
The plan that matters is not the technical runbook. It is the one page that says who decides. Most incident response failures in Philippine SMEs are not caused by missing tools or missing skills. They are caused by four hours lost on a Monday morning while people work out who is allowed to take the system offline.
The short answer
Write down, before anything happens: who declares an incident, who can take a system offline, who speaks to clients, who notifies the National Privacy Commission, and who can approve emergency spending. Name people, not job titles. Include mobile numbers. Keep it to one page and store a copy somewhere that does not depend on the systems that might be down.
Why authority is the bottleneck
Consider a realistic Monday. A finance staff member reports that files on the shared drive have unfamiliar extensions. Your IT provider suspects ransomware and recommends disconnecting the server immediately.
The operations manager will not authorise it because month-end billing is running. The owner is on a flight. Nobody is certain whether disconnecting counts as a decision the IT provider can make alone. The conversation takes three hours.
In those three hours the encryption continues. The technical capability to respond existed from the first minute. What was missing was the authority to use it.
This pattern repeats across incidents of every size. The organisations that respond well are rarely the ones with the best tooling. They are the ones where somebody could say yes.
The five decisions to settle in advance
1. Who declares an incident
Someone must be able to say "this is an incident" and start the process. Without a named person, reports circulate as questions for hours. Give this to at least two people so it does not depend on one person's availability.
2. Who can take a system offline
The most consequential technical decision, and usually the most contested. Disconnecting a server stops the damage and stops the business at the same time.
Decide in advance who holds this authority and under what circumstances they may exercise it without further approval. If your IT provider can act unilaterally when they see active encryption, put that in writing now — not while it is happening.
3. Who speaks to clients and staff
In the absence of an official line, staff will improvise one. Clients hear inconsistent accounts, and the reputational damage often outlasts the technical damage.
Name one person for external communication and one for internal. Everyone else refers enquiries to them.
4. Who notifies the National Privacy Commission
Under the Data Privacy Act of 2012, a personal data breach that meets the notification threshold must be reported to the NPC and to affected data subjects within seventy-two hours of becoming aware of it.
Seventy-two hours sounds generous. It is not, when the first day goes on containment and the second on establishing what was actually accessed. Name who prepares the notification and who signs it. If you have a Data Protection Officer registered with the NPC, this is their responsibility and they should know it.
5. Who can approve emergency spending
Incident response costs money at short notice: an external responder, replacement hardware, expedited recovery. If every purchase needs a signature from someone unreachable, the response stalls on procurement rather than on technique.
Set a figure that a named person can commit without further approval. Most organisations find that a modest ceiling removes almost all of the friction.
What the page should contain
- The five roles above, with named individuals and a named deputy for each
- Mobile numbers, including personal numbers, since the incident may involve the company phone system
- Your IT provider's out-of-hours escalation number, and what they are pre-authorised to do without asking
- Your cyber insurance details and notification requirements, if you carry cover
- The NPC notification deadline and who owns it
- The emergency spending ceiling and who holds it
- Where backups are, and who can authorise a restore
One page. Anything longer will not be read at seven in the morning.
Store it where a failure cannot reach it
A response plan saved only on the file server is a plan you cannot open during a file server incident. The same applies to one stored only in the Microsoft 365 tenant that may be compromised.
Keep a printed copy in the office, a copy on the phones of the named people, and a copy somewhere outside your primary environment. This is unglamorous and it is the difference between having a plan and having had one.
Rehearse it once a year
Spend an hour walking a scenario with the named people around a table. No technology, no simulation — just the conversation.
"It is Monday, ransomware on the file server, the owner is unreachable. What happens?"
Two things usually emerge. Someone named in the plan has left the organisation. And two people believe the same decision belongs to them. Both are far cheaper to discover in a meeting room.
Frequently asked questions
Do small businesses really need an incident response plan?
The smaller the organisation, the more a single incident threatens its survival, and the fewer people there are to absorb the disruption. The plan does not need to be elaborate — one page naming five decisions is enough to prevent the most common failure.
What triggers the seventy-two hour NPC notification?
A personal data breach involving sensitive personal information, or information that may enable identity fraud, where there is a real risk of serious harm to affected data subjects. The clock starts when you become aware of the breach, not when you finish investigating it. If you are uncertain whether the threshold is met, seek advice early rather than waiting.
Should our IT provider be able to disconnect systems without asking?
For active, ongoing damage such as ransomware encryption in progress, most organisations conclude that they should. The decision belongs to you, but it must be made in advance and written down. A provider who has to seek permission while encryption runs is watching the damage rather than stopping it.
How often should the plan be reviewed?
Annually, and whenever a named person leaves or changes role. A plan naming someone who left eight months ago is worse than no plan, because it creates false confidence.
Does cyber insurance change what we should do?
Yes. Most policies require notification within a defined window and many require you to use their approved responders. Engaging your own provider first can affect a claim. Read those terms before an incident and put the requirements on the same page.
Where to start
Onprem2Cloud IT Solutions Co. is a Microsoft Cloud Solution Provider based in Muntinlupa City, serving businesses and government agencies across Metro Manila and beyond. We help organisations document incident response roles and authority, and we run cloud security posture assessments for Microsoft 365 and Azure environments — privileged access, conditional access and MFA coverage, legacy authentication, application permissions, and the logging you will need to answer what happened.
The controls that make a response possible are the same ones that make an incident less likely. Get in touch to discuss your environment.
What's happening
Our latest news and trending topics
