Capability 05
Incident & Breach Response Readiness
When you discover a breach, a clock starts: regulators, clients, and your insurer all want answers, and the first hours decide how bad it gets. We get you ready before that day, with a plan your team has rehearsed, scenario playbooks for what actually hits firms like yours, and a number to call when it's real. When it happens, we run the response and bring in the right people, so you're making decisions instead of scrambling.
When to engage
Your cyber-insurance application asks if you have a written, tested incident response plan, and you're not sure your answer is true.
A client's security questionnaire wants your incident response plan before they'll renew.
A breach at a firm like yours made you realize you don't know who you'd call first.
You have a plan on paper, but no one has ever run it, and no one's sure who decides what when it's real.
How it works
We start with a tabletop: your team works through a realistic ransomware or fraud scenario while we watch where it snags and who hesitates. From what surfaces, we write the plan and the scenario playbooks, set up a contact tree that still works when email is down, and map your notification deadlines so you know the clock before it starts. Keep us on retainer and we're the number you call when it's real: we lead the response and bring in the specialists, your counsel, your insurer, and the regulators, so the right things happen in the right order.
What you receive
- A written incident response plan: who decides what, who has the authority to pull the plug, and who gets called in what order.
- Scenario playbooks for the incidents that actually hit firms like yours: ransomware, wire fraud and business email compromise, stolen data.
- A contact and escalation tree that still works when your email and systems are down.
- A tested tabletop exercise, with a short written summary of what to fix before it's real.
- If you retain us: a known team to call when something happens, with the terms already signed so you're not negotiating a contract mid-crisis.
Timeframe
A tabletop is a focused session. A full readiness plan comes together in weeks. A retainer is an ongoing relationship you can lean on.
Ways to work together
Tabletop exercise
A focused session
- Scope
- One realistic scenario, run with your team
- What you get
- A written readiness summary and a fix-it list
- Best for
- A first step, or an insurer or client asking
Readiness package
A few weeks
- Scope
- The plan, the scenario playbooks, the contact tree, and a tabletop
- What you get
- A complete, rehearsed plan you can hand to an insurer or regulator
- Best for
- Most firms that want a plan they could actually run
Response retainer
Ongoing
- Scope
- The readiness package, plus a team on call with terms pre-signed
- What you get
- A known number to call when it's real, and time that converts to tabletops and reviews when it's quiet
- Best for
- Firms that want someone on call, not just a plan on a shelf
Who does the work
Your response is led by people who've stood in the room during real breaches as CISOs and CTOs, made the call on what to disconnect, and managed the lawyers, forensics specialists, and regulators while the clock ran. When it's your turn, you want someone who has done it before holding the plan.