Could Your Business Survive a Cyber Attack Tomorrow?

200+ Articles published
5 IT topics covered
20+ Years of IT expertise
CE+ Cyber Essentials Plus
Share
In This Article
    Speedster IT
    Worried About Cyber Threats?

    Get a free cyber security review and find out where your business is exposed.

    Explore Cyber Security

    Why Every London Business Needs a Cyber Incident Response Plan

    Cybersecurity Controls Reduce Risk, but They Cannot Eliminate It

    Every business invests in preventative security measures, whether that is firewalls, endpoint protection, multi-factor authentication, monitoring tools or employee awareness training, the kind of layered protection covered by our IT security services. While these controls are essential, no organisation can completely eliminate cyber risk.

    Cyber criminals continually adapt their techniques, and even well-protected businesses can experience phishing attacks, compromised accounts, ransomware or supplier-related security incidents. The reality is simple: it is not enough to focus solely on preventing attacks. Businesses must also be prepared to respond when something goes wrong.

    Why the First Few Hours of a Cyber Incident Matter

    When a cyber incident occurs, the first decisions made often have the biggest impact on the outcome. Delays in isolating an affected system, uncertainty around who is responsible for decision-making, or confusion about recovery priorities can allow a relatively contained incident to escalate into a major business disruption.

    A clear response plan provides structure during what is often a high-pressure situation. It helps teams understand who needs to be involved, what actions should be taken first, how incidents should be escalated and how critical business services can be protected while investigations and recovery efforts take place. This is often where a managed security services provider plays a central role.

    A Cyber Incident Is a Business Problem, Not Just an IT Problem

    One of the most common mistakes organisations make is viewing cyber incidents as purely technical events. In reality, a serious cyber attack can affect every area of the business.

    Beyond the immediate impact on systems and data, organisations may need to manage customer communications, engage legal advisors, coordinate with suppliers, satisfy regulatory reporting requirements, involve cyber insurance providers and reassure stakeholders. Without a defined plan, these responsibilities can quickly become difficult to manage, particularly alongside the disaster recovery work often happening at the same time.

    Why Preparation Is Essential

    A cyber attack rarely arrives at a convenient moment. It may begin with a convincing phishing email, a compromised Microsoft 365 account, ransomware infection, or suspicious activity linked to a trusted third-party supplier. In many cases, the biggest challenge is not identifying that an incident has occurred, but knowing how to respond effectively once it has.

    • Who has authority to make decisions?
    • Which systems are most critical to the business?
    • How should the threat be contained?
    • How will staff, customers and suppliers be informed?
    • How can the business continue operating while recovery is underway?

    A documented and regularly tested cyber incident response plan answers those questions before they need to be asked in a crisis. Combined with proactive cybersecurity services and managed detection and response (MDR), it helps London businesses reduce downtime, limit financial and reputational damage, and recover faster when incidents occur.

    Put simply, the businesses that recover most effectively from cyber attacks are usually not the ones that never experience an incident. They are the ones that already know exactly what to do when one happens.

    What Is a Cyber Incident Response Plan?

    The Purpose of an Incident Response Plan

    A cyber incident response plan is a documented process explaining how a business identifies, contains, investigates, recovers from, and learns from a cyber security incident. It sets out who does what, when decisions get escalated, and how the business communicates internally and externally while it happens.

    Which Cyber Incidents Should the Plan Cover?

    A good plan should cover the realistic range of incidents a business might face, not just the most dramatic one, including:

    • Ransomware
    • Phishing
    • Account compromise
    • Data theft
    • Accidental exposure
    • Incidents involving suppliers or cloud services

    How Incident Response Connects With Business Continuity and Disaster Recovery

    Incident response, business continuity and disaster recovery are related but distinct. The National Cyber Security Centre recommends linking all three together, since a well-handled incident still needs a business continuity plan to keep operating and a disaster recovery plan to restore systems afterwards.

    What Could Happen Without a Tested Response Plan?

    Delayed Decisions Can Increase Disruption

    Without a plan, the first hours of an incident are often spent working out who should decide what, rather than acting on a decision that has already been agreed in advance. That delay directly increases how much disruption the business experiences.

    Unclear Responsibilities Create Confusion

    When roles are not defined ahead of time, several people can end up making conflicting decisions, or no one takes ownership at all. Both outcomes slow down the response when speed matters most.

    Poor Documentation Makes Reviews and Reporting Harder

    Businesses often need a clear record of what happened, when it was detected, and what actions were taken, whether for insurers, regulators, or their own internal review. Without documentation captured during the incident, this becomes far harder to reconstruct afterwards.

