| Quick Answer Ransomware, business email compromise, and data exposure incidents account for the vast majority of cyber incidents affecting small and mid-market businesses. Each requires a different response, different containment steps, different legal obligations, and different decisions about communications and third-party engagement. Generic incident response plans do not provide the scenario-specific guidance that effective response requires. Playbooks do. |
Key Takeaways
- A generic incident response plan describes the phases of response. A playbook provides the specific steps, decisions, and contacts for a particular incident type in the actual environment where it occurs.
- Ransomware, business email compromise, and data exposure are the three incident types most commonly affecting SMBs. All three have well-documented response patterns that organizations can prepare for in advance.
- Ransomware response requires specific decisions about isolation, backup integrity, ransom negotiation authority, and recovery sequencing that cannot be made effectively for the first time under pressure.
- Business email compromise requires immediate financial fraud response steps that have short windows: fraudulent wire transfers can sometimes be recalled within hours, but only if the response is fast enough.
- Data exposure incidents trigger regulatory notification obligations with defined time limits. Organizations that do not know their notification triggers and timelines risk regulatory penalties on top of the incident itself.
Incident response playbooks for a small business are what turn a generic plan into something a responder can actually execute under pressure. Ransomware, business email compromise, and data exposure account for the majority of incidents that hit small and mid-market organizations, and each demands a different sequence of containment, legal, and communication steps. The speed of that response is not a small factor: IBM’s 2025 Cost of a Data Breach Report shows that faster containment consistently lowers the total cost of an incident, and a scenario-specific playbook is how a team moves fast without improvising. A strong incident response capability is built from these playbooks, not from a binder that only describes the phases.
| By the NumbersRansomware appears in 44% of all breaches and 88% of breaches at small and mid-sized businesses, with a median ransom demand near $115,000. Source: Verizon 2025 Data Breach Investigations Report.$2.77B in reported business email compromise losses in a single year. Source: FBI Internet Crime Report 2024.Faster containment lowers breach cost. The global average breach cost $4.44M ($10.22M in the US). Source: IBM Cost of a Data Breach Report 2025. |
What Is the Difference Between an IR Plan and a Playbook?
An incident response plan describes the organizational framework for responding to security incidents: the phases of response (preparation, detection, containment, eradication, recovery, lessons learned), the roles and responsibilities of the response team, the escalation paths, and the general communication and documentation requirements. The IR plan is the architecture.
A playbook is the specific operational guidance for a particular type of incident in the specific environment where it would occur. It tells the person responding exactly what to do, in what sequence, with what tools, and with what decisions that need to be made along the way. A good playbook contains enough detail that a competent IT professional who has not previously managed this type of incident can follow it effectively under pressure.
The gap between having an IR plan and having playbooks is significant. An IR plan tells the response team that they need to contain the incident. A ransomware playbook tells them which specific systems to isolate first, how to check whether backup systems are affected before using them for recovery, what forensic evidence to preserve before isolation, and which decision-maker has authority to authorize taking production systems offline. That specificity is what determines whether the response is fast and effective or slow and improvised.
A playbook also has to be proven, not assumed. Running it as a tabletop exercise is what turns a written document into a capability the team can execute when the pressure is real.

What Should a Ransomware Playbook Cover?
Ransomware is the most destructive incident type affecting businesses of all sizes. In Verizon’s 2025 Data Breach Investigations Report, ransomware appeared in 44 percent of all breaches and in 88 percent of breaches at small and mid-sized businesses, with a median ransom demand near $115,000. The response window matters enormously: ransomware that is detected and contained early, before it has encrypted all accessible systems and propagated to backup infrastructure, results in dramatically better recovery outcomes than ransomware that is detected only after it has fully executed.
Detection and initial assessment
The first step in ransomware response is confirming that the incident is actually ransomware and not another type of alert, identifying which systems are affected, and determining the potential scope. This assessment needs to happen quickly and follow a defined procedure, because the next decision, isolation, affects business operations and must be taken with some understanding of the scope rather than blindly.
Isolation and containment
Isolation stops ransomware propagation by removing affected systems from network connectivity. The playbook needs to specify which systems to isolate first, based on the organization’s network architecture and the systems most likely to be targeted for propagation. Critically, it needs to address backup systems specifically: ransomware that has reached backup infrastructure before detection means that recovery from backup is not an option, which changes the response decision tree entirely.
