Cyber incident response for an SMB involves containing the attack, preserving evidence, understanding what was compromised, restoring the system, and then learning from it. The first few hours change everything: cutting things off too quickly can destroy clues, waiting too long makes the data breach worse. Above all, prepare three things before a crisis: contacts, offline backups, and decision-making roles.
Cyber incident response: what it really changes for an SMB
The intent behind this search is very practical: knowing what to do, who to call, how much it may cost, and how to prevent the incident from becoming a business crisis. Cyber incident response is not just an IT matter. It affects management, legal, communications, operations, and sometimes customers.
Since 2026, ANSSI has placed greater emphasis on operational response, including with REACTIV for government services, an enhanced capability dedicated in particular to compromised accounts and data breaches. An SMB does not fall within this public framework, but the message is clear: speed of decision-making and coordination matter just as much as the technical tool.
In a company of 20 to 250 people, the main risk is not always how sophisticated the attack is. It is the lack of clarity. Who decides to shut down the server? Who talks to customers? Where are the backups? Who has access to OVH hosting, Cloudflare DNS, Microsoft 365, or Google Workspace? Without written answers, every hour costs more.
The six useful steps: detect, contain, analyze, eradicate, restore, learn
The healthiest method follows a simple chain. Detection, containment, analysis, eradication, restoration, lessons learned. It avoids two common mistakes: restarting a system too quickly when it is still compromised, or spending three days investigating when operations need to resume within a minimal scope.
Detection begins with a signal: encrypted files, an email account sending spam, an EDR alert (detection tool on endpoints), unusual login, fraudulent invoice, suspicious Chrome extension. If the issue concerns user endpoints, comparing EDR and antivirus helps explain why traditional antivirus is not always enough anymore.
Containment aims to prevent the attacker from continuing. For a confirmed incident, ANSSI recommends disconnecting the affected equipment or the information system from the Internet in order to limit the attacker's actions and data exfiltration. Be careful: disconnecting does not mean shutting down. Cutting power to a server or reinstalling a workstation can erase useful traces.
Analysis is used to answer concrete questions: which account was used, what data left, since when, what scope is trustworthy? Eradication removes the cause: compromised password, email forwarding rule, malware, unpatched vulnerability, forgotten VPN access. Restoration gets operations back up and running, ideally from clean backups, then the lessons learned turn the incident into an improvement plan.
The right reflexes in the first 24 hours
The first reflex is not to “clean up.” It is to stabilize. Open a chronological log with date, time, person, action, and observation. ANSSI recommends this for very small businesses/SMBs, and it is very useful for the insurer, the CNIL, the technical provider, or a possible police report.
- Isolate suspicious machines or accounts without shutting them down if possible.
- Change passwords from a clean machine, giving priority to email, administrators, hosting, backups, and banking.
- Check the integrity of backups before any restoration.
- Preserve evidence: screenshots, logs, emails, IP addresses, timestamp, suspicious files.
- Notify the cyber insurer if a policy exists, because some require a rapid reporting process.
- Assess whether personal data is involved in order to trigger GDPR analysis.
In the projects we handle, we often see the same trap: the company restores a site or server from a backup, but keeps the compromised administrator account. Result: the attacker comes back. At that point, the cost almost doubles mechanically, because the analysis has to be redone and the teams’ trust regained.
CNIL, evidence, insurance: obligations not to miss
If the incident affects personal data, the GDPR (European regulation on personal data, applicable since 2018) requires all breaches to be documented internally. When there is a risk to individuals, the CNIL must be notified within 72 hours if possible. In the event of a high risk, the individuals concerned must also be informed quickly.
The 72-hour period does not start at the first vague suspicion. According to the CNIL, it begins lorsque the data controller has a reasonable degree of certainty that an incident has occurred and that it concerns personal data. An initial notification can then be supplemented if the investigation continues. That is reassuring, but it assumes serious documentation from the very beginning.
Cyber insurance deserves a separate point. Some policies cover technical assistance, business interruption, legal fees, or crisis communication, but exclusions are numerous: no backups, MFA (multi-factor authentication) not enabled, unmaintained systems. Before a loss, reread the guarantees and pitfalls of cyber insurance for SMEs helps avoid believing that a contract will pay for everything.
When it comes to communication, it is better to say little but say it accurately. In 2026, ANSSI published an updated version of its cyber crisis communication guide with sheets and a checklist. For an SME, the right level is often understated: acknowledge the incident, say what is being done, avoid hypotheses, orient customers if action is required.
Which provider should you call, and what price should you expect?
For an SME, three levels of assistance exist. D’abord the usual IT provider, useful if they know your infrastructure, your backups, and your access rights. Next are the professionals listed via Cybermalveillance.gouv.fr, whom ANSSI recommends for diagnosis and local orientation, with possible support from the CMA or CCI. Finally, there are PRIS providers, meaning security incident response providers qualified by ANSSI.
