Outsourcing IT makes sense for many SMEs. It still requires clear board-level direction. Without it, blind spots emerge: unknown vulnerabilities, weak supply chains and untested backups. These are exactly the areas where severe and potentially irreversible damage can arise. cyber incident. Not preventing every cyber attack, but the consciously choosing structure, preparation and continuous improvement ensures better control and less damage.
You can't eliminate all the risks. You can do them. control and the impact of an incident limit by prevention, detection and a practiced incident response plan.
Responding out of panic to a cyber attack
A cyber attack often comes unexpectedly and causes stress. It's human to panic, but it's precisely that that's when the wrong choices are made: Too fast to take systems offline, destroy evidence or unclear communication to customers and suppliers.
The solution lies in thinking in advance. Set clear guidelines and identify who has what role in an incident. Make agreements with employees and suppliers about reporting obligations, communication lines and responsibilities. Set up a central hotline where any incident or suspicion of a cyber attack is reported immediately.
By organising this in advance, you prevent panic from taking precedence. You can then fall back on agreed procedures in crisis situations, making the right, balanced choices as an organisation. – even when the pressure is high.
What is a cyber incident?
A cyber incident is any event that threatens the confidentiality, integrity or availability of your information or systems. That may range from a successful phishinginlog to ransomware, data leaks, DDoS, abuse of vulnerabilities or a social engineering fraud (BEC).
Common types of SMEs
- Phishing & social engineering: unlock login details or payment actions.
- Ransomware: file and system encryption, production and delivery stop.
- Entry through suppliers: weak MSP/SaaS configuration as a step to a deeper attack.
- BEC (Business Email Compromise): (invoice) fraud via seemingly legitimate e-mails.
- Exploit: abuse of outdated software or unsafe configuration.
Not every incident has to be a disaster, provided you detect it quickly, limit it, restore it and your network segmentation is sufficient. Time is your most important parameter in a cyber attack.
The impact of a cyber incident: costs, time and trust
Business impact
- Production loss: Stoppage in production, logistics or service.
- Financial damage: repair costs, loss of turnover, fines or claim risk.
- Reputation: customer confidence and partners who are going to make additional demands.
Operational impact
- Recovery capacity: lack of recent clean backups.
- Chain Dependency: suppliers who are also affected.
- Human pressure: Time pressure decisions, information stress.
With a clear incident response plan, you reduce the chance of chaos and make choices that protect continuity.
Prevent Cyber Attack: the 12 basic measures that are always profitable
Prevention is the first line of defense. Start with the smallest package of measures with the greatest impact. This reduces the risk of a cyber incident and reduces the impact when it happens.
- MFA: email, admin accounts (also from internal), external access, SaaS applications, data systems
- Strong password policy: Password manager, length <= 14, no reuse.
- Patch Management: OS, apps, firmware, plug-ins and SaaS add-ins.
- Backups according to 3-2-1 (+immutable): restore periodic tests (restore test).
- Network segmentation: office, OT/industrie, guestnet, IoT; limit lateral movement.
- Email Security: SPF/DKIM/DMARC, anti-phishing policies, blocking executables.
- Least privilege: minimum rights, temporary admin where necessary.
- EDR/XDR on endpoints and servers: Detect and block suspicious behaviour.
- Logging & retention: auditlogs M365/Entra/Azure AD, critical applications, firewall.
- Security awareness: micro-learnings + phishingsimulations + notification button suspicious mail.
- Asset and SaaS inventory: Know what you have, who has access and why.
- Supplier's agreements: clear SLA requirements, security requirements, exit and recovery arrangements.
With this set you avoid most of the .low-hanging .suffering incidents and reduce the impact of the rest.
The Incident Response Plan (IRP): construction, roles and decision-making rules
An incident response plan describes who what does, when and Why. It is short, practical and accessible in crisis time. Make sure it doesn't become a 100-page playbook, which will delay it. Short, concise and clear are the key words here.
Essential elements
- Definitions & classification: What's an incident, how do you scale up, when do we find something an incident (P1OIP4)?
- Rolls & RACI: crisis team, technical lead, communication, legal role, suppliers.
- Playbooks by scenario: Phishing, ransomware, BEC, DDoS, data exfiltration, OT/ICS.
- Communication plan: Internal, customers, partners, possibly media.
- Legal obligations: notifications to supervisors/customers where applicable.
- Recovery & validation: restart criteria, quality control, decision tree.
- Lessons learned: after action review, improvement measures, update IRP, update other policies.
Roles and responsibilities example
Role ResponsibilitiesCrisis ManagerCoordinates, decides on escalation, monitors priorities and communication channels.Technical leadAssesss impact, leads containment/eradication/recovery, switches on suppliers.CommunicationSets internal updates and external statements, manages Q&A and press enquiries.Legal/PrivacyAdvises on reporting obligations and contractual obligations, guarantees evidence.Process ownersPrioritize business-critical processes, accord restart and workarounds.The 6 stages of incident response (from preparation to improvement)
1) Preparation
- Incident response team appointed, accessibility and replacement arranged.
- Tools and access ready: EDR console, SIEM, any forensic toolkit, management accounts.
- Backups tested and documented; remedial procedures.
- Communication templates and contact lists up-to-date (clients, suppliers, media).
2) Identification
- Signals: EDR alerts, abnormal logins, unknown mailbox rules, data streams.
- Quick triage: real incident or false positive? Classify P1O-P4.
