Incident Response Planning for Small Businesses
How to create an incident response plan that meets NY DFS requirements without enterprise complexity.
Section 500.16 requires covered entities to establish written incident response and business continuity and disaster recovery (BCDR) plans. For small businesses, this doesn't mean creating a 100-page document—it means having a practical, actionable plan your team can actually follow when something goes wrong. (Limited-exemption entities under 500.19(a) are exempt from 500.16, but the 500.17 notice duties below still apply to them, so a plan is still wise.)
72-Hour Notification Requirement
Under Section 500.17(a), you must notify NY DFS as promptly as possible and within 72 hours after determining that a cybersecurity incident occurred at your company, an affiliate or a third-party service provider. If you make an extortion payment, you must notify DFS within 24 hours and explain it in writing within 30 days (500.17(c)). Your plan should account for these tight timelines.
What Section 500.16 Requires
Your incident response plan must address these areas for different types of cybersecurity events, including disruptive events such as ransomware:
- Goals of the incident response plan
- Internal processes for responding to cybersecurity events
- Roles, responsibilities, and levels of decision-making authority
- External and internal communications and information sharing
- Identification of requirements for remediation
- Documentation and reporting of incidents
- Recovery from backups
- Root cause analysis: how and why the event happened, its business impact, and how you will prevent a recurrence
- Updating the plan as necessary
Your BCDR plan must also identify essential data, systems and people, set out communications and recovery procedures, and cover offsite backups. Keep backups protected from unauthorized alteration or destruction (500.16(e)).
Building Your Incident Response Plan
1. Define Your Incident Response Team
Even in a small business, you need clear roles. At minimum:
- Incident Commander: Makes decisions and coordinates response (often the owner or CISO)
- Technical Lead: Handles technical investigation and containment
- Communications Lead: Manages internal and external communications
2. Establish Incident Categories
Not all incidents require the same response. Define categories:
Active ransomware, data breach with confirmed exfiltration, system-wide compromise
Malware infection, unauthorized access to sensitive systems, phishing with credential compromise
Suspicious activity, failed breach attempt, policy violation
Minor policy violations, spam, non-targeted threats
3. Create Response Procedures
For each incident category, document:
- Detection & Analysis: How do we identify and confirm the incident?
- Containment: How do we stop the incident from spreading?
- Eradication: How do we remove the threat?
- Recovery: How do we restore normal operations?
- Post-Incident: How do we learn from the incident?
4. Define Communication Procedures
Your plan should include:
- Internal notification: Who gets notified and how (phone tree, email, text)
- Customer notification: When and how to notify affected customers
- Regulatory notification: NY DFS, and potentially other regulators
- Law enforcement: When to involve police or FBI
5. Document External Resources
Include contact information for:
- Incident response consultants or managed security provider
- Cyber insurance carrier (claims hotline)
- Legal counsel with cybersecurity experience
- NY DFS reporting portal and phone number
NY DFS Notification Timeline
Detect, contain, and investigate to determine whether a cybersecurity incident (500.1(g)) has occurred. The 72-hour clock starts at that determination.
Notify NY DFS electronically through the portal, no later than 72 hours after the determination (500.17(a)(1))
Promptly answer DFS information requests and update DFS with material changes or new information (500.17(a)(2))
If you make an extortion payment: notify DFS within 24 hours, and within 30 days explain why payment was necessary, the alternatives and diligence considered, and your sanctions compliance checks (500.17(c))
Testing Your Plan
An untested plan is just a document. Test your plan by:
- Tabletop exercises: Walk through scenarios with your team
- Communication tests: Verify contact information works
- Annual testing (required): At least annually, test your incident response and BCDR plans with all staff and management critical to the response, and test your ability to restore critical data and systems from backups (500.16(d))
- Training: Train everyone responsible for carrying out the plans on their roles (500.16(c))
Buffalo Sentinel Incident Response Support
Our platform includes incident response plan templates and incident tracking with a 72-hour clock from your determination, a log of your DFS updates, and extortion-payment deadlines. Our vCISO service adds hands-on incident response support when you need it.
Need Help Building Your IR Plan?
Get started with our incident response plan template, designed specifically for small businesses.
Request a Demo