    Inconsistent Communication Can Damage Trust

    Customers, staff and suppliers tend to notice when communication during an incident is inconsistent or comes too late. A plan that includes agreed communication steps helps avoid this, even under pressure.

    Which Cyber Incidents Should London Businesses Prepare For?

    Ransomware and Malware

    Ransomware remains one of the most disruptive incident types, often affecting multiple systems at once and requiring a clear, pre-agreed decision on containment and recovery priorities. See our article on what is ransomware for more on how these attacks typically unfold.

    Phishing and Business Email Compromise

    Phishing remains one of the most common starting points for a wider incident, particularly where it leads to business email compromise and fraudulent payment requests. Our article on 12 types of social engineering attacks covers the tactics behind these campaigns.

    Microsoft 365 Account Compromise

    A compromised Microsoft 365 account can expose email, files and Teams conversations, and can sometimes be used to reach further into the business. We have covered the most common configuration gaps that make this easier for attackers in our article on Microsoft 365 security mistakes we see in London SMEs.

    Data Theft and Unauthorised Access

    Not every incident involves disruption. Some involve information being accessed or copied without authorisation, which still needs a clear response and, depending on the data involved, may carry regulatory reporting obligations.

    Cloud, Supplier and Supply-Chain Incidents

    An incident does not have to start inside your own systems. A supplier or cloud provider being compromised can still directly affect your business, which is why supplier dependencies are worth including in planning.

    Lost Devices and Accidental Data Exposure

    The National Cyber Security Centre’s own small-business guidance recognises that not every incident is a deliberate attack. Lost devices and accidental exposure of information should be covered by the same plan.

    What Should a Cyber Incident Response Plan Include?

    Named Contacts and Backup Contacts

    The plan should list who needs to be contacted, in what order, with backup contacts named in case the primary person is unavailable.

    Clear Roles, Responsibilities and Decision Authority

    Everyone involved should know their specific role in advance, and it should be clear who has the authority to make key decisions, such as isolating systems or informing customers.

    Incident Classification and Escalation Criteria

    Not every incident needs the same response. Defining severity levels in advance, and the criteria for escalating between them, helps the business react proportionately rather than either overreacting or underreacting.

    Technical Containment and Recovery Procedures

    The plan should set out, at a high level, how systems get contained and in what order recovery happens, based on which services matter most to the business.

    Legal, Regulatory and Insurance Contacts

    Depending on the incident, there may be legal advice to take, regulatory reporting obligations to meet, or a cyber insurance provider to notify, often within a specific timeframe. We have covered why cyber insurance matters alongside a response plan, not instead of one, in why every UK business should have cyber insurance in 2026.

    Internal, Customer and Supplier Communications

    Agreeing communication templates and approval steps in advance means the business is not drafting sensitive messages to customers or the public for the first time in the middle of a crisis.

    Evidence Capture and Incident Documentation

    A clear record of what was detected, when, and what actions were taken supports later review, insurance claims and any regulatory reporting that may be required.

    Incident-Specific Playbooks

    A general plan is useful, but specific playbooks for common scenarios, such as ransomware or a compromised Microsoft 365 account, help the response move faster because fewer decisions need to be made from scratch under pressure.

    The National Cyber Security Centre’s own guidance recommends these same essentials:

    • Contacts
    • Escalation criteria
    • Key decisions
    • A defined incident lifecycle
    • Legal and regulatory considerations
    • Incident-specific playbooks

    Who Should Be Involved in Cyber Incident Response?

    Senior Leadership and the Incident Decision-Maker

    Someone senior needs the authority to make fast decisions during an incident, rather than waiting for wider sign-off each time.

    IT Support and Cybersecurity Teams

    Technical teams, whether in-house, outsourced, or both, lead the containment and technical recovery work.

    Legal, Compliance and Data Protection

    Legal and compliance input matters most where personal data, contracts or regulatory obligations may be affected by the incident.

    Communications, Public Relations and Customer Teams

    Someone needs to manage how the incident is communicated, both internally and to customers, in a way that is accurate without creating unnecessary alarm.

    Human Resources and Internal Operations

    HR may need to be involved where the incident affects staff directly, or where internal policies and disciplinary matters are relevant.

    Cyber Insurers, Suppliers and External Specialists

    The National Cyber Security Centre specifically lists cyber insurers, external response providers, legal advisers and PR support among the contacts a business may need during an incident. Incident response is rarely a job for the IT team alone.

    How Should a Business Respond When an Attack Is Detected?

    Confirm, Record and Triage the Incident

    The first step is confirming what has actually happened, recording the details, and assessing how serious it is likely to be.

    Contain the Threat Without Destroying Evidence

    Containment needs to stop the threat spreading further, while preserving evidence that may be needed for investigation, insurance or regulatory purposes.

