How to Respond to a Cyber Attack: A Simple Incident Response Plan for UK SMEs (with Cyber Essentials & DCC)
26 August 2026

Meta description: Learn how to respond to a cyber attack with a simple UK SME incident response plan, including Cyber Essentials, DCC and virtual CISO support.
A cyber attack can make even an experienced business owner feel powerless.
Your systems may be unavailable. Your team may be unsure what to do. Customers, suppliers and regulators may need answers.
The first response matters. Acting quickly can limit disruption, protect evidence and reduce the chance of the attack spreading.
This guide explains the basics of incident response for UK small businesses. It also shows how Cyber Essentials certification, Defence Cyber Certification (DCC) and a virtual CISO can strengthen your preparation.
If you are experiencing a live attack now: isolate affected devices if it is safe to do so, contact your IT or security provider, call your insurer and consider contacting the NCSC incident line on 0300 123 2040.
What counts as a cyber incident for a small business?
A cyber incident is any event that threatens the availability, confidentiality or integrity of your systems or data.
That could include:
- A ransomware infection.
- A compromised Microsoft 365 or Google Workspace account.
- A phishing email that leads to stolen credentials.
- A fraudulent invoice or change to supplier bank details.
- A lost or stolen laptop containing business data.
- Unauthorised access to customer or employee information.
- A website outage caused by a denial-of-service attack.
- Malware found on a company device.
- A supplier or cloud service being compromised.
Not every incident becomes a major breach. However, every suspicious event should be reported and assessed promptly.
A simple rule works well:
If something looks unusual, report it. Do not wait until you have proof.
The first five things to do when you spot a breach
1. Stop the attack from spreading
Your immediate priority is containment.
Depending on the situation, this may mean:
- Disconnecting an affected laptop from Wi-Fi or the network.
- Removing an infected device from shared drives.
- Disabling a compromised user account.
- Revoking active sessions or access tokens.
- Temporarily disabling remote access.
- Blocking a malicious email address, domain or IP address.
- Asking your IT provider to isolate affected systems.
Do not start deleting files or wiping devices unless your technical adviser tells you to. You may destroy evidence that helps identify what happened.
2. Contain the damage
Work out what is affected and what is not.
Ask:
- Which devices, accounts or systems show signs of compromise?
- Is the attacker still active?
- Could the incident have spread to cloud services or suppliers?
- Is business-critical data unavailable?
- Could personal, financial or commercially sensitive data be involved?
If an account has been compromised, reset its password from a known clean device. Check for unauthorised mailbox rules, new forwarding addresses, unfamiliar administrator accounts and changes to payment details.
3. Preserve evidence
Evidence helps your technical team understand the attack. It may also be important for insurance, legal action, regulatory reporting or customer communications.
Record:
- The date and time the incident was discovered.
- Who discovered it and what they saw.
- Suspicious emails, messages or phone numbers.
- Screenshots of error messages or ransom notes.
- Affected usernames, devices and systems.
- Actions taken and when they were taken.
- Relevant logs, alerts and security notifications.
- Any financial loss or attempted fraud.
Keep an incident log in a secure location. Use a separate communication channel if your email or collaboration tools may be compromised.
4. Communicate carefully
Nominate one person to coordinate the response. This may be the business owner, IT lead, security adviser or virtual CISO.
That person should manage:
- Internal updates for staff.
- Communications with customers and suppliers.
- Contact with your insurer.
- Legal and regulatory decisions.
- Technical providers and incident response specialists.
- Updates to senior leadership or the board.
Avoid speculation. Share confirmed facts, explain what is being done and make clear when the next update will be provided.
5. Get expert help
Cyber incidents are difficult to manage while running a business. External help can reduce delays and prevent well-intentioned mistakes.
Contact:
- Your managed service provider or IT support company.
- Your cyber insurer, using the incident number in your policy.
- A cyber incident response specialist.
- Your legal adviser, particularly if personal data may be involved.
- The NCSC for serious or significant attacks.
- Report Fraud if criminal activity or financial fraud is suspected.
If personal data is involved, review the ICO’s guidance on reporting a personal data breach. You must assess the risk to people’s rights and freedoms. Where the risk is likely, the ICO says you should notify it as soon as possible and, where feasible, within 72 hours.
A simple incident response checklist
Every UK SME should keep a short, accessible incident response plan. It does not need to be a large technical document.
Prepare
- Name an incident coordinator and deputy.
- Create an up-to-date emergency contact list.
- Record your IT provider, insurer and legal contacts.
- List critical systems, suppliers and cloud services.
- Define who can approve major decisions.
- Confirm where the incident log will be stored.
- Add contact details for the NCSC and ICO.
- Check your backup and recovery arrangements.
- Prepare an alternative communication method.
Identify
- Record what happened and when.
- Identify the affected accounts, devices or services.
- Decide whether the incident is low, medium, high or critical.
- Assess the impact on business operations.
- Check whether personal or sensitive data is involved.
- Look for signs that the incident has spread.
Contain
- Isolate affected devices or systems.
- Disable compromised accounts.
- Reset passwords and enforce multi-factor authentication.
- Block malicious domains, senders or connections.
- Pause suspicious payment requests.
- Ask suppliers to check connected systems.
- Preserve evidence before making major changes.
Recover
- Remove malware or unauthorised access.
- Fix the vulnerability that allowed the attack.
- Restore systems from known-good backups.
- Test systems before reconnecting them.
- Monitor accounts and systems for further activity.
- Confirm that normal business processes are working.
Learn
- Hold a post-incident review.
- Record what went well and what did not.
- Update the incident response plan.
- Improve technical controls and staff training.
- Run a tabletop exercise using the updated plan.
The NCSC’s incident response process guidance provides a useful framework for preparing, identifying, containing, remediating and recovering from incidents.
How Cyber Essentials strengthens your baseline
Cyber Essentials is a UK government-backed certification scheme designed to protect organisations against common online threats.
It focuses on five key technical areas:
- Firewalls.
- Secure configuration.
- Security update management.
- User access control.
- Malware protection.

