I Need IT Support Now
Shane

Does a Small Business Really Need an Incident Response Plan? (2026 Guide)

Forget The Scary Number. You Still Need The Plan. – Incident Response For Small Businesses: What Is Real And What Works

Business Continuity Guide
The Scariest Cybersecurity Stat You Have Heard Is Fake. You Still Need an Incident Response Plan.

Why the "60% of small businesses close" line is made up, and what Houston companies should build instead.

TL;DR
An incident response plan for a small business is not a 40-page binder. It is a one-page list of who to call, what to shut off, and where the backups are. IBM found a tested plan saves $2.66 million per breach.

Every pitch for an incident response plan for a small business opens with the same number: 60% of small businesses close within 6 months of a cyberattack. That number has no source. The organization credited with it disowned it.

The National Cybersecurity Alliance, named as the origin in a thousand vendor decks, published a statement calling it an unverified third-party statistic from 2011, saying the number did not come from its research, that it could not verify the original source, and that it had removed every reference from its own site and does not recommend using it. Nextgov ran an exhaustive search for the underlying study in 2017 and reported the figure had no basis in fact, tracing it back to a 2011 trade blog post that cited nothing at all.

Infographic: what a small business incident response plan should contain, the six questions it must answer, and the cost of not having a tested plan
The One-Page Incident Response Plan Open Full Size

By then it had already traveled a long way. The same reporting found the number cited in a House bill approved by the Science Committee, in a companion Senate bill, in Federal Trade Commission testimony before the House Small Business Committee, and by the director of the NIST Information Technology Laboratory. A statistic with no study behind it helped shape federal small business cybersecurity policy. It stays in circulation because it works on a nervous owner, and in 30 years doing this I have watched it sell more security products than any real finding ever has.

So here is the honest version. Most Houston businesses that get hit do not close. They lose weeks, they pay for it, and they carry the mess for a year. CinchOps builds and tests incident response plans for small businesses across Houston and Katy, with a help desk that answers in under 15 minutes and a flat monthly rate per endpoint. The case for a plan does not need a fake statistic. The real numbers are bad enough.

The short version: a plan is not paperwork. It is the difference between a coordinated 2-hour response and a panicked 3-day guessing game. Business continuity planning is where it lives.
One caveat: this guide is a general reference, not legal advice. Breach notification duties vary by what data was exposed, so loop in your legal counsel and your insurance carrier early when an incident is live.

Does a Small Business Actually Close After a Cyberattack?

The famous number is fiction. What replaces it is less dramatic and more useful.

Most small businesses do not shut down after a cyberattack. They absorb weeks of downtime, unplanned cost, and customer damage, which is a slower and more common form of harm than closure.

Verizon's Data Breach Investigations Report has consistently found that small and mid-sized organizations carry the bulk of ransomware activity, with SMBs making up the overwhelming majority of victims, median ransom demands under $140,000, and fewer than a third of victims paying at all. Recovery, not the ransom, is where the money goes. Industry recovery estimates put average ransomware downtime around 3 weeks. For a 25-person Houston firm billing through its systems, 3 weeks is not an inconvenience. It is a quarter.

The honest argument for a plan is about that recovery window, not about an invented extinction rate. IBM's 2025 Cost of a Data Breach report puts hard numbers on it: organizations with a tested incident response plan saved an average of $2.66 million per breach, and the global average time to identify and contain a breach fell to 241 days, a 9-year low, precisely because response has gotten more organized.

MYTH VS FACTWhat Small Businesses Are Told vs What Is True WHAT YOU ARE TOLD WHAT IS ACTUALLY TRUE "60% of small businesses closewithin 6 months of an attack."Repeated in vendor decks everywhere No verifiable source. The National CybersecurityAlliance disowned it and pulled it from its site. "A plan means a 40-page bindernobody will ever read."The reason most SMBs never start One page covers it: who to call, what to shut off,where backups live, and who talks to customers. "We are too small to be worthplanning for." A tested plan saved $2.66M per breach on average.IBM, Cost of a Data Breach 2025 CinchOps · cinchops.com

What Is Incident Response in Cybersecurity?

The formal definition, then what each phase actually means for a company with no security team.

Incident response in cybersecurity is the organized process a business follows to detect, contain, remove, and recover from a security incident, along with the roles and decisions agreed on in advance. NIST defines it in 4 phases; most businesses experience it as 6 steps.