    Escalate the Incident to the Right Decision-Makers

    Once triaged, the incident should be escalated according to the plan’s own criteria, so the right people are making decisions at the right severity level.

    Protect Critical Services and Business Data

    Recovery priorities should be agreed in advance, so the most critical systems and data are protected and restored first.

    Communicate Through Approved Channels

    Using pre-agreed communication channels and approved messaging avoids inconsistent or premature information reaching customers, staff or the media.

    Work With Speedster IT

    Want IT support that actually works?

    Talk to us about how your IT is supported today, and what a managed IT partner should be taking off your plate.

    Talk to Our Team

    Recover Systems in the Agreed Priority Order

    Systems should be brought back in the order the business has already agreed matters most, rather than whichever order happens to be technically easiest.

    Review the Incident and Update the Plan

    Once the incident is resolved, a review should capture what worked, what did not, and what needs to change in the plan itself.

    This is intended as a high-level lifecycle, not a technical runbook. Detailed containment actions should come from your own approved plan and a qualified response team, not be improvised during an actual incident.

    Why London Firms Face Particular Incident-Response Pressures

    Complex Supplier and Cloud Dependencies

    Many London businesses rely on several cloud services and suppliers at once, which increases the number of places an incident could originate from, and the number of relationships that may need coordinating during a response.

    High-Value Data and Business Transactions

    Businesses handling high-value transactions or sensitive client data are often a more attractive target, which makes preparation more important, not less.

    Hybrid Working and Microsoft 365 Access

    Hybrid working means Microsoft 365 access happens from more locations and devices than before, which widens the range of ways an account or device compromise could begin.

    Client, Contractual and Regulatory Expectations

    Some clients and contracts now expect evidence of proper incident response planning as a condition of doing business, particularly in regulated or professional services sectors.

    Limited In-House Security Resources in SMEs

    Many SMEs do not have a dedicated internal security team, which is exactly the gap that a documented plan and external support, such as managed detection and response, are designed to help fill.

    Incident Response for Legal, Finance, Hospitality and Professional Services

    Legal Firms and Confidential Client Information

    Law firms hold highly confidential client information, which makes both data theft and the speed of the response particularly important. We have written more on this in why small law firms are vulnerable to cyberattacks.

    Financial Services and Business Email Compromise

    Financial services firms are a common target for business email compromise, given the volume of payment-related communication that typically passes through email.

    Hospitality Businesses and Operational Disruption

    For hospitality businesses, a cyber incident often means direct operational disruption, such as booking systems or payment terminals going down, on top of any data exposure.

    Professional Services and Client Trust

    For professional services firms, how an incident is handled and communicated can matter as much to client trust as the technical severity of the incident itself.

    Insurance Firms and Operational Resilience

    Insurance firms increasingly need to demonstrate operational resilience, including how incidents are detected, escalated and recovered from. We have covered this in more detail in our article on why operational resilience is now the biggest challenge for insurance IT support, which connects incident processes with continuity, system dependencies, and evidence for regulators.

    What Is the Difference Between Incident Response, Business Continuity and Disaster Recovery?

    Incident Response Controls the Immediate Cyber Incident

    Incident response focuses on identifying, containing and managing the attack itself, from detection through to resolution.

    Business Continuity Keeps Essential Operations Running

    Business continuity focuses on keeping the most essential parts of the business running while the incident is being dealt with.

    Disaster Recovery Restores Systems and Services

    Disaster recovery focuses on restoring systems, data and services once the immediate threat has been contained. See our disaster recovery services for more on how this works in practice, and see what your disaster recovery plan should cover post-CrowdStrike for a real-world example of why this matters.

    Why All Three Plans Must Work Together

    The National Cyber Security Centre recommends linking incident response, business continuity and disaster recovery together, rather than treating them as three separate, disconnected documents. In a real incident, a business typically needs all three at once.

    How Often Should a Cyber Incident Response Plan Be Tested?

    Why an Untested Plan May Fail Under Pressure

    A plan that has never been tested can look complete on paper while missing obvious gaps, such as an out-of-date contact or an unclear decision point, that only surface once someone actually tries to follow it.

    How Tabletop Exercises Expose Gaps Safely

    A tabletop exercise is a structured scenario where leadership and technical teams talk through how they would respond to a specific type of incident. It surfaces gaps in the plan without the cost or disruption of a real event.

    When Business or Technology Changes Require a Review

    The plan should be reviewed whenever there is a significant change to staffing, systems, suppliers or business structure, not just on a fixed annual date.

    Turning Lessons Learned Into Plan Improvements

    Every exercise or real incident should feed back into the plan itself. A plan that never changes after being tested is not being tested properly.

