Incident readiness covers the plan, the people, and the proof that they work together. Three services sit under this core. Incident Response Planning & Readiness builds or rewrites the policy, plan, playbooks, severity matrix, and notification decision tree against recognized incident response guidance. Executive Tabletop Exercises put leadership through the decisions an incident forces: activation, ransom posture, counsel and insurer engagement, and disclosure clocks. Technical Tabletop Exercises walk responders through detection, containment, eradication, and recovery on a scenario built from your own environment, whether on-premises, cloud, or hybrid. Most clients start with the plan, then test it with one exercise per audience on a shared scenario. The same principal reviews your documents, writes the scenario, facilitates the session, and writes the after-action report. Exercise findings land as redlines in the plan, not in a slide deck. Nothing here touches production. Readiness is documentation, discussion, and evidence, not incident handling on your behalf.
A GOOD FIT WHEN
For CISOs, CIOs, general counsel, and compliance leads who own the response when something goes wrong. You need to show a board, insurer, customer, or assessor that the plan exists and has been exercised. Common triggers: a cyber insurance renewal, a new defense contractor or PCI DSS obligation, a near miss, or the first time an executive asks what happens if ransomware hits.
THE WORK BEHIND THE SERVICE
What we do. What you can use.
01
Scope the plan and the scenario
We start with your existing incident response policy, plan, playbooks, insurance policy, monitoring provider contracts, and every reporting clause in play. Then we agree in writing which documents we build, which audience we exercise, and which scenario we run. You choose what is recorded and who receives the after-action report.
02
Build and facilitate by hand
The principal interviews stakeholders, drafts each artifact against recognized incident response guidance, and writes the scenario and timed prompts for each exercise. Sessions are discussion-based and run without keyboards or production access. Participants say what they would do, and we record where the plan, the tooling, and the people diverge.
03
Report, redline, and retest
You receive the finished documents, an after-action report and improvement plan with corrective actions assigned to owners and dates, and redlines to the plan and templates. Once corrections land, we re-run the affected module or walkthrough and record the result as evidence for insurers, customers, and assessors.
A facilitated, scenario-driven exercise that puts leadership through the decisions a serious incident forces, then records what has to change.
Scenario selection from your actual exposure: ransomware with data theft, business email compromise and wire fraud, cloud account compromise, or vendor breach
Scenario script with three to five modules, timed injects, facilitator guide, and an evaluator sheet per objective
Decision points on activation, severity declaration, and engaging the breach coach and forensic retainer through counsel