We are the IT department for a logistics company with 45 employees. Our team is just two people: myself and a systems specialist colleague. After the recent wave of ransomware and data breach news, management asked us to draft and implement a formal "cyber incident detection and response" plan.
With our daily workload—managing around 60 endpoints, 4 servers, and our cloud email setup—it's impossible for us to dig through logs or monitor alerts 24/7. Last month, a suspicious email attachment infected an accounting PC; it took us 6 hours to clean it up, and all regular operational support ground to a halt during that time.
How should a two-person team divide roles during incident detection and response? When an incident hits, who should look at what, and on a tight budget, at what point does it make sense to bring in managed security support?