When a cyber incident hits a large company, a trained team follows a rehearsed plan. When it hits a small business — a fraudulent payment moving through the company account, ransomware locking the billing computer, a hacked email account messaging customers — the first hour is usually improvisation, panic and Google searches. That first hour is precisely when the most damage is prevented or made permanent, which is why the single highest-value security investment for a small business is not a product. It is a one-page checklist everyone knows exists.

The premise is uncomfortable but liberating: assume something will eventually go wrong. Small businesses are targeted heavily and specifically because attackers know defences are thin and processes are informal. Accepting that changes the question from "how do we become unhackable?" — impossible — to "how do we make a bad day survivable?" — very achievable.

What the first hour should look like

Incident response for a small firm compresses into four verbs: contain, preserve, notify, recover. Containment comes first and beats investigation: disconnect the affected computer from the network, freeze the compromised account, call the bank’s fraud line to block the payment channel. Speed matters most with money — fraudulent transfers can sometimes be stopped or recalled if the bank is alerted within hours, and almost never after days.

  • Contain: isolate affected devices and accounts immediately — pull the network cable, sign out all sessions, change the password, suspend the account.
  • Preserve: do not wipe or reinstall anything yet; photograph screens, save suspicious emails, note times. Evidence answers the questions that come later.
  • Notify: bank fraud line first for financial incidents, then the national cybercrime helpline 1930 and cybercrime.gov.in, then affected customers if their data or your email account was involved.
  • Recover: restore from backups onto clean systems, reset credentials everywhere, and re-enable services one at a time rather than all at once.

The checklist itself: one page, printed

The document that makes this work fits on a single page, and it must be printed — an incident that locks your computers also locks the checklist stored on them. It contains: the four steps above in plain language; phone numbers for the bank’s fraud line, the IT support person or vendor, the insurer if there is cyber cover, and the cybercrime helpline; the location and password procedure for backups; and the name of the one person who makes decisions during an incident, with a deputy.

That last line matters more than it looks. In small firms without a designated decision-maker, incidents stall while everyone waits for the owner to come out of a meeting, or worsen while two people take contradictory actions. One name, one deputy, written down, ends that.

The preparation that makes the checklist work

A checklist assumes a few things exist. Backups top the list: automatic, tested by actually restoring a file quarterly, with at least one copy offline or in a separate cloud account that ransomware on the office network cannot reach. Two-factor authentication on email and banking is second — most small-business incidents begin with a compromised email account, and two-factor blocks the majority of those. A basic list of what you have — computers, accounts, software, who has admin rights — is third, because you cannot secure or restore what you have not written down.

Then rehearse once. Not a drill with sirens — a thirty-minute conversation over tea: the billing computer shows a ransom note, what do we do? Walking through it once surfaces the gaps — nobody knows the backup password; the bank contact is a branch number that closed — while they are free to fix.

Why this is worth an afternoon

The businesses that recover quickly from incidents are not the ones that spent the most on security software. They are the ones where containment started in minutes, the bank was on the phone within the hour, and backups actually restored. All of that is decided before the incident, by preparation that costs one afternoon and a laminated sheet by the till. Against the realistic alternative — days of downtime, unrecoverable money, customers finding out badly — it is the cheapest insurance a small business will ever buy.

The five-minute version to start today

If the full preparation feels like a project, begin with the five-minute version this week. Write four phone numbers on a card: your bank’s fraud helpline, the cybercrime helpline 1930, your IT person or vendor, and the colleague who decides when you are unreachable. Tape it inside a drawer. Turn on two-factor authentication for the business email and bank account tonight — it takes ten minutes and blocks the majority of real-world attacks on small firms. Check that one backup of your critical files exists somewhere that is not the office computer, and open it to confirm it actually restores. That is the whole starter kit: a card, two settings, one verified backup. It is not comprehensive security, and it does not need to be — it is the difference between a business that loses a morning to an incident and one that loses a season. The full checklist can follow next month; the card should exist by Friday.