Incident Response for Small Businesses: What You Can Actually Get
A small business can get real incident response without a security team, and most of what it can get is either already paid for or free. The breach coach and forensics panel inside a cyber insurance policy, a retainer that locks a response firm's rates and response time with no annual fee, the FBI's reporting portal, CISA's incident channel, and outside counsel who hires the investigator so the findings stay privileged: none of those requires a security hire, and every one of them works better if the paperwork exists before the incident. The contrarian part is that the cheapest way to get incident response help is not to find a cheaper firm. It is to have signed the paperwork on a calm day. A thirty-person company that calls a forensics firm cold on the night of a ransomware event is buying the most expensive version of the same service, and what incident response costs works through exactly why.
One thing this article does not do is chase "incident response near me". We deliver remotely and have no local office to claim, and neither does most of the specialist market. What follows is what a small company can get, from whom, in what order, and which obligations scale down with size and which do not.
Key takeaways
- Verizon's 2026 DBIR counts organisations with fewer than 1,000 employees as small businesses and found that, of the ransomware cases where organisation size was known, about 96% of victims were SMBs.
- A company with no security team has five sources of help: the panel in its cyber policy, a retainer with no annual fee, its MSP as hands, free government channels, and outside counsel. Four of the five cost nothing until they are used.
- The FTC's own breach guidance tells a business to consider hiring independent forensic investigators, to consult legal counsel, and not to turn machines off until the forensic experts arrive.
- Some notification duties scale down for small entities and some do not: a HIPAA breach affecting fewer than 500 individuals goes on an annual log, while the FTC Safeguards Rule notification at 500 consumers applies even to institutions exempt from its written plan requirement.
- Your MSP cannot investigate an incident that may have come through its own access. The DBIR records third-party involvement in 55 percent of SMB breaches.
Small is not the same as unnoticed
The Verizon 2026 Data Breach Investigations Report draws the line at headcount: "organizations with fewer than 1,000 employees are considered small businesses." Its SMB section opens with the sentence a small company should take personally: "Small organizations are disproportionally impacted by Ransomware and face many of the same threats as other industries and organizations but often with less resources available." The same section reports that "of the Ransomware cases where we have information on the organization size, we found that about 96% of Ransomware victims were SMBs", and that these attacks are largely opportunistic: victims "had credentials that were compromised (38%) or unpatched vulnerabilities in edge devices (29%)". Across the whole dataset, the report says that in 2025 "48% of all the breaches analyzed had a Ransomware action involved."
The initial access breakdown for SMB breaches in the same section is exploitation of vulnerabilities at 26 percent, credential abuse at 13 percent and phishing at 9 percent, and the "other metrics" row lists third-party involvement at 55 percent and the human element at 45 percent. Two of those figures decide who can investigate your incident, and we come back to them below.
There is one piece of better news in the same report, and it belongs to the payment decision rather than to this article: the share of organisations not willing to pay ransomware actors rose "from 65% in 2024 to 69% in 2025". Should you pay the ransom is the page for that decision; this one is about who helps you make it.
The five things a small company can actually get
| Source of help | What it gives you | What it costs before an incident | The catch |
|---|---|---|---|
| Your cyber policy's panel | A breach coach (specialist counsel) and a pre-vetted forensics firm, routed through the claims hotline | Nothing beyond the premium you already pay | Most policies require the carrier's consent before you incur response costs, and off-panel spend may not be reimbursed |
| A retainer with no annual fee | A signed agreement, a rate card and a response commitment with a firm that already has your contact tree | Nothing, or the paperwork effort | During a mass-exploitation event, paying retainer clients are staffed first |
| Your MSP, as hands | Isolation, snapshots, log exports and rebuilds, executed under direction | Already in the contract | It cannot investigate an incident that may have come through its own access |
| Government channels | Local police, the FBI and Secret Service, the IC3 portal, CISA's reporting channel, and free planning guidance | Nothing | They investigate crime and warn other victims; they do not rebuild your network |
| Outside counsel | The legal analysis of what you owe to whom, and the engagement of the forensics firm so its findings have a claim to privilege | Nothing until engaged | The order matters: counsel engages the investigator, not your IT lead |
Your cyber policy's panel. If you hold a cyber policy, you almost certainly already own the most important piece of incident response a small company can have. The claims hotline is staffed around the clock and routes you to panel breach counsel, who then engages a panel forensics firm. Consent and panel language vary by carrier and by form, so the reading has to be your own policy, not anyone's summary. What to do in the first 24 hours after ransomware owns the hour-by-hour sequencing and puts the insurer call before any vendor call; we do not repeat it here. If you are still filling in the questionnaire that gets you the policy, the cyber insurance questionnaire guide is the page for that.
