One page: who to call, what to do first, where the access details are, and who tells customers. Written while nothing is wrong and printed.

Why a page beats knowing

Everything on this page is obvious in advance and difficult in the moment.

The person dealing with it may not be the person who knows, and the person who knows may be unreachable, which is frequently the whole problem.

Under pressure the order gets wrong: the site is restored before the hole is closed, the review is requested before the site is clean, and the password is changed after the sessions are ended.

A page removes the thinking, which is exactly what is unavailable at the time.

What goes on it

The second is what makes the rest possible and is the item most often missing, since access details live in one person's head or password manager.

The contacts, with numbers

Specific people rather than roles, since a role does not answer a telephone.

Your host's support line and your account number, since finding both while a site is down wastes twenty minutes.

Whoever maintains the site, with a mobile number rather than an email address.

The domain registrar, which is a different company from the host and is frequently confused with it.

Your payment provider, if you take payments, and your insurer if you have relevant cover.

And the two or three people inside the business who need to know, in the order they should be told.

Check the numbers annually, since suppliers change and a plan with a dead number is worse than none.

The first four actions

Which are the same for most incidents and are the part that goes wrong.

Contain: take the site offline or put up a holding page rather than leaving it serving something harmful.

Secure: change the password on the affected account, then end all sessions, in that order.

Preserve: take a copy of anything unusual before removing it, and note the times.

Then diagnose, which is where most people start and where the plan says to start fourth.

Writing those four in that order, on the page, is most of the value the page provides.

A worked example

A business wrote a page on a quiet afternoon: four contacts with numbers, where the password manager lived and who else could open it, the four actions, the backup location, and a line saying the owner speaks to customers.

It was printed and put in the office folder, and a copy went home with the owner.

Eight months later the site was flagged with a warning on a Saturday morning while he was away.

His colleague found the page, put up a holding page, rang the host, and reached the developer, all within about twenty minutes.

Nothing on the page was information she could not have found eventually. Finding it eventually would have taken the morning.

Keep it on paper

Because the plausible incidents include losing access to the systems the plan is stored in.

A plan in a document on the drive is unavailable when the account holding the drive is compromised.

Print it, put it where somebody would look, and give a copy to whoever might be dealing with this without you.

Keep a digital copy as well, since paper does not travel, but do not make it the only copy.

Include the address of the password manager and who can open it, without including anything that would let a finder use it.

That balance is the reason this is a page of pointers rather than a page of credentials.

Say who decides and who speaks

The two questions that produce delay when unanswered.

Name who has authority to take the site down, since somebody will hesitate over that decision without permission.

Name who contacts customers and who does not, so that either it happens or it does not happen twice.

Say what can be said before the facts are known, which is usually that there is a problem, that it is being dealt with, and how to reach you.

And name the deputy for each, since the point of the page is the day the usual person is unavailable.

Write it in an hour

Since the barrier is that it sounds like a project.

Sit down with the last few articles' worth of scenarios in mind, or simply ask what would happen if the site were down tomorrow morning.

Write the contacts, the four actions, where things live, and who speaks. That is the page.

Do not write procedures for individual scenarios, which is where these become documents nobody reads.

Review it once a year alongside the other annual checks, and after any incident, when you will know what was missing.

An hour, once, and a few minutes a year afterwards.

Read it once with somebody else

The check that finds what a plan written alone always misses.

Hand the page to whoever might be dealing with this without you and ask them to walk through it aloud.

They will stop at the assumptions: a supplier named without saying what they do, a system named without saying where it is, an instruction that assumes knowledge they do not have.

Fix those there and then, since each is a sentence and each is the point at which the page would otherwise have failed.

Twenty minutes, once, and it is the difference between a page that reads well and a page that works.

The counter-case

A plan is not a substitute for the measures.

A business with a good plan and no backups, no updates, and shared passwords has documented how it will handle an incident it has made likely.

Elaborate plans also fail, since nobody reads twelve pages during an emergency, and the longer the document the less likely it is to be current.

And most small businesses will never need it, which is the same argument as for backups and is equally beside the point.

Keep it to one page, print it, name people rather than roles, and check the numbers annually.

The page

  1. Four contacts with mobile numbers.
  2. Where access details live and who can reach them.
  3. Contain, secure, preserve, diagnose.
  4. Where the backups are.
  5. Who decides and who speaks to customers.
  6. Print it and give somebody a copy.
  7. Check the numbers once a year.

Step three is the part that changes an outcome, since acting in that order is what stops an incident being handled twice.

Documenting the rest of how you work is covered in writing down how you do things.


Frequently asked questions

Why write it down if I already know?

Because the person dealing with it may not be you, and under pressure the order goes wrong: restoring before closing the hole, or ending sessions before changing the password.

What goes on the page?

Contacts with numbers, where access details live, the first four actions in order, where the backups are, who talks to customers, and what to record.

What are the first four actions?

Contain by taking the site offline, secure by changing the password then ending sessions, preserve by copying anything unusual, then diagnose. Most people start at the fourth.

Why keep it on paper?

Because plausible incidents include losing access to the systems the plan is stored in. A plan on a drive is unavailable when the account holding the drive is compromised.

Should it contain passwords?

No. It should say where the password manager is and who can open it, without including anything that would let somebody finding the page use it.

How long should it take to write?

An hour. Contacts, four actions, where things live, and who speaks. Do not write procedures per scenario, which is how these become documents nobody reads.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Would somebody else know what to do tomorrow morning?

Write the four contacts and the four actions on one page this week, and print it.

Start a Conversation