← Solutions
CyberPopular

Incident response readiness

An incident response plan your people have rehearsed, with ransomware playbooks, decision rights and a tested tabletop exercise.

Typical timing
4–6 weeks
Engagement
Fixed scope
Delivery framework
User researchDiscoveryAlphaBetaLive

Make sure that when a serious incident happens — ransomware, data breach, business email compromise — the organisation knows who decides what, how to contain it, when to notify regulators and customers, and how to recover, because it has practised.

  • No incident response plan, or one nobody has read
  • Leadership has never rehearsed a cyber crisis
  • Uncertainty about regulatory notification deadlines
How it runs

Activities, step by step

The plan follows our delivery framework. Steps that do not apply to this kind of work are left out rather than padded.

  1. 02 · Discovery1–2 weeks

    Assess readiness

    • Existing plans, contracts, insurance and logging reviewed
    • Notification obligations mapped: ICO, sector regulators, customers
    • Scenarios chosen from your threat profile
  2. 03 · Alpha2 weeks

    Plan and playbooks

    • Incident response plan with roles and decision rights
    • Playbooks for ransomware, data breach and account compromise
    • Communications templates and contact tree
  3. 04 · Beta1 week

    Exercise

    • Technical tabletop with IT and security teams
    • Executive crisis simulation
    • Lessons learned and plan updated
  4. 05 · LiveAnnual

    Stay ready

    • Annual exercise with a new scenario
    • Plan reviewed after every real incident

Deliverables

What you keep at the end.

  • Incident response plan
  • Scenario playbooks and communications templates
  • Tabletop exercise report
  • Readiness improvement plan

Outcomes

What it is built to change.

  • Faster, calmer decisions in a real incident
  • Regulatory deadlines met
  • Lower impact and recovery cost