What if one of your customers suffered a serious cybersecurity incident? Would they know what to do to protect themselves from further damage and begin the recovery process?
Ideally, every business should have an up-to-date cyber incident response plan that can be activated as soon as a breach occurs. In reality, many SMBs may not. When that happens, they are likely to turn to their trusted IT partner for guidance and support.

Understanding the first steps to take can help partners provide customers with immediate reassurance and practical assistance when they need it most.
Immediate action
When a security breach is discovered, the priority is to contain the threat and minimise any further damage.
Some immediate actions may include:
- Disconnecting or shutting down affected systems
- Changing passwords and passkeys
- Disabling or suspending compromised accounts
- Increasing firewall and security settings to the highest practical level
Anyone who may have been affected should be informed as soon as possible. It is also important to document what happened, including the events leading up to the breach and any actions taken afterwards. This information can be valuable during both recovery and reporting.
Understanding legal obligations
Businesses may have legal responsibilities following a cybersecurity incident, particularly where personal data is involved.
The Information Commissioner's Office (ICO) provides guidance on what organisations should do within the first 72 hours of discovering a data breach. It recommends seven key steps:
- Don't panic
- Report the incident within the required timeframe
- Work out what happened
- Try to contain the breach
- Assess the risk
- Protect anyone who may be affected
- Submit your report if required
Understanding these requirements can help businesses respond effectively while meeting their compliance obligations.
Using trusted guidance
The National Cyber Security Centre (NCSC) also provides practical advice for SMBs and mid-sized businesses responding to cyber attacks.
Its resources cover a range of attack scenarios and provide useful frameworks for containment, recovery and future resilience. For partners supporting customers through an incident, they can be a valuable source of guidance and best practice.
Recovery and prevention
Responding to the immediate incident is only the first step. Once the threat has been contained, the focus should shift to recovery and reducing the risk of future attacks.
This may include reviewing security policies, addressing vulnerabilities, strengthening protections and updating incident response plans.
For partners that do not yet feel confident supporting customers through a cyber incident, the TD SYNNEX security practice team can provide guidance and advice, alongside access to specialist expertise, solutions and services.
By helping customers prepare for, respond to and recover from cybersecurity incidents, partners can deliver additional value while building stronger long-term relationships.
