Incident Response & Readiness
Getting ready for the incident before it happens, and steadying the response when it does.
Most incident response plans are written to satisfy a control requirement and are never opened again. They describe a process in the abstract, list some contact details that went stale two reorganisations ago, and offer no help with the decisions that actually consume the first few hours. Those decisions are rarely technical. They are business decisions taken under pressure with incomplete information: do we take the platform offline, do we pay, what do we tell customers, and when does this become notifiable.
So the preparation worth doing rehearses decisions rather than steps. Clear decision rights agreed in advance, including who can authorise disruptive action out of hours and what happens when that person cannot be reached. Communications drafted before they are needed, because nobody writes well at three in the morning. A shared understanding of the notification thresholds under the Privacy Act 2020 and any sector obligations, worked out calmly rather than argued about during the event.
Tabletop exercises are where this becomes real, and a good one is uncomfortable. It should surface the disagreement about who decides, the dependency nobody had documented, and the backup restoration nobody has actually tested. Afterwards, a post-incident review that changes something: the point is not a document recording that an incident occurred, but a small number of specific changes that make the next one less damaging.
You might need this if
- The incident response plan exists and has never been tested
- Nobody is certain who can authorise taking production offline
- There is no agreed approach for telling customers or the regulator
- A previous incident produced a report and no lasting change
- Your backup restoration has not been proven end to end recently
Who it's for
Organisations that want confidence their incident response will hold up under real pressure, not just on paper.
How the engagement runs
- 01
Readiness assessment
Review the current plan, decision rights, escalation paths, and dependencies against what an incident would actually demand, including the parts that only fail under time pressure.
- 02
Plan and playbooks
A usable plan with scenario playbooks for the incidents you are realistically exposed to, clear roles, and communications templates drafted before anyone needs them.
- 03
Tabletop exercise
Rehearse the decisions with the people who would actually make them, executives included. The exercise is designed to find disagreement while it is still cheap to resolve.
- 04
Post-incident review and uplift
After an exercise or a real event, a review that produces a short list of specific changes with owners, rather than a narrative that gets filed.
What's delivered
- A tested incident-response plan, not a document nobody has opened
- Tabletop exercises that rehearse the decisions, not just the steps
- Clear roles, escalation paths, and communications templates
- Post-incident reviews that turn a bad day into a stronger posture
- An experienced hand on call when it matters most
Proof point
Designed incident response into Security Operations Centres built from the ground up, so the plan works when it is needed.
Common questions
- Do you provide round-the-clock emergency response?
- I am not a 24/7 digital forensics firm and will not pretend otherwise. What I provide is the preparation beforehand and an experienced hand during: helping you run the response, make the calls, and manage the communications, working alongside specialist forensic responders where deep technical investigation is required.
- Should we have a retainer with a forensics provider?
- If an extended outage would be existential, yes. The value is less the discounted rate than having the contract, the scoping, and the contacts already settled, so you are not negotiating terms on day one of an incident. Your insurer may also have a panel worth checking before you sign anything.
- How do we know whether an incident is notifiable?
- Under the Privacy Act 2020 the test is whether the breach has caused or is likely to cause serious harm, and sector obligations may add to that. The mistake is leaving the assessment until it is needed. Agreeing the criteria and who applies them in advance turns a panicked legal question into a decision someone is ready to make.
- How often should we exercise?
- At least annually, and after any significant change to the environment or the leadership team. Exercises decay quickly, mostly because the people change, and a plan rehearsed by a team that has since turned over is not really rehearsed.
Other services
- Risk Management & Quantitative Risk Analysis
- Digital, Cyber & Technology Risk
- Third-party & Supply Chain Risk
- AI Security, Risk & Governance
- Applied AI for Cyber
- Security Operations
- Governance, Risk & Compliance
- Data Governance & Privacy
- Secure Architecture & Zero Trust
- Secure Web Applications for SMEs
- Virtual CISO & Security Leadership
Let's talk about your security programme
Considering a vCISO, a security strategy and architecture, a SOC uplift, an AI assurance review, or a secure web build? Tell me where you are and where you need to get to.