Incident Response
During an incident, the difference between a bad week and a bad year is whether someone technical is coordinating.
The problem
Why this keeps happening.
Incidents don't announce themselves cleanly. They start as a strange email, a locked file share, or a bank call about a payment nobody authorized.
What follows is usually parallel chaos: the MSP is investigating, the insurer wants notice, counsel wants privilege, staff want to know if they can work, and no one is writing anything down.
The organizations that come through it well are not the ones with the best tools. They are the ones where someone owned the sequence.
What we do
Capabilities.
- Incident response plan written for your systems, staff, and vendors
- Roles, escalation paths, and contact tree — including after hours
- Tabletop exercises with leadership, IT, and operations
- Coordination during an active incident across MSP, forensics, counsel, and carrier
- Evidence preservation and timeline documentation
- Business continuity decisions: what stays down, what comes back first
- Recovery sequencing and validation before systems return to service
- Breach notification support and regulator or client communication coordination
- Post-incident review with a concrete remediation plan
- Cyber insurance claim documentation support
Outcomes
What you end up with.
A plan that fits on a page
Who to call, in what order, with what authority — usable at 2 a.m. by someone who didn't write it.
One coordinator
A single technically fluent point of contact managing vendors, counsel, and the carrier while you run the business.
A documented recovery
A defensible timeline and evidence trail that supports the insurance claim and the client conversation.
Signs you need this.
- You have no written incident response plan
- You've never run a tabletop exercise
- You had an incident and still don't have a written timeline
- Nobody knows who declares an incident, or who can authorize downtime
- Your cyber policy requires notice within hours and you'd miss it
Start with an assessment.
Two to four weeks, fixed fee. You end up with a current-state picture, a risk register, and a prioritized roadmap — whether or not you work with us after that.
Book a Technology Assessment
