I recently came across an online discussion asking what someone should do after discovering ransomware actively spreading through a network. The most popular answer was simple: reference the incident response plan.

That is good advice, but it misses an important point. If an active incident is the first time your team seriously reads the plan, it is already too late. You will lose valuable time interpreting instructions, deciding who has authority, and searching for contact information while the situation gets worse.

An incident response plan should guide a practiced response, not introduce it.

Preparation Happens Before the Incident

Cybersecurity is largely proactive work. You establish policies, assign responsibilities, implement controls, and then test whether they work. Tabletop exercises reveal gaps that rarely show up during a document review: an outdated phone number, a missing decision-maker, an inaccessible backup, or a task that everyone assumed belonged to someone else.

Those findings should lead to better procedures and controls. Exceptions should be documented, assigned an owner, and reviewed regularly. The plan itself should be revisited at least annually and whenever the business, technology environment, or threat landscape changes materially.

When a serious incident occurs, the team should already know its first moves. A printed copy of the plan should be available in case normal systems are unavailable, but no one should be opening it for the first time.

IT Support and Cybersecurity Leadership Are Different Roles

Many small and mid-sized businesses have limited visibility into their environment. They may not recognize an attack until operations are disrupted, and even then, they may not know who can make urgent decisions.

Calling the IT provider or MSP is often the right first step. These partners keep systems running, deploy security tools, manage patches, configure MFA, support backups, and handle day-to-day technology needs. Their role is essential.

But operating technology is not the same as leading a cybersecurity program. Some providers offer both capabilities; many do not. Businesses should understand that distinction before an incident—not rely on a service list or marketing language when the pressure is on.

Cybersecurity leadership determines how risk is assessed, which safeguards matter most, how response responsibilities are divided, and whether the controls in place are actually working. That responsibility may sit with an internal security leader or a fractional resource such as a vCISO.

Someone Must Run the Security Program

A mature security program needs clear ownership. Dedicated cybersecurity leadership can maintain the information security management system, evaluate technical, administrative, and physical controls, manage the risk register, review vendors, coordinate testing, and help leadership direct a limited security budget where it will have the most impact.

That security leader advises and coordinates, but cannot own the business risk. Ultimately, risk decisions belong to executive leadership. The CEO, CFO, and other officers need enough visibility to understand what is being accepted, what is being reduced, and what remains unresolved.

This division of responsibility matters during an incident. The MSP may isolate systems and begin technical recovery. Legal counsel may advise on notification obligations. The insurer may direct the use of approved response firms. Executives may need to make operational and financial decisions. A practiced plan connects those parties before the first emergency call.

Could Your Team Act Right Now?

If ransomware appeared on your network today, could your team answer these questions without hesitation?

  • Who has authority to declare an incident and make urgent decisions?
  • Who contacts your IT provider, security team, insurer, legal counsel, and leadership?
  • Where is the offline copy of the incident response plan?
  • How will the team communicate if email and normal systems are unavailable?
  • When were backups last tested, and can they be restored without relying on the affected environment?
  • When was the last tabletop exercise, and were the findings resolved?

If those answers are unclear, the next step is not another security product. It is preparation.

Contact MN Risk & Cybersecurity Advisory to discuss incident response planning, tabletop exercises, and practical security leadership for your business.