Directorate, Australian Cyber Security Centre — Small business cyber security guide
  3. Australian Signals Directorate, Australian Cyber Security Centre — Business email compromise

Links and technical details checked 2 September 2026. Corrections can be sent to info@turnstoneai.com.

A practical next step

Apply the guidance to the real environment.

Share what is not working, what is changing or what decision needs to be made. Technical answers can come after the business context is clear.