PROTECT · INCIDENT RESPONSE

Incident Response — What Would You Do If Something Went Wrong?

When an incident happens, the first few decisions matter. A simple plan can stop confusion becoming another problem.

An incident is a business problem

A compromised email account, ransomware infection, lost device, fraudulent payment or unavailable supplier can affect customers, staff, money, information and operations.

Technical investigation may be necessary, but the organisation also needs business decisions: what must be protected first, who needs to know, what can continue and who has authority to act.

Know who takes the first call

People should know how to report something unusual and who receives that report. The response route should not depend on the very system that may have failed.

Keep essential contact information available somewhere appropriate outside the affected environment.

Contain the problem without destroying useful evidence

The immediate objective is often to limit further harm. That may mean disabling an account, isolating a device or contacting a provider. Avoid improvised actions that could make recovery or investigation harder.

For serious incidents, get appropriate specialist, legal, insurance or regulatory advice as required by the circumstances.

Communicate deliberately

Decide who communicates with staff, customers, suppliers and other parties. Share what is known, distinguish facts from assumptions and record important decisions.

After recovery, review what happened and what should change. Incident response is not complete until the organisation learns from the event.

BOI ACTION

Write down your first three incident contacts.

Identify who in the business makes decisions, who provides technical support and who provides an alternative contact if normal email or systems are unavailable.

Make sure the people who may discover an incident know how to reach them.

A useful question for the business

If our main email system were compromised at 9am tomorrow, how would we coordinate the response?

Don’t assume. Check.

A plan stored somewhere is not proof that people can use it. Walk through a realistic scenario and see what happens.

NOT SURE WHERE TO START?

Take the 15-Minute Business Security Check

Ten straightforward questions will help you identify three priorities for sensible action.

Start the free Security Check →

Useful guidance

Final publication QA will verify current UK-first incident-response and reporting guidance and supporting authoritative sources.

Continue exploring

Individual controls work better when the organisation manages security as a connected system.

Explore the Cyber Security Guides →


Found something that may be outdated or incorrect? Let us know.

Better Decisions. Stronger Organisations.

Understand what matters. Take sensible action. Check whether it worked.