INCIDENT RESPONSE & DISASTER RECOVERY

Prepare your organization for cyber incidents before they happen: response retainer readiness, playbooks, and tabletop simulation exercises.

Best suited forDuring active ransomware, business-email compromise, data exposure or cloud incidents
Primary outcomeIncident-management cadence, roles and a single situation overview
ScopeCustom Incident Response Playbook development (Ransomware, BEC, Data Exfiltration)
Typical timingTiming depends on the number of systems, roles, environments, available documentation and agreed constraints.

Is this right for you?

When to choose this service

During active ransomware, business-email compromise, data exposure or cloud incidentsOrganisations wanting a retainer and agreed activation process before an incidentAfter a suspicious signal when the internal team cannot establish compromise scopeBefore a regulatory incident exercise or cyber-insurance renewal

Incident Readiness Services

  • Custom Incident Response Playbook development (Ransomware, BEC, Data Exfiltration)
  • Executive Tabletop Simulation Exercises testing board decision-making under crisis
  • Digital Forensics and Incident Response (DFIR) retainer integration
  • Statutory reporting workflow alignment with NIS2 and DORA deadlines (24h / 72h notifications)

What you receive

  • Incident-management cadence, roles and a single situation overview
  • Confirmed incident scope and list of affected assets
  • Timeline of attacker activity and material evidence
  • Containment and recovery plan aligned with business priorities
  • Digital-forensics notes and evidence register
  • Summary suitable for leadership, legal, insurer and regulator communication
  • Post-incident report with causes, control gaps, owners and deadlines

Delivery flow

From scope to a verified result

  1. Scope and safety boundaries. Confirm the objective, systems, roles, environment, exclusions, authorised actions and emergency stop contact.

  2. Information and access. Receive only the documentation, accounts, configuration or evidence needed for the work through a secure channel.

  3. Digital Forensics & Incident Response (DFIR). We isolate compromised systems, perform root-cause analysis, and contain active cyber threats.

  4. Validation and reporting. Confirm findings, remove false positives and connect each risk to business impact and an accountable owner.

  5. Workshop and follow-through. Explain priorities, answer delivery teams, agree remediation timing and perform a retest where included.

Before we start

Frequently asked questions

How long does an engagement usually take?

Timing depends on the number of systems, roles, environments, available documentation and agreed constraints. After initial information is received, the scope states the stages, customer involvement and a specific schedule.

What should we prepare before work starts?

Usually we need a system or process owner, current scope, access and test accounts, architecture or process information, critical business scenarios and an emergency contact. Never send passwords through a normal website form.

Will we receive only a technical report?

No. The standard output includes an executive summary, prioritised detail, evidence, remediation guidance and a results workshop. Where relevant, the engagement includes a retest or implementation roadmap.

What should we do in the first hour after detecting an incident?

Activate an incident lead, preserve time and evidence, isolate only when the side effects are understood, and avoid mass restarts or log deletion. Use a separate secure communication channel and record decisions.

Do you guarantee a specific response time?

Only where a signed retainer defines availability, activation process, language, geography and dependencies. Retainer contracts define an SLA that the contract and team capacity cannot support.

Related next steps