Opulence.
Cybersecurity

Incident Response Readiness & Retainer

An incident response plan, rehearsed with tabletop exercises, and an on-call retainer for when it happens.

The first hour of an incident decides how bad it gets. Organisations with a plan, a rehearsed team and a number to call contain incidents in hours. Those without spend days improvising. We build the plan, run the rehearsal and stand behind the number.

The retainer gives you priority access to responders with pre-agreed terms, so there is no procurement conversation while systems are encrypted.

How we're different
  • The plan is written to be used at two in the morning, short and specific.
  • Retainer hours not used for incidents can be spent on readiness work, so nothing is wasted.
  • Responders work alongside our MDR and IT teams, so containment and recovery happen together.
Who this is for
  • A bank, airline or logistics operator where an hour of downtime is a board-level event.
  • A group whose cyber insurer requires a named response provider.
  • A company that has had one incident, improvised through it and does not want to do that again.
Signals you need this now
  • The incident plan is a policy document nobody has opened under pressure.
  • Nobody knows who can authorise shutting down a system.
  • Logs needed for an investigation are not retained long enough.
  • Regulatory notification deadlines are known to legal and unknown to IT.
Scope of work

What is included.

  1. 01

    Readiness assessment

    Current plans, logging, backups and contacts reviewed against what an incident would demand.

  2. 02

    Incident response plan

    Roles, escalation, decision authority, communication templates and legal and regulatory steps.

  3. 03

    Tabletop exercise

    A facilitated scenario with the leadership and technical teams, with findings captured.

  4. 04

    Retainer

    Pre-agreed hours, response times and terms for live incident support.

  5. 05

    Live response

    Triage, containment, forensics, recovery support and reporting when an incident occurs.

Method

Four steps, no surprises.

  1. 01

    Assess

    Readiness review of plans, evidence sources and recovery capability.

  2. 02

    Plan

    Incident response plan and playbooks for likely scenarios.

  3. 03

    Rehearse

    Tabletop exercise with lessons fed back into the plan.

  4. 04

    Stand by

    Retainer in place with contacts, terms and regular check-ins.

How the engagement runs

From first meeting to steady state.

  1. 01Weeks 1 to 2

    Assess

    Current plans, logging, backups and contacts reviewed against what an incident would demand.

  2. 02Weeks 3 to 5

    Plan

    Incident response plan, playbooks for likely scenarios and communication templates written with legal and communications.

  3. 03Weeks 6 to 8

    Rehearse

    Tabletop exercise with leadership and technical teams, with lessons fed back into the plan.

  4. 04Ongoing

    Stand by

    Retainer in place with contacts, terms, regular check-ins and readiness work from unused hours.

What we measure
  • Time from detection to containment in exercises and in live incidents.
  • Decisions made within the plan rather than escalated ad hoc during the tabletop.
  • Readiness gaps closed after each exercise.
  • Regulatory notifications made within the required window.
Who is on the engagement
  • Incident response lead
  • Digital forensics analyst
  • Crisis communications adviser
  • Engagement director
Deliverables
  • Readiness assessment report.
  • Incident response plan and playbooks.
  • Tabletop exercise report.
  • Retainer agreement with SLA.
  • Post-incident reports when activated.
Engagement terms

Readiness work is fixed scope and takes four to eight weeks including the tabletop exercise. The retainer is an annual agreement with a block of hours and defined response times. Emergency response without a retainer is available subject to capacity.

FAQ

Incident Response Readiness & Retainer, in plain terms.

Anything that threatens confidentiality, integrity or availability of your systems or data: ransomware, business email compromise, data breaches and insider events among others.

Retainer clients get a response within the agreed time, usually within the hour, with remote containment starting immediately.

We support it. The plan includes the timelines and templates, and we work with your legal counsel on the submissions.

Insurance pays for response. A retainer makes sure the responders know your environment before the incident. Many insurers accept or require a named provider.

Next step

Ready to talk about incident response readiness & retainer?