- Job title
- Lawyer · IT
- Organization type
- 300-person organization
- Joined
- Sep 2023
- Message
- 168
We are a five-person architectural design and project consultancy firm based in Milan. We store sensitive commercial floor plans and tender documents for our clients on our cloud servers. Last week, an employee clicked on a phishing link in an email, triggering a brief ransomware scare; thankfully, our automated backups saved us from losing any data.
But that day made us realize that if the systems had completely locked up, nobody knew who was supposed to pull the plug on the server, notify the police or data protection authority, or call our IT support contractor. Everyone in the office just stared at each other, and we spent half an hour panicking on the phone.
Our budget is tight, so hiring a full-time security specialist is out of the question. Is building a formal incident response team realistic for a five-person company, or is an emergency phone list pinned to a bulletin board good enough? What should the baseline setup look like for a small business?