A CSIRT on call. When you are breached, one team takes the technical response, the crisis room and the legal exposure until you are clean and trading again.
Stop the breach, prove the environment is clean and get the organisation trading again, while the same team runs the crisis room and the legal exposure. Called incident response, CERT or CSIRT depending on who you ask, it covers ransomware and extortion, data theft, malware, denial of service, business email compromise, account and brand takeover, and insider misconduct. One number to call, one commander, and a report at the end that a board, an insurer and a regulator can each rely on.
The plan follows our delivery framework. Steps that do not apply to this kind of work are left out rather than padded.
Retained clients get a named responder and an agreed callout time. We take emergency calls without a retainer, but mobilising takes longer and costs more, and the first hours are the ones that decide the rest.
What you keep at the end.
What it is built to change.