Images are AI-generated illustrations, not documentary photographs or product screenshots.
Incident response contact plan: assign responsibilities before an incident
Identify who coordinates the response, who can make business decisions and who has technical authority. CISA’s small-business guidance recommends a written incident response plan with roles and responsibilities. A contact list supports that plan; it does not replace it. Avoid leaving one person as the only holder of every account and recovery route without an approved backup.
Include relevant providers
Record legitimate support routes for hosting, email, payment services and other critical systems. Verify current contact information and account ownership. Do not rely on a search advertisement during an emergency to locate support. Separate routine contacts from escalation routes and explain when each is appropriate. Store sensitive identifiers only where authorized people can access them.

Prepare an accessible copy
CISA notes the need for an address book usable when the network is down. Choose a protected alternative access route that matches your security obligations. Do not make the plan depend entirely on the compromised account. Avoid publishing private phone numbers or recovery material in a public project page. Test access with the people expected to use it.
Define reporting and decision limits
State how staff report suspicious activity and who approves consequential actions. Do not tell everyone to erase logs or reset systems automatically. Legal notifications and law-enforcement routes depend on the situation and jurisdiction; obtain qualified advice where needed. The plan should direct people to responsible help rather than prescribe unsupported universal incident fixes.
Review and practice
Check the contacts after provider, personnel or account changes. Use a proportionate tabletop exercise to identify missing authority or inaccessible records. Record improvements without simulating harmful actions on production systems. A basic contact plan is valuable because it makes communication possible under pressure, not because it guarantees an incident can be resolved quickly.

Sources and further reading
CISA: small-business security and incident planning
Related reading
A Small-Business Security Risk Assessment You Can Keep Updating
Hiring Cybersecurity Consulting Services: Scope, Evidence and Boundaries