These controls do not guarantee that your business will never suffer an attack. They reduce common weaknesses and make it harder for attackers to gain access or move through your environment.
Cyber Essentials also supports incident response by giving you a clearer view of:
- Which systems are in scope.
- Who has access to business data.
- Which devices require updates.
- How your network is protected.
- Where malware protection is deployed.
Cyber Essentials Plus adds independent technical testing. It provides greater assurance that your controls work in practice, rather than only being documented or described in a self-assessment.
You can use our Cyber Essentials service to review your readiness, address gaps and prepare for certification in plain English. Our Cyber Essentials Readiness Check is also designed to help businesses understand what needs attention before they apply.
Where DCC fits for defence suppliers
If your business supplies the Ministry of Defence or a defence prime contractor, you may need to meet Defence Cyber Certification (DCC) requirements.
DCC provides assurance that defence suppliers have appropriate cybersecurity controls for their risk profile. Depending on your contract and the information you handle, you may need to demonstrate more than basic technical protection.
Incident response is an important part of that assurance.
A defence supplier should be able to show that its response plan is:
- Based on a risk assessment.
- Maintained and kept up to date.
- Suitable for different incident scenarios.
- Linked to business continuity and disaster recovery.
- Supported by clear roles and responsibilities.
- Tested regularly.
- Able to deal with supplier and supply-chain incidents.
SimpleCyber is accredited to assess and certify organisations to DCC Level 1. Find out more about Defence Cyber Certification with SimpleCyber, including readiness reviews, evidence preparation and annual check-ins.
When a virtual CISO can help
Many growing businesses need security leadership before they need a full-time CISO.
A virtual CISO, or vCISO, provides experienced cybersecurity leadership on a part-time or project basis. This gives you access to strategic expertise without the cost and commitment of a permanent executive hire.
A vCISO can help you:
- Create and maintain your incident response plan.
- Build practical playbooks for ransomware, phishing and data breaches.
- Assign clear responsibilities across your team.
- Coordinate your IT provider, insurer and legal advisers.
- Prepare for Cyber Essentials or Cyber Essentials Plus.
- Align your processes with DCC expectations.
- Run tabletop exercises.
- Report cyber risk to directors in clear business language.
- Track remediation work and outstanding vulnerabilities.

This is particularly useful when cybersecurity is currently shared between the founder, an office manager and an outsourced IT provider. A vCISO provides ownership, structure and continuity.
Learn more about SimpleCyber’s virtual CISO services.
Your next steps as a business owner
Do not wait for an attack to decide what happens next.
This week, aim to:
- Name your incident coordinator and deputy.
- Create a one-page emergency contact sheet.
- Check that backups can actually be restored.
- Review administrator accounts and multi-factor authentication.
- Start a Cyber Essentials checklist.
- Confirm whether DCC applies to your contracts.
- Write simple playbooks for your three most likely incidents.
- Schedule an annual tabletop exercise.
- Decide whether a virtual CISO would provide useful support.
Good incident response is not about having every answer immediately. It is about knowing who takes charge, what to do first and when to bring in help.
If you need support with Cyber Essentials certification, DCC readiness, incident response or virtual CISO services, contact SimpleCyber for a straightforward conversation about your business.
