If you suspect a breach right now, stop reading and act: activate your incident response plan, call your insurer’s 24/7 hotline, and get your MSP or IT support on the line. Isolate affected devices without shutting them down, and don’t try to fix anything solo. Write down what you saw and when. Everything else in this guide matters, but that first hour is what determines how bad the next thirty days get.
TL;DR:
- Have your insurer’s hotline and MSP emergency contacts immediately accessible offline, preferably on the first page of your printed incident response plan.
- Confirm your team can identify genuine incidents quickly, and avoid attempting any self-repair to prevent evidence destruction during the initial detection.
- Isolate affected devices by disconnecting from networks and preserve logs with timestamps, involving legal counsel before considering ransom payments.
- Only restore from tested backups after completing forensic analysis, patch vulnerabilities, and rotating credentials to prevent reinfection within days.
- Conduct regular, leadership-involved tabletop exercises and update your IRP promptly after any incident or near miss to keep response readiness sharp.
Table of Contents
- Preparation: Building the IRP Every Virginia SMB Needs Today
- What Counts as an Incident, and Who Should Report It?
- Containment and Eradication: Stopping the Bleeding Without Destroying Evidence
- Getting Back Online Safely After a Breach
- Virginia Notification Rules: What the Law Actually Requires
- Turning Every Incident Into a Better Plan
- Why Total Cyber Recommends This Exact Sequence
- Get Your Virginia Breach Response Plan Built Right, Not Fast
- Your Quick-Reference Breach Response Checklist
- Sources
Preparation: Building the IRP Every Virginia SMB Needs Today
A written incident response plan (IRP) does one job: it removes decision-making from the moment you’re most likely to make a bad decision. CISA’s guidance for small businesses is blunt about this: build the plan in “peacetime,” not during a crisis, because an active incident gives you zero time to figure out who’s in charge or where the insurer’s number lives.
Your plan doesn’t need to be a binder. Effective SMB plans run two to four pages, and shorter plans actually get used when it counts. Here’s what belongs in yours:
- Named roles with backups: incident commander, IT liaison, communications lead, legal counsel, HR, and finance.
- An offline emergency contact sheet with your insurer’s hotline and your MSP’s after-hours number, printed, not just saved to a server that might be the thing that’s compromised.
- A ranked list of your five to ten most critical systems, so you know what to protect first.
- Verified, tested backups with a named owner responsible for restore drills.
- Draft templates ready to go: employee notice, customer notice, and an Attorney General notification checklist.
Vetting your managed IT provider’s incident response capabilities before an incident happens is part of this step too. Ask them directly what their documented response time is and whether they’ve run a forensic engagement before.
Pro Tip: Put your insurer’s hotline number on page one of the printed plan, not buried in an appendix. Insurance policies often require notification within a tight window, and fumbling for a number costs you minutes you don’t have.
What Counts as an Incident, and Who Should Report It?
Not every IT hiccup is a breach, but treating ambiguous signals as potential incidents is cheaper than ignoring them. Watch for ransom notes, logins from unfamiliar locations or odd hours, unexplained data loss, and abnormal CPU or network activity that has no obvious cause.
- Employees report immediately. Anyone who spots a warning sign calls the incident commander or IT liaison, not their manager, not a coworker down the hall.
- No self-repair. Employees should never try to delete a suspicious file, reboot a frozen machine, or “just see if it clears up.” Touching the system can destroy evidence.
- IT/MSP triages within the hour. Within 30 to 60 minutes, your MSP or internal IT should confirm whether it’s a real incident, identify which systems are affected, and brief the incident commander with a scope estimate.
- The incident log starts now. Every timestamp, every action taken, every person notified goes into a running log from the first report forward.
Knowing what qualifies as a security incident ahead of time keeps this step fast instead of debated in the moment.
Containment and Eradication: Stopping the Bleeding Without Destroying Evidence
Containment is where most untrained teams cause secondary damage. Pulling a network cable feels productive, but shutting a machine down entirely can wipe volatile memory that forensic investigators need.
- Isolate affected devices from the network (disconnect Wi-Fi or unplug the cable) rather than powering them off.
- Revoke active sessions, force password resets, and confirm multifactor authentication is actually enforced, not just configured.
- Preserve logs and record exact timestamps; maintain a chain of custody if you expect law enforcement or a forensic firm to get involved later.
- If ransomware is in play, involve your insurer and legal counsel before any conversation about payment even starts. That decision isn’t yours to make solo, and most cyber policies have specific requirements around it.
A readable 24-hour action checklist from TechStackToday walks through this same sequence if you want a second reference to hand your team during the actual event.
Pro Tip: Screenshot everything before you touch anything. A phone photo of a ransom note or an error message takes ten seconds and might be the only clean evidence you get.