A retainer with no annual fee. A retainer does not have to be a prepaid block of hours. The form that fits a small company is a signed master agreement, a rate card and a defined response commitment, with no annual fee and no credited hours. What it buys is the removal of the procurement cycle from the worst week of your life: no conflict check, no contract redlines, no deposit while an attacker still holds your domain. Whether a paid tier is worth adding on top, and the rollover clause that decides that question, is worked through in is an incident response retainer worth it, and the rate tiers themselves are in what incident response costs. Ask for the no-fee form before you decide you cannot afford a retainer.
Your MSP, as hands. Most small companies have a managed service provider and no security staff, and the MSP is genuinely useful in an incident: it can isolate machines at the network layer, snapshot cloud volumes, export logs before retention rolls them, and rebuild systems under direction. What it cannot do is be the investigator when its own access is a plausible way in. The DBIR records third-party involvement in 55 percent of SMB breaches, and an MSP whose credentials or remote-management tooling may be the vector cannot objectively scope an intrusion whose findings decide its contract renewal. Keep the MSP in the room as hands. When to call an outside incident response firm owns the five triggers that say the investigator has to be someone else.
Government channels, all free. The FTC's breach response guide for business is direct about the first call: "Call your local police department immediately. Report your situation and the potential risk for identity theft." It adds that "if your local police aren't familiar with investigating information compromises, contact the local office of the FBI or the U.S. Secret Service." For the money side of an incident, the FBI's Internet Crime Complaint Center hosts the reporting portal at ic3.gov, and its 2024 annual report describes a Recovery Asset Team that "streamlines communications with financial institutions and FBI field offices to assist in the freezing of funds for victims of fraudulent domestic and international transactions via the Financial Fraud Kill Chain", most of whose cases are business email compromise. That is the mechanism behind the advice in investigating a business email compromise to report a fraudulent wire within hours rather than days. CISA's cyber guidance for small businesses says that "to request assistance or to share information about an incident that can help protect other potential victims, you can contact CISA at https://www.cisa.gov/report", and the same page carries CISA's incident response plan basics and tabletop exercise tips. NIST's SP 800-61 Revision 3, published April 2025, is the free reference for the response process itself.
Outside counsel. The FTC guide says to "consult with legal counsel", and then: "you may consider hiring outside legal counsel with privacy and data security expertise. They can advise you on federal and state laws that may be implicated by a breach." Counsel does two things a small company cannot do for itself. It works out which notification clocks are running and to whom, and it engages the forensics firm, so that the investigation has a credible claim to privilege. Is a forensic report privileged explains why that sequencing cannot be undone afterwards. If your carrier's hotline routed you to a breach coach, this is already handled; if you have no policy, a single call to a privacy lawyer before any vendor is engaged is the cheapest decision on this page.
Who investigates a breach at a thirty-person company
The honest answer is a forensics firm, engaged by counsel, and often a small one for a short engagement. The FTC's guidance for business puts it plainly: "Identify a data forensics team. Consider hiring independent forensic investigators to help you determine the source and scope of the breach. They will capture forensic images of affected systems, collect and analyze evidence, and outline remediation steps." Two of the guide's other instructions matter more for a company without a security team than for one with it, because nobody in-house has done this before: "Take all affected equipment offline immediately", but not to turn any machines off until the forensic experts arrive, and "Do not destroy evidence."