The framework everyone cites comes from NIST Special Publication 800-61, and it was written for organizations with a security operations center. That is not a Houston accounting firm with 30 people and 1 IT contact. The phases still apply, but the translation matters more than the vocabulary. Here is each one alongside what it actually means when there is no security team in the building.

PhaseWhat the framework saysWhat it means for a 30-person Houston business
PreparationEstablish policy, tooling, and a trained response teamOne page listing who decides, who calls the bank, who calls the lawyer, and where the backups are. Practiced once a year.
IdentificationDetect and analyze events to confirm an incidentSomeone notices and reports it fast. This is a culture problem, not a tooling problem.
ContainmentLimit blast radius, short-term and long-termLock the account, revoke sessions, unplug the machine, freeze pending payments.
EradicationRemove the threat and its persistenceDelete attacker inbox rules and app grants, rebuild the infected machine rather than cleaning it.
RecoveryRestore systems and monitor for reinfectionRestore from a backup you have actually tested, and watch that account closely for 30 days.
Lessons learnedPost-incident review feeds back into preparationA 30-minute meeting that changes 1 thing. Most businesses skip this and repeat the incident.

Notice how much of the right column is decisions rather than technology. That is the part a plan buys you. When an incident lands, nobody is confused about who has authority to take a server offline or whether to call the insurer before or after the forensics firm, because those arguments happened on a calm Tuesday instead of at 2 a.m.

Doesn't Our IT Provider or Our Backup Already Handle This?

Partly. The parts they cannot handle are the ones that cost the most.

An IT provider handles the technical response. It cannot make the business decisions in an incident, which include whether to pay, when to notify customers, what to tell staff, and which legal obligations apply.

I run a managed IT company, so take this as an argument against my own convenience: your provider does not own your incident. CinchOps can lock accounts, pull a machine off the network, hunt persistence, and restore systems, and we do exactly that. But nobody at an MSP can decide whether your firm notifies a client whose data may have moved, or approve a ransom conversation, or speak for your business to a reporter. Those are owner decisions, and an incident is a terrible time to discover nobody knows who makes them.

The backup assumption fails differently. Backups solve data loss. They do nothing about the other 3 problems in a modern attack: stolen credentials that still work after restore, data already copied out for extortion, and the notification clock that starts whether or not you got your files back. Ransomware crews figured this out years ago, which is why stealing data before encrypting it became standard.

  • Your provider owns: detection, containment, eradication, restoration, and the technical evidence trail.
  • You own: notification calls, customer and staff communication, insurance claims, legal exposure, and paying or not paying.
  • You share: the decision to take systems offline, because it is a technical action with a business cost.
  • Nobody owns by default: whichever of these is missing from your plan. That is the gap that turns a 2-hour incident into a 3-day one.

Worth checking on the CinchOps side of that line too: geo-redundant backups held outside the Gulf Coast flood zone exist because a Houston business needs its recovery copy to survive both encryption and a hurricane. Those are the same requirement here.

What Goes on a One-Page Incident Response Plan?

The version that actually gets used when everyone is upset.

A usable small business incident response plan fits on 1 page and answers 6 questions: who decides, who to call, what to disconnect, where backups live, who talks to customers, and what gets written down.

Long plans fail for a boring reason: nobody can find anything in them at 2 a.m. The plans that work are short enough to print, tape inside a supply cabinet, and hand to whoever is in the building. Everything below fits.

  • Who decides. Name 1 person and 1 backup, with authority to take systems offline and to spend money. Titles, not just names, so it survives turnover.
  • Who gets called, in order. IT provider, cyber insurance carrier, attorney, bank fraud line. Real phone numbers, printed, because your email may be the thing that is compromised.
  • What gets disconnected. Name the systems and how to isolate them. "Unplug the cable, do not power it off" belongs here, in those words.
  • Where the backups are and when they were last tested. An untested backup is a rumor. Write the date of the last successful restore test on the page.
  • Who talks to customers and staff. One voice, with a holding statement already drafted. Silence and 6 conflicting versions do equal damage.
  • What gets logged. Times, actions, and who did them, in a plain document. Your insurer and any regulator will want it, and memory will not survive the week.

