Cyber Incident Response: Preparing Before a Breach

August 29, 2026 Mark O'Malley

Cyber Incident Response: Preparing Before a Breach

The worst time to decide how your organisation will respond to a cyber incident is after the incident has already started.

Cyber incident response is not simply a technical procedure for the IT team. It is an organisational capability involving leadership, communications, legal advice, privacy, business continuity, suppliers and the people responsible for critical services.

For Family Offices and other high-trust organisations, preparation is particularly important because an incident may affect highly sensitive information, globally distributed family members, advisers and operating businesses at the same time.

Key takeaways

  • Incident response should be designed around business continuity, not only technical containment.
  • Roles, escalation and decision authority should be agreed before an incident.
  • Tabletop exercises expose gaps that written plans often hide.
  • Critical suppliers and external advisers need to be included in the response model.
  • Backups are useful only if restoration works and the organisation knows how long recovery will take.

What counts as a cyber incident?

An incident does not need to be a dramatic ransomware event. Examples include:

  • a compromised Microsoft 365 account;
  • business email compromise or payment fraud;
  • lost or stolen devices containing sensitive information;
  • malware or ransomware;
  • unauthorised access to files or systems;
  • data sent to the wrong recipient;
  • a vulnerable third-party service being breached;
  • credentials or API keys being exposed;
  • sensitive information submitted to an unapproved AI service;
  • an AI agent taking an inappropriate or unauthorised action.

A useful response framework therefore needs to handle security, privacy, operational and AI-related events.

Start with the business impact

The first practical question is not “Which firewall failed?” It is “What do we need to keep operating?”

Organisations should identify:

  • critical systems and services;
  • the information whose loss or exposure would cause the greatest harm;
  • maximum acceptable downtime;
  • critical suppliers and dependencies;
  • manual workarounds if technology becomes unavailable.

This is where incident response, business continuity and disaster recovery meet.

Define roles before the crisis

An incident plan should clearly identify who can make decisions. Depending on the organisation, roles may include:

  • incident lead;
  • technology/security lead;
  • executive decision-maker;
  • privacy or legal adviser;
  • communications lead;
  • business-continuity lead;
  • external cyber incident-response provider;
  • cyber insurer or broker.

Family Offices may also need specific processes for principals, family members, executive assistants and trusted advisers.

Know what triggers escalation

Not every security alert belongs at board level. But management should know what requires immediate escalation.

Examples might include:

  • suspected exposure of sensitive family or customer information;
  • ransomware or destructive malware;
  • fraud or payment diversion;
  • compromise of privileged administrator accounts;
  • loss of a critical service beyond an agreed timeframe;
  • material third-party breach;
  • an incident likely to require regulatory, insurer or stakeholder notification.

Preserve evidence

Well-intentioned actions can destroy useful evidence. Reimaging devices, deleting suspicious messages or changing systems without recording what happened can make investigation harder.

The plan should establish how logs, emails, devices, cloud records and other evidence are preserved and who is responsible for coordinating forensic activity where needed.

Backups must be tested

“We have backups” is not the same as “we can recover.”

Boards and executives should be comfortable that:

  • critical systems are actually backed up;
  • backup copies are protected from the same credentials used in production;
  • restore tests occur;
  • recovery priorities are documented;
  • recovery time is understood;
  • Microsoft 365 and SaaS data are included where appropriate.

Third parties belong in the plan

Modern organisations depend on cloud providers, MSPs, software vendors, finance systems, telecommunications providers and specialist advisers. A response plan that assumes everything is controlled internally is incomplete.

Maintain current emergency contacts for critical suppliers and understand:

  • who owns escalation;
  • what contractual notification obligations exist;
  • what logs or evidence suppliers can provide;
  • how access can be suspended;
  • what happens if the supplier itself is compromised.

Run tabletop exercises

A tabletop exercise is one of the most useful ways to test whether a plan works. It places decision-makers into a realistic scenario without disrupting production systems.

Useful scenarios include:

  • a compromised executive mailbox and fraudulent payment request;
  • ransomware affecting files and email;
  • a stolen laptop containing confidential information;
  • a key cloud provider being unavailable;
  • an adviser account exposing Family Office data;
  • sensitive documents being entered into an unapproved AI service.

The objective is not to catch people out. It is to identify ambiguity before a real incident does.

Five questions boards and principals should ask

  1. What information or system would cause the greatest harm if it were unavailable or exposed?
  2. Who has authority to lead and make decisions during an incident?
  3. Could we operate for several days without our normal email, files or key systems?
  4. When did we last test restoration and incident-response procedures?
  5. Which suppliers would we immediately depend on during a crisis?

AI is changing incident-response assumptions

Public ASD/AICD guidance on frontier AI notes that AI may reduce the time required to discover and exploit vulnerabilities and can enable attacks to become faster and more automated. That places additional pressure on organisations to detect, escalate and respond quickly.

Incident plans should therefore be reviewed as threat conditions change, not left untouched for years.

Preparation creates resilience

DSC’s approach to cybersecurity focuses on resilience as well as prevention. For Family Offices, incident readiness forms part of the wider technology and cyber environment, including identities, devices, advisers, data protection and continuity.

Sources and further reading