Not every incident at a small company needs that firm, and that is where the money is saved. The table below is the mapping we use in practice; the five escalation triggers that convert an in-house incident into an outside one are owned by when to call an outside incident response firm, and we do not restate them here.
| Incident | In-house or MSP | Outside investigator | Counsel | Report to |
|---|---|---|---|---|
| Phishing click caught by the mail filter, no credential entered | Handle and document | No | No | Nobody; keep the record |
| Lost laptop, disk encryption verified, remote wipe confirmed | Handle and document | No | Usually no | Depends on state law and the data on it |
| Hijacked mailbox and a fraudulent invoice or wire | Contain the mailbox; the bank and IC3 within hours | Yes, if any payment moved or the mailbox held customer data | Yes | Bank, IC3, and possibly individuals |
| Ransomware on any server | Isolate, do not power off, sever backups from the network | Yes, through the panel or the retainer | Yes, before any vendor | Carrier first, then law enforcement, then whoever the data requires |
| Customer database exposed on the internet | Take it offline, preserve logs | Yes, to establish what was accessed | Yes | Individuals and regulators on the statutory clocks |
The rows where the answer is "handle and document" are most of what a small company experiences, and documenting them is not busywork. CISA's advice to small businesses is to "invoke the IRP even when you suspect a false alarm", because "near misses" are how the plan gets better before it is needed.
The obligations that scale down, and the ones that do not
Size changes some notification duties and leaves others exactly where they are, and a small company should know which is which before the incident.
HIPAA notification to the Secretary scales down. Under 45 CFR 164.408, for breaches of unsecured protected health information "involving less than 500 individuals, a covered entity shall maintain a log or other documentation of such breaches and, not later than 60 days after the end of each calendar year, provide the notification" to the Secretary for breaches discovered during the preceding year. At 500 or more individuals, the notification to the Secretary is made "contemporaneously" with the notice to individuals. The individual notice itself, and the breach risk assessment that decides whether a notice is owed at all, do not shrink with size; HIPAA breach risk assessment covers the second and breach notification deadlines covers the clocks.
The FTC Safeguards Rule exempts the plan, not the notice. For financial institutions under the FTC's Safeguards Rule, 16 CFR 314.4(h) requires a written incident response plan "designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity, or availability of customer information". 16 CFR 314.6 then says that "Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers." The notification duty in 314.4(j) is not on that list: on discovery of a notification event involving the information of at least 500 consumers, the institution "must notify the Federal Trade Commission as soon as possible, and no later than 30 days after discovery of the event", and a notification event "shall be treated as discovered as of the first day on which such event is known to you." A four-thousand-customer firm is excused from writing the plan and not from the thirty-day notice, which is a strange place for a small company to discover the difference.
State law does not scale down at all. The FTC's guide states that "all states, the District of Columbia, Puerto Rico, and the Virgin Islands have enacted legislation requiring notification of security breaches involving personal information." The thresholds and clocks vary by state and by the data involved, which is why counsel owns this analysis rather than the person who found the breach.
What to sign on a calm Tuesday
Everything above works better if it exists before the incident, and none of it takes a security hire.
- Read the policy. Find the notice deadline, the claims hotline and the panel or consent language. If you have a response firm you trust, ask your broker to get it pre-approved now.
- Sign the no-fee retainer paperwork. A master agreement, a rate card and a response commitment. If the firm will not offer that form, ask why.
- Write the plan. CISA's advice to small businesses is that the incident response plan "will include roles and responsibilities for all major activities and an address book for use should the network be down during an incident", and that it should be reviewed quarterly and after every security incident or near miss. How to write an incident response plan is the long version.
- Rehearse it. CISA recommends that the security program manager "host quarterly tabletop exercises", and its example scenario is exactly the small-company case: "one employee discovering their laptop is blocked by ransomware." What is a tabletop exercise covers how to run one without a consultant.