Then test it once a year. A tabletop exercise takes 90 minutes: read a scenario aloud, have each person say what they would do, and write down every place the plan was wrong. The first run of these is always ugly. That is the point, and it is also why IBM's savings figure applies specifically to plans that have been tested rather than plans that merely exist.

THE ONE-PAGE PLAN6 Questions Your Plan Must Answer 1Who decides?One name, one backup, withauthority to act and spend. 2Who to call?IT, insurer, attorney, bank.Printed. Email may be down. 3What to unplug?Named systems, and how.Disconnect, do not power off. 4Where are backups?Location plus the date of thelast successful restore test. 5Who speaks?One voice to customers andstaff, statement pre-drafted. 6What gets logged?Times, actions, and who didthem. Insurers will ask. Then test it once a year. An untested plan is a document, not a plan. CinchOps · cinchops.com
Nobody needs a scary statistic to justify writing down 6 phone numbers. The businesses that recover well are not the ones with the thickest binder, they are the ones where everybody already knew their job before anything broke.
Shane Stevens, CEO, CinchOps - LinkedIn

Build the Plan Before You Need to Read It

CinchOps writes the one-page plan with you, runs the tabletop test, and is the number at the top of the call list. It is part of business continuity and disaster recovery for Houston small businesses.

Explore Business Continuity and Disaster Recovery →

How CinchOps Can Help You Build an Incident Response Plan

CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area. CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10 to 200 employees.

  • Through business continuity and disaster recovery, CinchOps writes the one-page plan, keeps backups geo-redundant outside the Gulf Coast flood zone, and tests restores so the recovery step is real.
  • Through managed cybersecurity, CinchOps takes the containment and eradication work when an incident lands, with a help desk that answers in under 15 minutes.
  • Through managed IT support, plan maintenance and annual tabletop exercises are included at a flat monthly rate per endpoint, with no contracts, no hidden fees, and no cancellation penalties.
  • CinchOps supports businesses across Houston, Katy, and Sugar Land, including law firms, CPA firms, and manufacturers, where downtime and client data carry the heaviest consequences.

If your plan today is "we would call our IT guy," that is a starting point, not a plan. It takes an afternoon to write down the 6 answers above and 90 minutes a year to find out whether they hold up. That is a small price for the only thing that reliably shortens an incident. When you want a second set of eyes on it, talk to CinchOps.

100% Free

Know Your Business Security Score

Get a FREE comprehensive security assessment for your Houston area business. Understand vulnerabilities across your network, applications, DNS, and more.

Get Your Free Assessment

Frequently Asked Questions

What is incident response in cybersecurity?

Incident response is the organized process a business uses to detect, contain, remove, and recover from a security incident, plus the roles and decisions agreed on beforehand. NIST SP 800-61 defines the phases. For a small business it means knowing who decides, who to call, and what to disconnect before anything happens.

Does a 20-person business really need an incident response plan?

Yes, though not a long one. A single page covering decision authority, call list, isolation steps, backup location, communication, and logging is enough. IBM's 2025 Cost of a Data Breach report found organizations with a tested plan saved an average of $2.66 million per breach compared with those without one.

Is it true that 60% of small businesses close after a cyberattack?

No. The National Cybersecurity Alliance, usually credited with it, published a statement disowning the figure and removed it from its own materials, and a 2017 Nextgov investigation traced it to an uncited 2011 blog post. Real harm shows up as weeks of downtime and recovery cost rather than mass closure.

What does an incident response plan cost in Houston?

A standalone consulting engagement typically runs into thousands of dollars. CinchOps includes plan development, annual tabletop testing, and incident response in its managed IT service for a flat monthly rate per endpoint, so a 25-person Houston business pays a predictable amount rather than a project fee.

How often should we test our incident response plan?

Once a year at minimum, and again after any major change such as a new office, a new core system, or turnover in the people named on the plan. A 90-minute tabletop exercise where each person talks through their actions surfaces most gaps, and the first run almost always finds several.

Discover More

Sources

Shane Stevens, founder and CEO of CinchOps
About the Author

Shane Stevens

Shane Stevens is the founder and CEO of CinchOps, a managed IT and cybersecurity provider for small and mid-sized businesses across the Greater Houston area, including Katy. He brings more than 35 years of IT experience, including senior roles at Tidal Software, Cisco, ABB, Delinea, Digital.ai, and NinjaOne, to keeping local businesses secure, efficient, and productive.

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

281-269-6506