Incident Response Readiness & Retainer
An incident response plan, rehearsed with tabletop exercises, and an on-call retainer for when it happens.
The first hour of an incident decides how bad it gets. Organisations with a plan, a rehearsed team and a number to call contain incidents in hours. Those without spend days improvising. We build the plan, run the rehearsal and stand behind the number.
The retainer gives you priority access to responders with pre-agreed terms, so there is no procurement conversation while systems are encrypted.
- The plan is written to be used at two in the morning, short and specific.
- Retainer hours not used for incidents can be spent on readiness work, so nothing is wasted.
- Responders work alongside our MDR and IT teams, so containment and recovery happen together.
- A bank, airline or logistics operator where an hour of downtime is a board-level event.
- A group whose cyber insurer requires a named response provider.
- A company that has had one incident, improvised through it and does not want to do that again.
- The incident plan is a policy document nobody has opened under pressure.
- Nobody knows who can authorise shutting down a system.
- Logs needed for an investigation are not retained long enough.
- Regulatory notification deadlines are known to legal and unknown to IT.
What is included.
- 01
Readiness assessment
Current plans, logging, backups and contacts reviewed against what an incident would demand.
- 02
Incident response plan
Roles, escalation, decision authority, communication templates and legal and regulatory steps.
- 03
Tabletop exercise
A facilitated scenario with the leadership and technical teams, with findings captured.
- 04
Retainer
Pre-agreed hours, response times and terms for live incident support.
- 05
Live response
Triage, containment, forensics, recovery support and reporting when an incident occurs.
Four steps, no surprises.
- 01
Assess
Readiness review of plans, evidence sources and recovery capability.
- 02
Plan
Incident response plan and playbooks for likely scenarios.
- 03
Rehearse
Tabletop exercise with lessons fed back into the plan.
- 04
Stand by
Retainer in place with contacts, terms and regular check-ins.
From first meeting to steady state.
- 01Weeks 1 to 2
Assess
Current plans, logging, backups and contacts reviewed against what an incident would demand.
- 02Weeks 3 to 5
Plan
Incident response plan, playbooks for likely scenarios and communication templates written with legal and communications.
- 03Weeks 6 to 8
Rehearse
Tabletop exercise with leadership and technical teams, with lessons fed back into the plan.
- 04Ongoing
Stand by
Retainer in place with contacts, terms, regular check-ins and readiness work from unused hours.
- Time from detection to containment in exercises and in live incidents.
- Decisions made within the plan rather than escalated ad hoc during the tabletop.
- Readiness gaps closed after each exercise.
- Regulatory notifications made within the required window.
- Incident response lead
- Digital forensics analyst
- Crisis communications adviser
- Engagement director
- Readiness assessment report.
- Incident response plan and playbooks.
- Tabletop exercise report.
- Retainer agreement with SLA.
- Post-incident reports when activated.
Readiness work is fixed scope and takes four to eight weeks including the tabletop exercise. The retainer is an annual agreement with a block of hours and defined response times. Emergency response without a retainer is available subject to capacity.
Compliance & Business Continuity
GDPR, ISO 27001 and NIS2 readiness with backup and disaster recovery plans that have been tested.
CybersecurityManaged Detection & Response (MDR/XDR)
Continuous monitoring, alert triage and response across endpoints, identity and cloud.
CybersecurityRed Team & Social Engineering
Objective-based adversary emulation including phishing and physical scenarios, measured against your defences.
Incident Response Readiness & Retainer, in plain terms.
Anything that threatens confidentiality, integrity or availability of your systems or data: ransomware, business email compromise, data breaches and insider events among others.
Retainer clients get a response within the agreed time, usually within the hour, with remote containment starting immediately.
We support it. The plan includes the timelines and templates, and we work with your legal counsel on the submissions.
Insurance pays for response. A retainer makes sure the responders know your environment before the incident. Many insurers accept or require a named provider.