Getting Back Online Safely After a Breach
Rushing to restore systems before you understand what happened is how businesses get reinfected within days. Recovery has a specific order, and skipping steps defeats the point of having a plan at all.
- Finish forensic analysis to confirm the full scope, including whether data was actually exfiltrated, not just accessed.
- Restore only from backups you’ve tested and validated, checking file integrity before bringing systems back online.
- Patch the vulnerability that let the attacker in. Restoring a clean backup onto an unpatched system just invites round two.
- Rotate all credentials tied to affected systems and keep monitoring restored systems for at least 30 days for signs of reentry.
A vulnerability assessment run right after recovery catches the gaps that got you here in the first place, before an attacker finds them again.
Virginia Notification Rules: What the Law Actually Requires
Virginia Code §18.2-186.6 requires businesses that own or license computerized personal information to notify affected Virginia residents and the Office of the Attorney General without unreasonable delay once unencrypted personal information has been both accessed and acquired. That “accessed and acquired” distinction matters. Mere access without evidence of acquisition doesn’t automatically trigger the statute, though most businesses notify anyway out of caution.
Your notice needs to include specific elements, not a vague apology letter:
- A general description of what happened.
- The type of personal information involved.
- Protective measures already taken.
- A contact phone number for questions.
- Guidance on credit monitoring or other protective steps.
If more than 1,000 Virginia residents are affected, you also owe notice to consumer reporting agencies, and detailed guidance on Virginia’s specific thresholds covers when substitute notice (posting notice publicly instead of mailing individually) becomes an option. A law enforcement request can justify delaying notification, but document that request and get written confirmation, not a verbal nod, before you sit on it.
Turning Every Incident Into a Better Plan
A breach you survive without learning from it is a breach you’ll survive worse the second time. Run a formal post-incident review within two weeks of resolution, while details are still fresh.
- Document the root cause, not just the symptom you patched.
- Build a full timeline from first detection to full recovery.
- Note what worked, what didn’t, and who wasn’t reachable when they should have been.
- Update the IRP, the contact sheet, and backup test records based on what you found.
Near misses deserve the same treatment. CISA recommends treating a caught phishing click or a suspicious login as a live drill for your communications chain, since it exercises the same decision points without the real stakes. Schedule tabletop exercises every six months and quarterly leadership decision drills so the plan stays muscle memory, not a document nobody’s opened since it was written.
Pro Tip: Rotate who plays “incident commander” in your tabletop drills. If only one person knows the plan cold, you don’t have a plan, you have a bottleneck.

Why Total Cyber Recommends This Exact Sequence
Total Cyber built its guidance for Virginia SMBs around one observation: businesses with a leadership-approved plan move faster in a real incident than those improvising with good intentions. A CEO-signed IRP gives the incident commander actual authority to make calls under pressure. Managed monitoring and a standing incident response retainer compress the gap between detection and containment from hours to minutes. That gap is usually where damage compounds. Tabletop facilitation and penetration testing round out the readiness cycle so the plan stays tested, not theoretical.
— Alden
Get Your Virginia Breach Response Plan Built Right, Not Fast
Most SMBs discover their incident response gaps mid-incident, which is the worst possible time to learn your backup restore doesn’t actually work. Total Cyber is a veteran-owned alternative to figuring this out alone: our managed cybersecurity services include 24/7 monitoring, incident response support, and the kind of documented, leadership-approved planning that Virginia’s notification statute practically demands.

If your business doesn’t have a tested IRP, or hasn’t run a tabletop exercise in over a year, that’s the gap to close first. We’ll walk your team through a planning session, identify where your current setup would slow down a real response, and help you build contact sheets, backup verification, and notification templates that hold up under Virginia law. Request a discovery call and get a plan in place before you need one.
Your Quick-Reference Breach Response Checklist
Print this, keep it near the printed contact sheet, and update both after every drill.
- Right now: add your insurer’s hotline and MSP emergency number to an offline sheet; activate your IRP the moment anything looks suspicious.
- This month: test one full backup restore and run a two-hour IR planning session with your core team.
- This quarter: run a tabletop exercise and a leadership decision drill.
| Timeframe | Action | Owner |
|---|---|---|
| Immediate | Add insurer/MSP contacts to offline sheet | Incident commander |
| Immediate | Activate IRP on suspected incident | IT liaison |
| This month | Test one backup restore | IT/MSP |
| This month | Run 2-hour IR planning session | Leadership team |
| This quarter | Tabletop exercise | All roles |
| This quarter | Leadership decision drill | Executive team |
Sources
- CISA — Cyber Guidance for Small Businesses
- Virginia Code §18.2-186.6 — Breach of personal information notification
- Security breach notification chart – Virginia (Perkins Coie / Ashurst summary)
- How to Create a Small Business Incident Response Plan (SmallBizSecurityGuide)