vCISO & Advisory / CORE SERVICE

Incident Readiness

Incident response planning, playbooks, and executive and technical tabletop exercises to test decisions, response roles, and recovery readiness.

THE WORK, IN CONTEXT

Incident Readiness, with a clear purpose.

Incident readiness covers the plan, the people, and the proof that they work together. Three services sit under this core. Incident Response Planning & Readiness builds or rewrites the policy, plan, playbooks, severity matrix, and notification decision tree against recognized incident response guidance. Executive Tabletop Exercises put leadership through the decisions an incident forces: activation, ransom posture, counsel and insurer engagement, and disclosure clocks. Technical Tabletop Exercises walk responders through detection, containment, eradication, and recovery on a scenario built from your own environment, whether on-premises, cloud, or hybrid. Most clients start with the plan, then test it with one exercise per audience on a shared scenario. The same principal reviews your documents, writes the scenario, facilitates the session, and writes the after-action report. Exercise findings land as redlines in the plan, not in a slide deck. Nothing here touches production. Readiness is documentation, discussion, and evidence, not incident handling on your behalf.

A GOOD FIT WHEN

For CISOs, CIOs, general counsel, and compliance leads who own the response when something goes wrong. You need to show a board, insurer, customer, or assessor that the plan exists and has been exercised. Common triggers: a cyber insurance renewal, a new defense contractor or PCI DSS obligation, a near miss, or the first time an executive asks what happens if ransomware hits.

THE WORK BEHIND THE SERVICE

What we do.
What you can use.

Scope the plan and the scenario

We start with your existing incident response policy, plan, playbooks, insurance policy, monitoring provider contracts, and every reporting clause in play. Then we agree in writing which documents we build, which audience we exercise, and which scenario we run. You choose what is recorded and who receives the after-action report.

Build and facilitate by hand

The principal interviews stakeholders, drafts each artifact against recognized incident response guidance, and writes the scenario and timed prompts for each exercise. Sessions are discussion-based and run without keyboards or production access. Participants say what they would do, and we record where the plan, the tooling, and the people diverge.

Report, redline, and retest

You receive the finished documents, an after-action report and improvement plan with corrective actions assigned to owners and dates, and redlines to the plan and templates. Once corrections land, we re-run the affected module or walkthrough and record the result as evidence for insurers, customers, and assessors.

FIND YOUR FOCUS

Specific services.
Substantive answers.

01 / Incident Readiness

Incident Response Planning & Readiness

An incident response policy, plan, playbooks, and notification decision tree written for your organization and proven in a walkthrough.

  • Review of the incident response policy, plan, playbooks, continuity plans, insurance policy, and monitoring provider contracts
  • Interviews with security, IT, legal, privacy, communications, HR, finance, and the executive sponsor
  • Inventory of every reporting obligation in play across defense contracts, PCI DSS, HIPAA, securities and state regulators, and customer contracts

From $6,000

Scope, pricing & FAQs
02 / Incident Readiness

Executive Tabletop Exercises

A facilitated, scenario-driven exercise that puts leadership through the decisions a serious incident forces, then records what has to change.

  • Scenario selection from your actual exposure: ransomware with data theft, business email compromise and wire fraud, cloud account compromise, or vendor breach
  • Scenario script with three to five modules, timed injects, facilitator guide, and an evaluator sheet per objective
  • Decision points on activation, severity declaration, and engaging the breach coach and forensic retainer through counsel

From $3,000

Scope, pricing & FAQs
03 / Incident Readiness

Technical Tabletop Exercises

A response-team walkthrough of detection, scoping, containment, eradication, and recovery on a scenario built around your own systems and logs.

  • Technical scenario with alert text, log excerpts, access-policy changes, app authorizations, and an extortion note
  • Detection and triage: which alert fired, who saw it, how it was escalated, and to whom
  • Scoping and evidence preservation: tracing activity, finding persistence, reviewing audit logs, capturing memory and disk, chain of custody

From $4,200

Scope, pricing & FAQs
WHAT YOU TAKE FORWARD

Built to support the next decision.

  • Incident response policy, plan, and per-scenario playbooks aligned to recognized incident response guidance
  • Severity matrix and notification decision tree naming who decides, who is told, and which clocks start
  • Scenario script, inject timeline, and facilitator guide for each exercise, reusable for future sessions
  • After-Action Report and Improvement Plan with corrective actions, owners, and due dates
  • Walkthrough or re-run record confirming corrections were made, packaged for insurers, customers, and assessors

The selected services, deliverables, access requirements, and any follow-up validation are agreed in your engagement scope.

INFORMED BY RECOGNIZED GUIDANCE
START AT THE SOURCE

Let’s find your next move.

A focused conversation. A clear scope. A practical path to stronger security.

Let’s talk security