Cybersecurity

The First Hour Decides Everything: The Incident Response Plan for Montgomery County Businesses

September 1, 2026 · 8 minutes

The First Hour Decides Everything: The Incident Response Plan for Montgomery County Businesses

In small and mid-sized business breaches last year, a third party was involved 55 percent of the time, according to Verizon's 2026 Data Breach Investigations Report. That number reshapes what an incident response plan for Montgomery County businesses has to cover, because the first call may not go to anyone on your payroll.

The Hour Nobody Rehearses

It rarely starts with a ransom note. It starts with a file that will not open.

Someone in billing says the shared drive looks wrong. Someone else mentions the scanner has been offline since yesterday. The office manager tries the IT number and reaches voicemail. Ten minutes pass, then twenty.

By the time a real conversation begins, an intruder has often had the run of the network for days. What happens next gets decided by people who are improvising under pressure, in an office that still has patients in the waiting room or clients on the calendar. That is the part worth fixing, and it costs nothing but an afternoon of planning.

The technology side of a breach eventually gets handled. Someone isolates a machine, restores from backup, and rebuilds what needs rebuilding. The expensive damage usually comes from the decisions made around that work: who was told, how quickly, and whether anyone was writing it down.

Verizon's 2026 report found that exploitation of vulnerabilities was the leading way attackers got into small and mid-sized businesses, at 26 percent of breaches. Credential abuse followed at 13 percent, and phishing at 9 percent. None of those leave a dramatic calling card on the way in. They leave a slow Tuesday and a confused staff.

Where the First Hour Actually Goes

Ask an office manager to narrate a breach morning and the same delays surface every time. Almost none of them require technical skill to solve. They involve information nobody bothered to write down.

  • Nobody is certain who holds administrative credentials for the server or the cloud tenant
  • The support contract, the vendor's after-hours number, and the account ID sit in three different places
  • No one has clear authority to decide whether to disconnect the network
  • The list of systems holding client or patient records exists only in someone's memory
  • The owner or managing partner is in court, in a procedure, or on a plane

Each of those is a paperwork problem wearing a technology costume. Every one of them can be answered on a quiet afternoon, well before the morning it matters. Written answers turn a scramble into a sequence.

Maryland Starts a Clock You Cannot Pause

Under the Maryland Personal Information Protection Act, a business that discovers a security breach must notify affected Maryland consumers within 45 days. That clock starts at discovery. It does not wait for your investigation to feel finished.

Maryland also reverses the order most owners expect. The Office of the Attorney General must be notified before consumers are. That notice has to describe the breach, the number of Maryland residents being notified, what information was compromised, and the steps taken to restore the integrity of the system.

Personal information under the statute is broader than most people assume. It covers Social Security and passport numbers, driver's license numbers, and financial account numbers paired with access codes. It also covers health information including mental health, health insurance identifiers, biometric data, and email credentials.

The law does allow some breathing room. A business may delay notice at the request of law enforcement, or to determine the scope of the breach, identify affected individuals, and restore the system. That is a narrow allowance, not a reset button.

Medical and Legal Offices Run Two Clocks at Once

A practice subject to HIPAA carries a second obligation, and the incident response plan for Montgomery County businesses in healthcare has to track both deadlines at once. HHS requires that affected individuals be notified without unreasonable delay, and no later than 60 days after a breach is discovered. When a breach affects more than 500 residents of a state, prominent media outlets must be notified in the same window.

One detail catches small practices repeatedly. If the breach happens at a vendor, that vendor must notify the practice within 60 days, but the practice remains responsible for notifying patients. Your billing service or cloud provider can create the incident. The notification duty still lands on your desk.

Documentation matters here too. Covered entities carry the burden of showing that required notifications were made, or that an incident did not meet the definition of a breach. That proof is far easier to assemble when someone was taking notes on day one.

The Vendor Question Most Offices Skip

Given that 55 percent third-party figure, the contracts sitting in your filing cabinet deserve a second look. Most small offices in Bethesda, Rockville, and Silver Spring rely on a stack of outside providers: an IT company, a cloud application, a billing service, a document management platform. Any one of them can be the entry point.