- Secure evidence: logs, images, timeline (do not overwrite!).
(3) Containment
- Short term: Isolation of endpoints/segments, withdrawal of tokens/creds.
- Medium term: temporary workarounds, alternative processes, additional monitoring.
- Communication: concise, factual, with clear instructions for employees.
4) Eradication
- Remove malware, back doors, malicious accounts and rules.
- Patching/hardening of relevant systems; password resets and key rotation etc.
- Verify that indicators of compromise (IoCs) are no longer available.
- Implementation extra monitoring via firewalls, for example.
5) Recovery
- Restore Off clean backups; Priority in Critical Processes (RTO/RPO).
- Phased reboot with additional monitoring; validation by process owners.
- Communicate to customers/partners as soon as stability is restored.
6) Lessons learned
- After Action Review: What went well, what could be better, what can we adapt?
- Update of IRP, playbooks, configurations, training and contract agreements.
- Reporting to the Board: impact, costs, improvement plan with milestones.
Scenarios you want to unsubscribe
Phishing (stolen login)
- Block account, withdraw tokens, reset password, force MFA.
- Forensic security initiates log files.
- Check mailbox rules and forwarding; Remove suspicious rules.
- Inform involved contacts in case of abuse with tips.
Ransomware
- Isolate Segment, block C2 traffic, roll out IoCs in EDR/SIEM.
- Forensic security; decide on reinstallation versus recovery.
- Restore from immutable backups; tackle root cause (patch/hardening).
BEC (Payment fraud)
- If possible, immediately freeze transaction via bank; Enable fraud unit.
- Enhance verification process: four-eye principle, out-of-band verification or implement new policy rules.
- Repeat awareness, share spear-phishing indicators.
Vulnerability Exploit
- Isolate vulnerable systems; apply emergency patches/hardening.
- Rotate Credentials and API keys; Review access lists.
- Schedule a Pentest or Security Audit; improve patch management.
Communication during a cyber incident: quiet, factual, targeted
Communication determines how stakeholders experience the incident. Work with pre-defined templates for internal updates and external statements.
Internal
- Short status updates via one channel (e.g. Teams/Slack incident channel).
- Clear instructions: what do/do not do, who answers questions.
- Management availability for bottlenecks.
External
- Customer and partner message: Actually, without speculation, with follow-up.
- Website/Statuspage update with wide impact.
- Media response via spokesperson; Prepare Q&A.
Reporting obligations, contracts and chain agreements
Depending on the nature of the incident, legal obligations may apply (e.g. in the case of a data breach with data subjects or a competent authority such as the Personal Data Authority). In contracts with suppliers, record:
- Reporting periods and content: what information they deliver within what time.
- Review rights: access to relevant audits/reports.
- Exit and recovery arrangements: Data ownership, portability, RTO/RPO.
It prevents discussion in crisis time and accelerates decision-making.
Practice and measure: tabletop, KPIs and continuous improvement
Practice (for example 1× per year)
- Tabletop exercise: Going through scenario with crisis team, simulating decisions.
- Technical drills: Restore tests, failover, key rotations.
- Communication simulation: Test templates and approval flows.
KPIs & metrics
- MTTD: Mean Time To Detect.
- MTTR: Mean Time To Recover.
- Patch timeout: time from release to implementation.
- Awareness score: results phishing simulations and training participation.
Use evaluations to tighten up your incident response plan and prevention measures.
Toolingstack for SMEs: practical and feasible
- EDR/XDR: Endpoint protection with behavioral detection.
- SIEM/SOAR: central logs + automated actions.
- Immutability backup: separate management, regular repair tests.
- Email security: filtering, sandboxing, DMARC reporting.
- Asset and vulnerability management: overview and periodic scans.
- Access management: MFA, SSO, last privilege, JIT admin.
Start small and scale up. It is a matter of discipline and consistencyNot the most expensive tools.
Checklist ready for a cyber incident .
- Asset and data inventory complete and up-to-date.
- MFA, patching, segmentation and email security set up.
- Back-ups 3-2-1 + immutable; restore Recently successfully tested.
- EDR/XDR active; log/retention centrally and controlled.
- IRP with reels, contact list and playbooks available.
- Communication templates and Q&A2s prepared (internal/external).
- Supplier contracts with security requirements and exit agreements.
- Annual tabletop + reporting to board.
Frequently asked questions about cyber incidents
How do I know an alert is a real incident?
Look at context: suspicious logins, mailbox line changes, traffic spikes, endpoint blocks. Use a triage checklist and quickly classify P1O-P4.
Do I have to pay ransom at ransomware?
Paying does not guarantee recovery and can affect laws and regulations. Focus on containment and recovery from clean backups; decide legally and administratively with all the facts on the table.
What if my supplier is causing it?
Follow your own IRP. Activate contractual agreements, request forensic information and recovery plan. Make sure critical accounts remain the property of your organisation.
How often do I have to update my IRP?
After every exercise and every incident. Minimum annual reviews, as well as contact lists, playbooks and templates.
Summary: make incidents manageable events
Preventing a cyber incident is extremely difficult, but it doesn't have to be to limit the damage. By investing in prevention (prevent cyberattack), detection (detecting cyber attack) and a trained incident response plan (making conscious choices in crisis time) you turn serious business risk into a manageable event. Start with the base, lay down responsibilities and practice. That's directing.
Start with baseline assessment


