
One-page incident response plan (that someone will read)
An 80-page IRP nobody opens. Minimum viable version for SMBs: roles, contacts, first 4 hours, and when to call legal.
CISA publishes excellent incident response templates; many SMBs in Puerto Rico download them, file them, and on day zero call the consultant in panic not knowing who turns off what. A useful plan fits on one page plus technical annexes — not the reverse.
Section 1 — Roles: who is incident commander (manager with a
Section 1 — Roles: who is incident commander (manager with authority), who talks to employees, who talks to customers, who preserves evidence. Without names and backups, there is no plan. Section 2 — Contacts: MSP, attorney, cyber insurance carrier, PR forensics. Tested quarterly with a tabletop drill.
First four hours: contain (isolate hosts, reset privileged c
First four hours: contain (isolate hosts, reset privileged credentials, preserve logs), assess preliminary scope, activate internal comms, decide disconnect production vs run degraded. Document decisions with timestamps — adjuster and regulator will ask later.
Default policy is do not pay ransom per FBI and CISA; exceptions exist but require legal and forensics involved, not owner alone on WhatsApp. Keep offline printed copies — ransomware encrypts SharePoint too.
Practice: annual minimum, 90-minute phishing→ransomware tabletop. Krebs documents incidents where competent companies failed on communication, not technique. Your advantage as a local SMB is agility — if you know who decides what before chaos.

Writes about practical cybersecurity for SMBs in Puerto Rico and the Caribbean — no fluff, just what actually needs to get done.