  • Does the contract state how quickly the vendor must notify you of an incident
  • Do you have a direct after-hours number, not a general support queue
  • Which of your systems and data can that vendor reach today
  • Do they hold your backups, and could you restore without their cooperation
  • Who at that vendor has authority to confirm an incident in writing

Those five answers belong in the same folder as your call list. Chasing them down during an incident wastes the hours you can least afford to lose.

Who Belongs on the Call List

A workable incident response plan for Montgomery County businesses starts with names and phone numbers, not architecture diagrams. Six roles cover nearly every scenario a small office will face.

  • The IT provider, with a documented after-hours escalation path
  • The owner or managing partner who can authorize containment and spending
  • The cyber insurance carrier, since most policies require prompt notice
  • Outside counsel, particularly for firms and practices with privilege concerns
  • Any vendor with access to your systems or your data
  • One named person who communicates with staff and clients

Print it. A call list stored only on the network you just disconnected is not a call list.

Decisions That Should Not Be Made at 6 a.m.

Ransomware appeared in 48 percent of breaches in Verizon's 2026 dataset, up from 44 percent the year before, and small organizations are disproportionately affected. The pressure to pay arrives quickly, and it arrives with a countdown attached.

Worth knowing before that morning: 69 percent of ransomware victims in the same dataset did not pay. Whatever your position, it should be reached calmly, with counsel and your insurer, rather than by a rattled owner at dawn.

Two other decisions belong in the plan rather than in the moment. The first is whether to isolate a machine or power it off, because a hard shutdown can destroy evidence you will later need. The second is what staff are told in the opening hours, since a well-meaning employee posting about an outage can complicate a legal position.

The Notes Nobody Thinks to Take

In the middle of an incident, documentation feels like a distraction. It is the opposite. Both Maryland and federal regulators expect a record, and the record is far easier to build in real time than to reconstruct from memory three weeks later.

Maryland's notice to the Attorney General must describe the nature of the breach, the number of residents affected, what information was compromised, and the steps taken to restore the system. HHS goes further and places the burden of proof on the organization. A covered entity has to demonstrate either that required notifications went out, or that the incident did not meet the definition of a breach at all.

A single running log covers most of it. Time the problem was first noticed, who noticed it, what they had clicked or opened, what was disconnected and when, who was called, and what each person was told. A legal pad works. So does a phone note, provided it is not stored on the system in question.

What the Plan Looks Like on Paper

It should be short. An incident response plan for Montgomery County businesses that runs 40 pages will not be opened during an actual incident. One or two printed pages, kept off the network, will.

  • Named people for each role, not job titles
  • After-hours numbers for every vendor, carrier, and adviser
  • The first three containment steps, in order
  • Where backups live and who is authorized to restore them
  • A short list of systems that hold regulated data
  • Who owns the notification timeline and where the deadlines are recorded

Keep a copy at home or in a glove box. Incidents have an unhelpful habit of starting outside business hours, and the office may be exactly where you cannot get to your files.

A Plan You Have Never Run Is Only a Draft

Reading a document is not the same as using one. A 30-minute tabletop exercise, run twice a year, exposes more gaps than any checklist review. Someone reads a scenario aloud, everyone walks through their part, and the missing phone numbers reveal themselves in the first five minutes.

Small offices tend to discover the same three things. The after-hours number routes to a queue. Two people each assume the other one calls the insurer. Nobody has been designated to talk to clients, which means everyone talks to clients.

The fix for each is a sentence in a document, not a project. That is what makes this worth doing during a quiet week rather than a loud one.

The human element was present in 45 percent of small and mid-sized business breaches last year. A rehearsed plan will not eliminate mistakes. It shortens the distance between the mistake and the response, and in Maryland that distance is measured against a statutory clock that started the moment you found out.

Sources

  • Verizon, 2026 Data Breach Investigations Report Executive Summary
  • U.S. Department of Health and Human Services, Breach Notification Rule
  • Office of the Attorney General of Maryland, Guidelines for Businesses to Comply with the Maryland Personal Information Protection Act