Forensic preservation before remediation
Before reimaging affected systems or taking recovery steps, forensic preservation must happen. The playbook specifies which evidence to capture, in what format, using what tools, and in what sequence. This step is frequently omitted or executed incorrectly when response is improvised, resulting in the loss of evidence needed to confirm breach scope, support insurance claims, and inform the regulatory notification assessment.
Ransom negotiation decision authority
The decision to engage in ransom negotiation, pay a ransom demand, or decline payment is one of the most consequential decisions in a ransomware response. It involves legal considerations, insurance policy conditions, regulatory implications, and strategic judgments about recovery options. The playbook needs to document who has authority to make this decision, what factors they should weigh, what process they should follow, and which advisors, breach counsel, the cyber insurance carrier, forensic responders, should be engaged before the decision is made.
Recovery sequencing
Recovery from ransomware is not simply restoring from backup. It involves confirming backup integrity, sequencing restoration to bring the most critical systems back first, validating that restored systems are clean before reconnecting them to the network, and managing business continuity during the recovery period. The playbook specifies the recovery sequence based on business impact analysis of the specific systems in the environment.

What Should a Business Email Compromise Playbook Cover?
Business email compromise (BEC) is one of the costliest incident types for businesses, causing billions in reported losses annually through fraudulent wire transfers, invoice fraud, payroll redirection, and gift card scams. The FBI’s 2024 Internet Crime Report recorded $2.77 billion in reported BEC losses in a single year. The response window for financial fraud is extremely short: fraudulent wire transfers can sometimes be recalled through the banking system if the response is fast enough, but that window is typically measured in hours, not days.
A BEC playbook needs to address email account compromise indicators and the immediate steps to contain a compromised account without alerting the attacker prematurely. It needs to specify the exact financial institution contacts and procedures for attempting wire recall, which requires speed that is only possible if those contacts are documented in advance. It needs to cover the forensic preservation steps for the compromised email account before remediation, since the forensic evidence will be needed for the insurance claim and potentially for law enforcement.
The playbook also needs to address the customer and partner notification requirements if compromised email accounts were used to send fraudulent communications. Customers who received fraudulent invoices or payment instructions from a compromised account need to be notified quickly enough that they can take protective action, and that notification needs to be approved through a defined process that does not create additional liability.

What Should a Data Exposure Playbook Cover?
Data exposure incidents, whether through misconfigured cloud storage, unauthorized access to systems containing personal information, or database exposure, trigger regulatory notification obligations that are time-bound from the point of detection or awareness. Organizations that do not have a clear process for assessing notification obligations risk missing mandatory notification deadlines, which creates regulatory penalties on top of the incident costs.
A data exposure playbook needs to cover the immediate steps to contain and remediate the exposure, the forensic investigation steps to establish scope (what data was exposed, to whom, for how long), the privacy counsel engagement process, the notification trigger assessment against applicable frameworks (PIPEDA, sector-specific obligations, and any applicable US state laws for organizations with US customers), and the documentation required to support the regulator notification filing.
Armour Cybersecurity’s breach readiness assessment inventories existing playbooks and runbooks against the most likely incident types for the organization and identifies coverage gaps. For organizations without documented playbooks, the remediation roadmap includes playbook development as a priority item. The assessment methodology draws from NIST SP 800-61, ISO 27035, and the response requirements of major cyber insurance carriers to ensure playbooks meet the standards that auditors and underwriters expect.
Where Playbooks Fit in Armour’s Managed Services
Playbooks rarely work alone. They are one pillar of Armour’s managed cybersecurity services, operating alongside a managed Security Operations Center that detects the incident in the first place, cyber threat intelligence to keep playbooks aligned with current attacker behavior, vCISO leadership to own the decision authority the playbooks reference, cyber awareness training to reduce the phishing and BEC triggers, and the all-in-one Armour 360 managed program. A playbook is only as good as the program it sits inside.
