Resilience
A small-business cyber incident plan people can actually use
A short, decision-led plan and tabletop exercise for common cyber incidents.
First response
An incident plan should help named people make the first decisions under pressure. Keep the initial plan short: reporting, authority, safe communications, containment contacts, payment escalation, evidence, legal and insurance escalation, recovery priorities and stakeholder communication. Test it with a plausible scenario before relying on it.
Work through it in this order
- 01
Choose plausible scenarios
Use email compromise, ransomware, lost device, supplier compromise or cloud outage according to the business.
- 02
Name decisions and owners
Record who can isolate systems, stop payments, engage help, communicate and approve recovery trade-offs.
- 03
Build the first-hour card
Include safe contact channels, actions to avoid, evidence notes and essential external contacts.
- 04
Run a facilitated exercise
Reveal information in stages, capture assumptions and avoid turning it into a technical quiz.
- 05
Fund the improvements
Assign owners and dates to the access, backup, supplier, communication and recovery gaps found.
- 06
Retest the hard decisions
Run a shorter follow-up once corrective actions are complete, focusing on the hand-offs and decisions that failed in the first exercise.
Keep these points in view
- Technical containment and business continuity decisions must run together.
- Keep essential contacts and a clean copy of the plan available outside the affected environment.
- A tabletop is valuable when it exposes ownership and information gaps; a perfect script proves very little.
Before closing the issue
- Incident lead named
- Safe contacts available
- Payment escalation defined
- Evidence guidance included
- Recovery priorities approved
- Tabletop completed
- Actions funded and tracked
Easy mistakes under pressure
- Keeping the only plan inside the system that may be unavailable
- Assuming the IT provider owns legal, payment and communication decisions
- Running an exercise without tracking corrective actions
Official guidance to keep nearby
- Australian Signals Directorate, Australian Cyber Security Centre — Annual Cyber Threat Report 2024–25
- Australian Signals Directorate, Australian Cyber Security Centre — Small business cyber security guide
- Australian Signals Directorate, Australian Cyber Security Centre — Business email compromise
Links and technical details checked 2 September 2026. Corrections can be sent to info@turnstoneai.com.