Proposal
Crisis management and incident response
We write the response plan and the playbooks by incident type, set out who decides what and build the communications: internally, to your customers, to the regulator and, where it applies, to the press. Then we train the crisis committee, because a plan nobody has rehearsed becomes forgotten paper at the moment it matters most. Anyone who wants more assurance adds the on-call arrangement and has our team standing by.
No price appears on this page. Scope does: what we do, how we run it, who runs it and what is not included. The people who read your request are the ones who will look after you, and they come back with the proposal and with time to talk it through.
Crisis management and incident response
Who decides what when the phone rings at three in the morning.
How we run it
What this work consists of
We prepare the company for the day something blows up. We write the incident response plan, from the first alert to closure, the playbooks for each incident type, and the crisis committee protocol, which defines who convenes, who decides, and who speaks. The communication matrix completes the set: what to say internally, to customers, to regulators, and, when it comes to that, to the press.
We start by comparing what already exists against what needs to exist and talking with the people who will make the calls in a real crisis. That conversation is what produces a protocol that works: who authorizes shutting down a system, who talks to the major customer, who wakes up the CEO. A document written without those answers becomes forgotten paper at the moment it matters most.
The service tiers change how much preparation is in place beforehand: documents only, documents plus a trained committee and the first exercise run by us, or all of that with our team on call for the duration of the contract, already familiar with your environment and your plan when the phone rings.
On your side, we need access to the people who will fill the committee roles, to the contacts that go into the communication matrix, and to whoever knows the technical environment. You receive documents with defined owners and, in the tiers with training, a committee that has already made its mistakes once in a safe environment.
How we conduct it, stage by stage
Interviews
We talk to IT, to security and to the business areas. Documents say what should happen; interviews say what does.
Gap assessment
We compare what exists today with what the reference requires, item by item, and classify each gap by risk and by effort to fix. The result comes out in order of attack: what to do first and why, instead of an inventory of everything that is wrong.
Writing the plans
We write the plans in the format someone will use on the worst day of the year: direct, with steps and phone numbers.
Exercise
We put people in the situation and run it. What fails here is what would have failed for real.
What is not included
- Forensic investigation of the incident, which is a separate service and comes in when needed
- Negotiating with attackers, which we do not do and advise against
- Press relations, which stays with your communications agency: the matrix defines who speaks, it does not write the press release
- Real-time monitoring of the environment, which is security operations and a different service
- The legal opinion on notifying regulators or data subjects: the matrix defines who engages legal, and the legal decision belongs to them or to outside counsel
- Technical rebuilding of the environment after the incident, which is executed by your team or the provider
- Filing and negotiating the cyber insurance claim, which stays with your legal team and the broker
- Recurring exercises throughout the year, which belong to the testing and simulation service; here you get the first one, in the tiers that include it
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.