Responding to a Cyber Incident
Find out what you can do if you think that you have been a victim of a cyber incident.
- Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile—seeks to assist organizations with incorporating cybersecurity incident response recommendations and considerations throughout their cybersecurity risk management activities as described by the NIST Cybersecurity Framework (CSF) 2.0.
National Institute of Standards and Technology
- Cyber Readiness Institute Incident Response Plan Template - Establishing cyber readiness practices and policies helps to reduce risk, but it’s important to assume that our company is likely to have to deal with a security incident at some point that could impact business operations.
Cyber Readiness Institute
- FBI’s Internet Crime Complaint Center - The Internet Crime Complaint Center (IC3) is the central hub for reporting cyber-enabled crime. It is run by the FBI, the lead federal agency for investigating crime.
Federal Bureau of Investigation
- Data Breach Response: A Guide for Business – addresses the steps to take once a breach has occurred
Federal Trade Commission
- Recovering from a Cybersecurity Incident – geared towards small manufacturers; presentation about best practices that use the Incident Response Lifecycle to provide guidance on recovering from and preventing cybersecurity incidents
Manufacturing Extension Partnership
- Hacked Devices & Accounts - A hacked account or device can make you more vulnerable to other cyberattacks. Get the info you need to recognize, report, and recover.
Cybercrime Support Network
- Best Practices for Victim Response and Reporting of Cyber Incidents - “best practices” document to help organizations prepare a cyber incident response plan and, more generally, to better equip themselves to respond effectively and lawfully to a cyber incident.
U.S. Department of Justice
- Guide for Cybersecurity Event Recovery - This publication provides tactical and strategic guidance regarding the planning, playbook developing, testing, and improvement of recovery planning.
National Institute of Standards and Technology
- Creating an IT Disaster Recovery Plan - An information technology disaster recovery plan (IT DRP) should be developed in conjunction with the business continuity plan. Priorities and recovery time objectives for information technology should be developed during the business impact analysis. Technology recovery strategies should be developed to restore hardware, applications and data in time to meet the needs of the business recovery.
U.S. Department of Homeland Security
- NIST Incident Response Preparation Resources Page
Content outlined on the Small Business Cybersecurity Corner webpages contains documents and resources from our contributors. These resources were identified by our contributors as information they deemed most relevant and timely—and were chosen based on the current needs of the small business community. Certain commercial entities may be identified in this Web site or linked Web sites. Such identification is not intended to imply recommendation or endorsement by NIST, nor is it intended to imply that the entities, materials, or equipment are necessarily the best available for the purpose.
Created February 7, 2019, Updated August 24, 2026