
By Yiddy Lemmer, CEO – CompuConnect, Inc.
A cyber incident is not the time to decide who should call the insurance company, isolate a device, notify employees, or restore critical systems.
Businesses in New York and New Jersey need an incident response plan before a cybersecurity event happens because the first few hours matter. A clear plan helps leadership act quickly, limit disruption, protect sensitive information, and keep the business operating.
CompuConnect has completed certified incident response training, strengthening our ability to help businesses prepare for and respond to cybersecurity incidents. That training supports our proactive approach to cybersecurity, business continuity, communication, containment, and recovery.
The goal is simple: give your team a clear path forward before the pressure begins.
What Is an Incident Response Plan?
An incident response plan is a documented set of steps your organization follows when a cybersecurity issue is suspected or confirmed.
It answers practical questions such as:
- Who takes the lead?
- Who contacts the IT provider, legal counsel, insurer, or law enforcement?
- Which systems should be isolated?
- How will employees communicate if email is unavailable?
- Which business systems must be restored first?
- Who communicates with customers or vendors?
A strong plan removes guesswork and helps everyone understand their role.
Why Planning Ahead Matters
Faster Action
Without a plan, valuable time can be lost figuring out who is responsible.
Employees may restart a compromised computer, delete evidence, continue using an affected account, or wait too long to report suspicious activity.
A documented process helps the right people respond quickly and in the correct order.
Less Business Disruption
Cyber incidents often affect more than technology.
Employees may lose access to:
- Shared files
- Accounting systems
- Scheduling platforms
- Customer records
- Cloud applications
- Phone systems
An incident response plan identifies which systems are most important and how the business will continue operating while recovery is underway.
Better Communication
Poor communication can make a difficult situation worse.
Leadership needs to know:
- What happened
- What is being done
- What employees should do
- Whether customers or vendors may be affected
- Who is authorized to speak on behalf of the organization
A clear communication process helps prevent confusion, speculation, and inconsistent messaging.
Stronger Business Continuity
An incident response plan should work alongside your backup, disaster recovery, cybersecurity, and business continuity strategies.
It should define:
- Critical systems and recovery priorities
- Alternate communication methods
- Emergency vendor contacts
- Backup access procedures
- Manual processes for essential work
- Primary and backup decision-makers
This helps the organization stay focused on operations, not only the technical problem.
Why New York and New Jersey Businesses Face Added Complexity
Businesses across New York, New Jersey, and the Tri-State Area often work with a wide network of banks, payroll providers, cloud platforms, accounting firms, healthcare organizations, attorneys, government agencies, and other vendors.
Many also operate with remote employees, multiple offices, mobile devices, and cloud-based systems.
That interconnected environment creates important questions:
- Did the incident begin internally or through a vendor?
- Which locations or employees are affected?
- Is sensitive information involved?
- Can the business operate if a major platform becomes unavailable?
- Are there legal, contractual, insurance, or notification requirements?
These decisions should not be made for the first time during an active incident.
What Should an Incident Response Plan Include?
A useful plan does not need to be overly complicated. It needs to be clear, current, and practical.
Defined Roles
Assign responsibility for:
- Executive decisions
- Technical response
- Legal review
- Insurance communication
- Employee updates
- Customer communication
- Documentation
Each role should have a primary and backup contact.
A Simple Reporting Process
Employees should know exactly how to report:
- Suspicious emails
- Unexpected login prompts
- Lost devices
- Unusual account activity
- Fraudulent payment requests
- Files that suddenly become inaccessible
- Accidental data exposure
They should also be able to reach a real person who can assess the issue quickly.
Containment Steps
The plan should identify who can:
- Disable an account
- Disconnect a device
- Suspend remote access
- Isolate a system
- Contact outside specialists
- Begin recovery procedures
Containment should be coordinated carefully so the business protects both its systems and any evidence needed for investigation.
Communication Procedures
Your team should know how to communicate if normal email or phone systems are unavailable.
The plan should also identify who may communicate with employees, customers, vendors, legal counsel, insurance representatives, regulators, or law enforcement.
Recovery Priorities
Leadership should decide in advance which systems must be restored first.
Typical priorities may include:
- User accounts and identity systems
- Network access
- Email and communications
- Financial and operational applications
- Customer-facing systems
- Department-specific tools
Backups should also be tested. A backup is only useful if it can be restored when needed.
A Written Plan Must Be Tested
Creating a document is only the first step.
A tabletop exercise allows leadership to walk through a realistic scenario and identify gaps before a real event occurs.
For example:
An employee's Microsoft 365 account has been compromised. Fraudulent messages were sent to customers, and the attacker may have accessed sensitive files.
The team would then work through questions such as:
- Who receives the first call?
- How is the account contained?
- Can the company communicate without email?
- When are legal counsel and the insurance carrier contacted?
- What should employees be told?
- What systems must be checked?
- How will normal operations continue?
These exercises often uncover outdated contact information, unclear responsibilities, missing vendor procedures, and unrealistic recovery assumptions.
Finding those gaps during a planned session is far better than discovering them during a cyber event.
How Certified Incident Response Training Strengthens Our Support
CompuConnect has completed certified incident response training designed to strengthen how we help businesses prepare for and respond to cybersecurity incidents.
This training supports our work in:
- Incident response planning
- Cybersecurity coordination
- Business continuity
- Containment
- Communication
- Recovery guidance
It also reinforces our role as a proactive managed IT and cybersecurity partner.
For our clients, that means working with a team that understands the importance of acting quickly, staying organized, and protecting business operations when security issues arise.
The certification does not replace legal counsel, forensics, insurance guidance, or law enforcement. It strengthens the planning and coordination support we provide as part of a broader response team.
The Value of a Proactive IT Partner
A managed services provider should do more than respond when technology stops working.
A proactive partner helps your business prepare by:
- Creating and updating the incident response plan
- Documenting systems, vendors, and recovery priorities
- Monitoring for suspicious activity
- Managing identity and access
- Protecting and testing backups
- Supporting cyber insurance readiness
- Conducting tabletop exercises
- Helping leadership coordinate the response
- Reviewing lessons after an incident or exercise
Technology matters, but so do judgment, communication, and accountability.
When something unusual happens, your team should be able to reach a live person who understands your business and can help guide the next steps.
Prepare Before the Pressure Begins
An incident response plan helps your business:
- Respond faster
- Reduce confusion
- Protect critical operations
- Improve communication
- Coordinate with legal, insurance, and cybersecurity specialists
- Recover in a more controlled way
- Strengthen long-term business continuity
CompuConnect helps businesses across New York, New Jersey, and the Tri-State Area prepare through proactive managed IT services, business cybersecurity, continuity planning, and 100% live human support.
You should not have to navigate an automated system or wait for someone unfamiliar with your environment when your business is under pressure.
Talk to us about cybersecurity and incident response planning.
About the Author
Yiddy Lemmer is the Founder and CEO of CompuConnect IT, a leading IT support and cybersecurity firm serving small and midsize businesses across New York and New Jersey. With over 18 years of hands-on experience, multiple Microsoft and CompTIA certifications, and deep roots in Brooklyn, Yiddy leads with a passion for technology, service excellence, and helping businesses thrive through secure and efficient IT systems.