    How Often Should an Incident Response Plan Be Tested?

    The National Cyber Security Centre’s own board guidance recommends that boards seek assurance that a plan exists, remains current, and is tested regularly, with at least annual exercising involving relevant stakeholders as a minimum governance action.

    How MDR Strengthens a Cyber Incident Response Plan

    Detecting Threats Outside Normal Business Hours

    Many incidents begin outside normal working hours. Managed detection and response provides continuous monitoring, so threats can be picked up long before someone notices something unusual the next morning.

    Triage and Investigation by Security Analysts

    Rather than relying on internal staff to interpret alerts, MDR analysts triage and investigate suspicious activity as it happens, which speeds up how quickly a genuine incident gets identified.

    Containing Threats Across Identities, Devices and Email

    MDR supports containment across identities, endpoints, email and cloud applications, rather than treating each as a separate, disconnected system to check.

    Producing Clear Incident Timelines and Evidence

    A clear timeline of what happened and when supports the documentation and evidence-capture steps covered earlier in this article, which matter for insurers, regulators and internal review.

    Where the Business Retains Decision-Making Responsibility

    MDR strengthens detection and containment, but decisions such as customer communication, legal notification and business continuity remain the business’s own responsibility, guided by its incident response plan.

    What Is the Difference Between MDR and an Incident Response Plan?

    MDR is a monitoring and containment service that helps detect and respond to threats technically. An incident response plan is the wider business document covering roles, decisions, communications and recovery. The two work well together, but one does not replace the other.

    How Speedster IT Helps London Businesses Prepare and Respond

    Cyber Incident Response Readiness Reviews

    We help London businesses review their existing incident response arrangements, or build a plan where none currently exists, covering the essentials set out earlier in this article.

    Microsoft 365, Identity and Endpoint Monitoring

    Our managed security services cover Microsoft 365, identity and endpoint monitoring, so unusual activity is more likely to be caught before it becomes a full incident.

    MDR and Escalation Support

    Through managed detection and response, we provide ongoing monitoring and escalation support that plugs directly into your own incident response process.

    Backup, Disaster Recovery and Business Continuity Support

    Our disaster recovery services support the recovery side of incident response, restoring systems and data once containment is complete.

    Tabletop Exercises and Response-Plan Reviews

    We can run tabletop exercises with your team to test an existing plan, or help build one from scratch if your business does not currently have a documented response process.

    Can Our IT Support Provider Manage a Cyber Attack?

    An IT support provider can play a central role in technical containment, monitoring and recovery, but a full response usually also needs input from leadership, legal and communications, as covered earlier in this article. We work alongside those other roles rather than replacing them.

    Can Speedster IT Review Our Existing Response Plan?

    Yes. If you already have a response plan in place, we can review it against current good practice and identify any gaps before you need to rely on it. If you do not yet have one, our free IT audit is a practical starting point, and you can get in touch to request an incident response readiness review.

    Do Small Businesses Really Need an Incident Response Plan?

    Yes. Smaller organisations are frequently targeted precisely because they tend to have fewer resources and less formal security processes than larger businesses. A documented plan helps an SME make decisions quickly and recover more effectively when disruption happens, regardless of its size. Our article on UK cyber security growth and what small UK businesses need to know looks at this trend in more detail.

    The UK Government’s annual Cyber Security Breaches Survey has reported that a substantial proportion of UK businesses identify a breach or attack in any given year, though the survey itself notes that unreported or unidentified incidents mean the true figure is likely higher. Preparation matters whether or not an incident has happened to your business yet.

    Does Cyber Essentials Replace an Incident Response Plan?

    No. Cyber Essentials certifies a set of baseline technical controls, but it does not itself provide a documented incident response plan. The two are complementary, not interchangeable, and a business can hold Cyber Essentials certification while still lacking a proper response plan. See Cyber Essentials has changed, what UK businesses need to know for the current certification requirements.

    How Do We Prepare for a Microsoft 365 Account Compromise?

    Preparation includes MFA on every account, Conditional Access where appropriate, monitoring for unusual sign-ins, and a specific playbook for disabling and investigating a compromised account quickly. We cover the underlying configuration issues in more detail in our article on Microsoft 365 security mistakes we see in London SMEs.

    Talk to Speedster IT About Your Incident Response Plan

    Whether you need a plan built from scratch or your existing one reviewed, Speedster IT can help. Call us on 0204 511 9111, email hello@speedster-it.com, or get in touch to request an incident response readiness review.

    Ready to Talk?

    Let’s fix this properly.

    Book a free consultation with one of our engineers and find out what better IT support actually looks like.

    Get In Touch