An incident response plan does not need to be a 50-page document to be useful for a small business. A clear, practical checklist — understood by the people who would actually use it — is more valuable than a detailed plan sitting in a folder that no one has read. This guide provides a simple checklist structure you can adapt for your business.
Preserve evidence first
The first instinct when something goes wrong is often to fix it immediately. Resist this. Making broad changes before documenting what you observe destroys evidence that helps you understand what happened, whether it has been fully resolved, and whether notification obligations apply. Evidence loss can also complicate insurance claims if you carry cyber insurance.
Document first: take screenshots of anything unusual (redirects, unexpected content, error messages, browser warnings). Note the date, time, and which device and browser you were using. Save a copy of any relevant emails, alerts, or notifications from hosting providers or security tools. If you have server access, download a copy of recent access logs before making any changes.
Photograph or screenshot any error messages rather than dismissing them. Even a generic server error message contains useful information about what failed and when. The pattern of when something happened — was it a gradual change or a sudden one? — is part of the evidence base.
Contain accounts and devices
Containment means limiting further spread or damage while you investigate. For a suspected email account compromise, this means changing the password, revoking active sessions, removing suspicious inbox rules, and enabling MFA. For a suspected website compromise, this means taking the site offline or placing it in maintenance mode while you investigate — not because the site is necessarily broken, but because continuing to serve potentially malicious content to visitors is itself a harm.
If a device (a staff laptop or phone) may have been compromised — for example, someone opened a malicious attachment — disconnect it from the network and set it aside. Do not use it for further investigation. A compromised device could expose credentials entered during the investigation, or spread malware to other systems on the same network.
Coordinate containment with anyone else who might take action on the same accounts or systems. If you lock a shared email account to investigate, tell the relevant staff member so they do not inadvertently undo containment steps.
Escalate when money, data, or public pages are involved
Not every security incident needs external help. A missing security header, an expired SSL certificate, or a spam comment on your blog are handled internally. But certain categories of incident raise the threshold for self-service response: any incident involving financial transactions or payment data; any incident involving customer personal information (names, emails, health information, payment details); any incident where your website is actively serving malware or phishing content to visitors; and any incident you cannot contain or understand within a few hours of initial response.
In Australia, data breaches involving personal information that is likely to cause serious harm to any individual are notifiable under the Notifiable Data Breaches scheme (administered by the OAIC). The test is not whether you are certain harm occurred — it is whether harm is likely. If you are in doubt, seek legal advice before making public statements or deciding not to notify.
- Document before acting: screenshots, timestamps, error messages, access logs.
- Change compromised credentials: hosting, WordPress admin, email, FTP, database — in that order.
- Revoke active sessions on any compromised account.
- Take the website offline or into maintenance mode if it may be serving malicious content.
- Isolate any potentially compromised device from the network.
- Contact hosting support if you see server-level issues you cannot access directly.
- Seek legal advice if personal information or payment data may have been exposed.
- Report fraud to Scamwatch and cyber incidents to ReportCyber (cyber.gov.au/report).
When something feels wrong, a simple checklist beats guesswork.
Open the free cyber tools hub