The Bottom Line
A plan tells you that you need to respond. A playbook tells you how, step by step, for the incident you are actually facing. Ransomware, business email compromise, and data exposure are predictable enough that every small and mid-market business can prepare for them in advance, and the organizations that do respond faster, lose less, and stay on the right side of their notification obligations. A breach readiness assessment shows exactly which playbooks you have, which you are missing, and which no longer match the environment they were written for. Build the playbooks before the incident writes them for you.
Across the 260+ organizations Armour protects in 52+ industries, most have an incident response plan and almost none have scenario-specific playbooks, so the ransomware, BEC, and data exposure steps that actually decide the outcome are still being improvised under pressure.
Frequently Asked Questions
What are incident response playbooks for a small business?
Incident response playbooks for a small business are scenario-specific response guides that turn a general IR plan into concrete, executable steps for a particular incident type. Where the plan sets out phases and roles, a playbook tells the responder which systems to isolate first, what evidence to preserve before remediation, who holds the authority for each decision, and which contacts to call, all tailored to the organization’s actual environment. The three that most SMBs need first are ransomware, business email compromise, and data exposure, because those account for the majority of real incidents.
How detailed should a ransomware playbook be?
A ransomware playbook should be detailed enough that a competent IT professional who has not previously managed a ransomware incident can follow it effectively under pressure. That means specific steps in a specific sequence, with named tools, specific decision points with documented authority, and specific contacts for each escalation. Generic guidance, isolate affected systems, notify leadership, engage external support, is not sufficient. The value of a playbook is in the specifics that make it actionable under crisis conditions.
What is a wire recall and how fast does it need to happen?
A wire recall is a request to the sending financial institution to reverse a fraudulent wire transfer before the funds are moved by the receiving institution. The window for a successful wire recall depends on the destination: domestic transfers have a longer recall window than international transfers, and some destination jurisdictions make recall effectively impossible regardless of timing. The critical point is that initiating the recall process requires contacting the financial institution’s fraud team with specific information, through a specific process, that needs to be documented in advance. Organizations that discover the process for the first time during a BEC incident typically miss the recall window.
Which privacy laws apply to data exposure incidents for Canadian businesses?
PIPEDA applies to personal information in commercial activities across Canada and requires notification of affected individuals and the Office of the Privacy Commissioner when a breach creates a real risk of significant harm. Quebec’s Law 25 requires prompt notification of the Commission d’accès à l’information and affected individuals when a confidentiality incident presents a risk of serious injury. There is no fixed statutory hour count the way there is under GDPR, but many organizations plan against a 72-hour benchmark. Provincial health privacy legislation applies to healthcare sector organizations, and for organizations with US customers, applicable US state breach notification laws may also be triggered. Determining which obligations apply to a specific incident requires privacy counsel engagement, which is why pre-establishing that relationship is a standard component of breach readiness.
How often should incident response playbooks be updated?
Playbooks should be reviewed and updated whenever the technology environment they describe changes, whenever an incident or exercise reveals that a procedure does not match reality, and as a minimum on an annual cycle. Playbooks that reference specific systems, tools, or configurations need to be updated when those specifics change. A ransomware playbook that describes isolation procedures for an on-premises environment does not provide useful guidance for an organization that has moved substantially to cloud infrastructure. Outdated playbooks can be worse than no playbook because they provide false confidence that a procedure exists.
What is the difference between a playbook and a runbook?
The terms are sometimes used interchangeably, but in practice they describe different levels of detail. A playbook is the strategic response guide for an incident type: the phases, decisions, escalations, and communications framework for responding to a ransomware attack or a BEC incident. A runbook is the technical procedure for a specific operational task within that response: the exact steps to isolate a Windows endpoint from the network, the specific commands to preserve memory forensics from a live system, the procedure to revoke and rotate compromised cloud credentials. Both are needed: the playbook provides the decision framework and the runbook provides the technical execution steps.
About the Author
David Chernitzky is the CEO and Co-Founder of Armour Cybersecurity, a Toronto-based firm that protects organizations across North America from advanced cyber threats. He brings more than 25 years of cybersecurity and military cyber intelligence experience, having served as an officer in an elite technology unit before co-founding Armour. Armour’s team of military-intelligence veterans and senior advisors serves 260+ clients across 52+ industries with a 97% client retention rate.



