forumNew topic

Should I set up an incident response team or is a phone list enough?

AAv. Kemal U***Expert
Job title
Lawyer · IT
Organization type
300-person organization
Joined
Sep 2023
Message
168
#1

We are a five-person architectural design and project consultancy firm based in Milan. We store sensitive commercial floor plans and tender documents for our clients on our cloud servers. Last week, an employee clicked on a phishing link in an email, triggering a brief ransomware scare; thankfully, our automated backups saved us from losing any data.

But that day made us realize that if the systems had completely locked up, nobody knew who was supposed to pull the plug on the server, notify the police or data protection authority, or call our IT support contractor. Everyone in the office just stared at each other, and we spent half an hour panicking on the phone.

Our budget is tight, so hiring a full-time security specialist is out of the question. Is building a formal incident response team realistic for a five-person company, or is an emergency phone list pinned to a bulletin board good enough? What should the baseline setup look like for a small business?

FFatih K***Expert
Job title
Data entry clerk
Sector
Agriculture
Organization type
medium-sized business
Joined
Jun 2022
Message
228

Doki · Penetration test · 2025

Most Helpful#2

Short answer: Relying solely on a phone list guarantees decision paralysis during a crisis, but assigning big enterprise-style titles in a five-person team is just as useless. What you actually need is a lean, three-pillar response framework that clarifies internal responsibilities and external escalation protocols ahead of time.

In small teams, the problem isn't a lack of technical knowledge; it's knowing who has the authority to make the final call in the heat of the moment. You can boil it down to three core roles: 1) Crisis Coordinator (typically the founder or office manager): The sole person authorized to notify clients and, if necessary, approve a complete system shutdown. 2) Communications and Process Lead: The person who interfaces with the external IT provider, legal counsel, and insurance firm, while keeping a detailed, timestamped log of events. 3) Operational Support: The person who secures offline backups and coordinates internal communication with office staff.

To make this setup work, you need an emergency response SLA with an external IT support provider. Add a clause guaranteeing remote response within two hours max to an external support contract, which usually costs around 1,500 to 2,500 EUR per year. A phone list is just a directory; it's useless unless you have a one-page flowchart mapping out who takes what action in each scenario, backed by a 15-minute tabletop drill twice a year.

İİbrahim A***ExpertCommunity member
Joined
May 2024
Message
1
#3

Tacking a phone list to the wall isn't enough but don't write a fifty-page manual either. Print a single laminated sheet: 1) Unplug the network cable, do not shut down the computer (so you don't destroy evidence). 2) Notify Ahmet. 3) Call the external IT specialist. 4) Never enter credentials on any suspicious prompt. In a five-person office, the only thing that saves you is your reaction in the first five minutes.

KKemal T***MemberCommunity member
Joined
Feb 2023
Message
4
#4

We went through a similar incident last year at our logistics company of seven people. We had no procedures in place, and the external incident response specialist we brought in billed us 180 EUR an hour, totaling 2,200 EUR. If we had signed a retainer agreement from the start at 120 EUR a month, our systems would have been down for just an hour instead of six, and our costs would have been cut in half.

PPolat K***MemberCommunity member
Joined
May 2025
Message
27
#5

Employees pulling the plug and shutting down devices during an attack is the biggest mistake you can make from a digital forensics perspective. When a machine powers off, attacker traces and encryption keys stored in volatile memory (RAM) are lost. When defining roles within your team, train your technical staff to sever network connectivity (turning off Wi-Fi, unplugging the Ethernet cable) while strictly enforcing the rule to leave the machine running.

OOsman A***ExpertCommunity member
Joined
Aug 2025
Message
316
#6

Trying to set up a committee in a five-person office sounds ridiculous to me. Everyone already sits right next to each other anyway. Let's be realistic: no one on the inside is going to magically turn into a security expert. What actually matters is knowing who to call on the outside and regularly testing that your backups are truly kept in an isolated environment. Formal team titles are just a waste of paper.

RRıdvan Ç***Member
Job title
Marketing director
Sector
Media and publishing
Organization type
cooperative
Joined
May 2023
Message
200

Doki · Log management setup · 2024

#7

This happened to us at our three-partner agency in Turin. One morning, a ransom note popped up on the accounting computer. Nobody dared to call the boss, and the intern installed some cleanup tool they found on Google which wiped all the logs. In the end, because we notified the Italian data protection authority (Garante) late, we faced the risk of thousands of euros in administrative fines. All because the chain of authority was never made clear.

KKübra Ö***Member
Job title
Front office accounting
Sector
Real estate
Organization type
two-branch business
Joined
Jul 2024
Message
155
#8

there are three of us we set up a shared whatsapp group if anything happens we just text there and the tech lead from our outsourced it firm is in the group too. tbh handled two suspicious emails instantly so far no need to go digging through call lists or whatever.

HHavva M***Expert
Job title
Front office accounting
Sector
Media and publishing
Organization type
chain store
Joined
Sep 2022
Message
197
#9

What do your client contracts stipulate in the event of a potential data breach? Under Italian law, you have a 72-hour notification window. Legally, who in your company holds the authority to make the official announcement to clients and regulatory authorities within those 72 hours? When assembling a response team, have you established this signing authority beyond just the technical roles?

FFatih K***MemberCommunity member
Joined
Jun 2025
Message
61
#10

To sum up the discussion, the formula for a five-person company is straightforward: designate a single internal decision-maker, train staff to leave devices powered on and merely cut the internet connection, and retain an external IT provider with guaranteed response times. You need neither a bureaucratic committee nor a passive phone list.

KKader U***Member
Job title
Store associate
Sector
Media and publishing
Organization type
family business
Joined
Jun 2024
Message
86
#11

Noted, thanks.

MMeryem S***Member
Job title
Human Resources Specialist
Sector
E-commerce
Organization type
two-branch business
Joined
Dec 2024
Message
303
#12

Saved.

CCemMember
Job title
Agency · Project Manager
Organization type
chain store
Joined
Jun 2024
Message
103

Doki · Infrastructure migration · 2023

#13

Do you think this works at any scale? If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

I'm also curious if anyone does it differently.

NNecati T***ExpertCommunity member
Joined
Oct 2024
Message
50
#14

I didn't know that.

TTolga Y***Expert
Job title
Export manager
Sector
Printing
Organization type
chain store
Joined
Aug 2023
Message
3
#15

I went through the same thing.

SSerkan U***Member
Job title
Site Manager
Sector
Education
Organization type
medium-sized business
Joined
May 2025
Message
312
#16

Let me summarize the topic, since several different answers were given. When we decide without measuring, we always end up in the same place.

Good luck with that.

KKübra E***Member
Job title
Logistics planning
Sector
Leather
Organization type
20-person company
Joined
Mar 2025
Message
46
#17

I was thinking the same thing. If you scold false alarms, nobody will report again.

Proven by experience.

OOkyanusMember
Job title
Embedded software
Organization type
regional distributor
Joined
Apr 2024
Message
96
#18

It's rare to find an explanation this clear. Payment information changes are never verified through the channel they came from.

The answer varies greatly by industry; there is no one-size-fits-all rule. Just leaving this note, it might be useful.

JJülide G***MemberCommunity member
Joined
Jul 2023
Message
166
#19

i agree with this. hasty decisions become decisions you have to fix six months later.

an automated scan report is not the same as a penetration test.

BBurcu A***VeteranCommunity member
Joined
Apr 2024
Message
360
#20

Thanks for writing this, that's the right way. If you don't write this down from the start, it leads to arguments later.

I'm also curious if anyone does it differently.

Reply