- Turn on MFA, especially for email. CISA calls this "the most important step an organization can make", and the DBIR's credential figures above are the reason. A hijacked mailbox is the small-company incident we see most, and MFA on email is the control that prevents most of them.
- Keep the logs. Investigations at small companies are shortened or lengthened by whether authentication and endpoint logs still exist when the investigator arrives. The hours argument is made in what incident response costs; the retention setting is yours to change today.
Where Top Floor fits
Against our own interest, and consistent with what we say in the first-24-hours guide: if your policy has a panel and we are not on it, use the panel firm, and we will tell you the same thing if you call us first. Where we fit for a small company is the no-fee retainer form, so that our incident response and digital forensics teams already have your contact tree and your paperwork when the call comes, and the peacetime work: the plan, the tabletop, the logging and MFA decisions that decide how long the eventual investigation takes. If nobody at the company owns that checklist, a vCISO engagement is usually the cheapest way to give it an owner.
How to decide this week
Open the cyber policy and find three things: the claims hotline number, the notice deadline, and the sentence about panel firms or carrier consent. Put the hotline number somewhere that survives the network going down.
Then ask one response firm, ours or anyone's, for the no-fee retainer form and read the response commitment it actually contains. If the firm will only sell prepaid hours, that tells you what the retainer is for.
Finally, check whether MFA is enforced on every mailbox, not merely available. That single setting removes the most common small-company incident before any of the machinery above is needed.
Frequently asked questions
Do small companies need a DFIR firm on retainer?
Not necessarily a paid one. A small company with no regulated data, cloud-hosted email with MFA enforced, and backups it has actually restored can usually cover its realistic downside with a retainer that carries no annual fee: a signed agreement, a rate card and a response commitment, with no prepaid hours. What it should not do is have no relationship at all, because a firm engaged cold during an incident starts after conflict checks, contract negotiation and a deposit, while the attacker keeps working. If the company holds health, payment or personal data at scale, or runs on-premises infrastructure, a paid tier starts to make sense, and the retainer article covers how to judge that.
Who investigates a breach at a company with no security team?
A forensics firm engaged by outside counsel, with the company's MSP or IT contractor acting as hands under the investigator's direction. The FTC's breach guidance for business tells companies to consider hiring independent forensic investigators to determine the source and scope of the breach, and to consult legal counsel on the federal and state laws implicated. If the company holds a cyber policy, the carrier's claims hotline typically routes to panel counsel, who engages a panel forensics firm; that path also keeps the response inside the policy's consent requirements. The MSP should not be the investigator when its own access is a plausible way in.
What is the cheapest way to get incident response help?
Sign the paperwork before you need it. A retainer with no annual fee gives a small company locked rates and a response commitment for the cost of the paperwork, and it removes the procurement delay that makes a cold engagement both slower and more expensive. Beyond that, the cheapest help is free: the claims hotline inside an existing cyber policy, local police and the FBI, the IC3 portal for fraudulent transfers, CISA's reporting channel and planning guidance, and NIST SP 800-61 Revision 3 for the process itself. The rate tiers and the arithmetic behind the cold-versus-retained gap are in our incident response cost article.
Do we have to report an incident to the government?
It depends on the data and your sector, and the clocks run from discovery rather than from the end of your investigation. HIPAA covered entities report breaches affecting fewer than 500 individuals to the Secretary on an annual log within 60 days after the end of the calendar year, and larger ones contemporaneously with the individual notices. Financial institutions under the FTC Safeguards Rule must notify the FTC within 30 days of discovering a notification event involving at least 500 consumers, even where the rule exempts them from maintaining a written plan. Every state has a breach notification statute of its own. Reporting to law enforcement is separate from all of that and is advisable in nearly every case; the FTC's guidance is to call local police immediately and escalate to the FBI or Secret Service if they are unfamiliar with information compromises.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.