Your Cyberattack Plan Cannot Live Inside the System That Just Went Down

by | Jul 25, 2026 | AI Knowledge Hub for Nonprofits, nonprofit

When a nonprofit experiences ransomware, account takeover or another cyberattack, employees immediately need reliable instructions.

They need to know who has authority to isolate systems, contact vendors, preserve evidence, notify leadership and communicate with employees, participants or donors. Yet many organizations keep those instructions in the same email, cloud storage or network environment that may become unavailable during the incident.

A response plan that cannot be accessed during an attack is not a usable plan.

Build One Trusted Response Source

Cybersecurity procedures are often scattered across IT tickets, insurance documents, vendor contracts, employee handbooks and personal contact lists. Different departments may also hold conflicting versions.

The nonprofit should document:

  • Who declares a cyber incident
  • Internal and external response contacts
  • Cyber insurance notification procedures
  • Technology vendor escalation paths
  • Steps for isolating affected accounts or devices
  • Backup communication methods
  • Legal and regulatory review responsibilities
  • Evidence-preservation procedures
  • Approved public communication roles
  • Recovery priorities
  • Password-reset and access-restoration procedures
  • Post-incident review requirements

CISA recommends maintaining and regularly exercising an incident-response plan and a communications plan covering ransomware and data-extortion events. Its StopRansomware Guide provides practical preparation and response guidance.

NIST’s current incident-response recommendations treat preparation, response and recovery as parts of broader cybersecurity risk management rather than a document created only after an attack. (NIST CSRC)

Keep an Offline or Independent Copy

SharePoint should serve as the organized knowledge source during normal operations. It can contain approved response procedures, blank incident forms, role assignments, vendor information and training materials.

However, essential contact lists and first-response instructions should also be available through a protected offline or independently accessible method. Employees should not assume Microsoft 365, email, Teams or the organization’s network will remain available.

The backup copy must be controlled carefully. It should not expose passwords, private keys, recovery codes or detailed security information to unauthorized employees.

Use AI Before and After the Attack—Not as the Incident Commander

Copilot Studio provides the conversational AI layer. Through Maisy, authorized employees might ask during normal operations:

  • Who handles a suspected phishing incident?
  • Where is the cyber insurance policy?
  • Which vendor manages our Microsoft tenant?
  • What information must be preserved?
  • Who approves external communications?
  • When was the response plan last tested?

Microsoft states that a Copilot Studio agent using SharePoint can surface only content the authenticated user already has permission to access. SharePoint access can also be limited through Microsoft 365 and Entra security groups. (Microsoft Learn)

Maisy should not decide whether to pay a ransom, determine whether a breach notification is legally required or direct forensic activity. Those decisions require leadership, legal counsel, cybersecurity professionals, insurers and law enforcement when appropriate.

Security platforms remain authoritative for technical alerts. Signed insurance policies remain authoritative for coverage. Incident records should remain in the approved secured system.

How Maisy Helps

Pixeldust begins by identifying repeated security questions, critical vendors, response roles, authoritative procedures and gaps in backup access.

Pixeldust then resolves conflicting documents, assigns content owners, reviews permissions and organizes approved guidance in SharePoint. Maisy is configured through Copilot Studio and tested with realistic scenarios before an actual incident occurs.

This helps the nonprofit retain institutional knowledge about cybersecurity response while ensuring that human experts—and an accessible backup plan—remain in control when systems fail.

Pixeldust IT Contract Risk Review Icon

Free Assessment

Complete the form below, and let's talk about how we can help preserve your organizational knowledge and make it easier for your team to find the answers they need.

Name(Required)

Free Guide: The Knowledge Capture Playbook

A practical system for extracting critical knowledge from employees, documents, workflows and real operational cases. This white paper includes prioritization scoring, interview scripts, workshop agendas, capture templates, evidence standards, validation controls, performance metrics and a 30/60/90-day rollout plan.

Download The Free PDF Guide

The Intelligence Compound: A New Operating Model for AI in Small Business

The Intelligence Compound presents a practical framework for implementing AI in small business. Rather than treating AI as a collection of isolated productivity tools, the paper explains how businesses can use it to preserve knowledge, support decisions, reduce owner dependency, identify operational problems, and improve processes over time. It includes original use cases, governance principles, real-world examples, and a 90-day implementation roadmap.

Download Whitepaper PDF