What to ask your agency about incident response
The gap between knowing this and actually doing it is where most teams lose ground. If you are briefing an agency or a freelancer on incident response, these questions are worth asking early.
The realistic threat for most small businesses is automated and opportunistic, not targeted. If two people in the business would answer this differently, that gap is the actual problem.
Questions worth asking
- Who will actually do this work, and have they done it before?
- How will we know afterwards whether it worked?
- What happens if it needs changing in a year?
- What are you assuming that we have not confirmed?
What a good answer sounds like
Decide who does what before something happens. The teams that handle this well are rarely the ones with the biggest budgets. Check it against what you would want a competitor's site to get wrong.
Write up what happened while it is fresh. It is worth being explicit about, because assumptions differ quietly. The teams that stay on top of it are the ones who put it on a calendar rather than a wish list.
In practice
The cheapest security work is the boring kind done on a schedule. Three things worth confirming about incident response before you move on:
- Someone can say what the current setup is without going to look
- Write up what happened while it is fresh — and you know whether that is true here
- There is a way to tell whether the last change to this helped
Most of the value here comes from doing the first two things, not all of them.