Incident response for small teams
The version of this that works is simpler than the version most people imagine. Most advice about incident response assumes a team that does not exist at your size. Here is the version that does not.
The realistic threat for most small businesses is automated and opportunistic, not targeted. Doing this properly once is usually cheaper than doing it approximately three times.
What to keep
Decide who does what before something happens. None of that requires a large budget, only a decision and someone to own it. Doing this properly once is usually cheaper than doing it approximately three times.
What to drop
Process that exists to coordinate ten people is overhead when there are two of you. Where this goes wrong is almost never a lack of knowledge.
How to approach it
Write up what happened while it is fresh. The teams that handle this well are rarely the ones with the biggest budgets. It is worth deciding this deliberately rather than inheriting whatever the last person set up.
In practice
The cheapest security work is the boring kind done on a schedule. Three things worth confirming about incident response before you move on:
- Someone can say what the current setup is without going to look
- Write up what happened while it is fresh — and you know whether that is true here
- There is a way to tell whether the last change to this helped
Pick the one that would hurt most if it failed, and start there.