PRIS providers intervene in sensitive or complex incidents: searching for indicators of compromise, digital investigation, malware analysis, coordination of investigations, qualification of the compromised scope, and remediation recommendations. The ANSSI 2025 catalog notably mentions PricewaterhouseCoopers Advisory, Sopra Steria Infrastructures and Security Services, Thales Cyber Solutions, and Wavestone; players such as Capgemini, Lexfo, Synacktiv, or Synetis also appear among the qualification projects made public in 2026.
| Situation | Likely responder | Realistic timeline | Estimated budget France |
|---|---|---|---|
| Compromised email account with no proven leak | Local IT or cybersecurity provider | A few hours to 1 day | Around €500 to €2,000 |
| Infected or defaced WordPress site | Secure web agency or web incident specialist | 1 to 3 days | Around €800 to €4,000 |
| Ransomware on multiple workstations | Cybersecurity provider, sometimes regional CSIRT | 3 to 10 days to partially restart | Often €5,000 to €30,000 depending on scope |
| Customer data leak or widespread attack | Specialized team, possibly PRIS | 1 to 4 weeks | Several tens of thousands of euros |
These ranges are not official rates. They reflect orders of magnitude observed on the French market depending on providers, system size, and urgency. Honestly, unless there is a serious incident, a PRIS is not always the right first call for a small organization: sometimes it is better to use a responsive, local team capable of securing the essentials quickly and properly.
Backups, access, hosting: the preparation that reduces the bill
Backup is the least glamorous topic, and often the most cost-effective. ANSSI reminds us that intact backups allow for a quick restart after ransomware encryption, and recommends regular backups that are not connected. A backup permanently synchronized in the cloud can be encrypted at the same time as everything else. An unpleasant surprise.
For an e-commerce site, a business application, or an extranet, the plan must specify dependencies: host, database, DNS, CDN (content delivery network like Cloudflare), transactional emails, payment provider, GitHub or GitLab code repository. An attack on a single administrator account can block the entire chain. Remote digital access therefore deserves particular attention, especially for hybrid teams; the topic is detailed in this guide on securing remote access.
The most costly attacks very often start with an email. Training teams remains useful, provided cybersecurity is not turned into constant blame. An approach to phishing awareness tailored to teams reduces the number of incidents without disrupting daily work.
Another trade-off comes up often: invest in prevention or keep budget for the crisis? Both, but not at the same level. For an SME, a few thousand euros per year spent on MFA, tested backups, basic monitoring, and updates is better than a very ambitious audit that is never followed by action.
Roles and contacts: the short plan management must have
An effective cyber incident response plan can sometimes fit on five pages. It names the decision-makers, backups, service providers, insurer, lawyer if necessary, host, bank, the DPO (data protection officer) or equivalent. No need for a binder no one will read.
ANSSI also highlights regional CSIRTs, first-level response centers present in the French regions, with a network of 12 regional CSIRTs and 3 overseas centers intended to become one. For an SME without an internal cyber team, this is a useful entry point, especially for guidance and first steps.
On the agency side, the reflex is to separate the technical emergency and business recovery very quickly. Can a static version of the site be put back online? Can emails be switched temporarily? Should a payment feature be suspended rather than stopping everything? The best answer is not always immediate full restoration.
Defining this type of project in advance avoids most unpleasant surprises: access, backups, responsibilities, recovery scenarios, messages ready to be adapted. This is often where an outside perspective saves time, especially when the website, business application, and hosting are linked.
FAQ on cyber incident response
What should you do first after a cyberattack in an SME?
Isolate suspicious equipment or accounts without erasing evidence, open a chronological log, and contact your provider or a service such as Cybermalveillance.gouv.fr. Do not reinstall before you have understood the scope of what was affected.
Should you shut down a ordinateur infected with ransomware?
Not automatically. ANSSI recommends preserving evidence and not modifying attacked equipment; disconnecting from the network is often preferable to abruptly shutting it down, unless there is a hardware risk or an expert advises otherwise.
When should a data breach be reported to the CNIL?
If personal data is involved and there is a risk to individuals, the notification must be made to the CNIL within 72 hours if possible. All breaches must at a minimum be documented internally.
How much does a cyber incident response cost for an SME?
A limited incident can cost around €500 to €4,000. A ransomware attack or a data breach can rise to several tens of thousands of euros, especially if business interruption, legal costs, and communications are added to the technical response.
Is a PRIS provider mandatory?
No. PRIS providers qualified by ANSSI are suited to sensitive or complex incidents, but an SME can first contact its provider, Cybermalveillance.gouv.fr or a regional CSIRT depending on the severity.