Incident Readiness / FOCUSED SERVICE

Incident Response Planning & Readiness

An incident response policy, plan, playbooks, and notification decision tree written for your organization and proven in a walkthrough.

WHAT THIS SERVICE ADDRESSES

The challenge behind the engagement.

This service replaces a template with a plan that names your people, systems, and deadlines. We review your incident response policy, plan, playbooks, insurance policy, monitoring provider contracts, and every reporting clause you carry. Then we interview security, IT, legal, communications, and finance to find where process and practice diverge. We write a policy and a plan with defined roles and a severity matrix tied to business impact, data sensitivity, and recovery difficulty. Playbooks cover ransomware, business email compromise, credential compromise, cloud account compromise, and third-party compromise, aligned to recognized incident response guidance. A notification decision tree records which facts start which counsel-led analysis. You receive the documents, a gap register with owners, and a walkthrough record. We are not your forensic retainer or counsel; the plan names who is.

WHEN THIS IS THE RIGHT FIT

For organizations whose plan is a template, is years old, or lives in the head of one IT manager. Typical triggers: a cyber insurance application asking for a tested plan, a new defense contractor or PCI DSS obligation, or the first ransomware near miss.

THE WORK BEHIND THE SERVICE

What we do.
What you can use.

Collect documents and interview owners

We gather the policy, plan, playbooks, business continuity and disaster recovery plans, insurance policy with its panel and prior-consent clauses, monitoring provider contracts, logging and retention inventory, and prior incident records. Each stakeholder then sits for a 45 to 60 minute interview. We need read access to describe your detection setup, never to operate it.

Write the plan, matrix, and playbooks

Each artifact is drafted against recognized incident response guidance: the policy, the plan with defined roles and activation criteria, and a severity matrix tying each level to who is notified and which clocks start. Per-incident playbooks carry containment steps for the identity and cloud platforms you run. An evidence-handling runbook and clear recovery priorities round out the set.

Walk through and set the cadence

We walk the finished plan with your team scenario by scenario, correct what breaks, and record the session. You leave with a gap register naming owners and a review cadence that lines up with the annual testing that PCI DSS and consumer data regulators expect. The walkthrough record is the bridge to the executive and technical tabletops.

IS THIS THE RIGHT ENGAGEMENT?

Who it’s for.
When you need it.

BEST SUITED FOR
  • Organizations whose incident response plan is a template, years old, or owned by one person
  • Regulated businesses carrying reporting duties across several agencies, customers, and contracts at once
  • Companies that outsource monitoring to an MSP or MDR but still own the decisions
  • Security or IT leaders asked to show an insurer or board a tested plan
WHEN IT’S TIME TO ENGAGE
  • A cyber insurance application or renewal asks whether the plan has been tested
  • A new defense contract, PCI DSS, or state reporting obligation now applies
  • A near miss or a peer breach exposes how thin the current plan is
  • A merger, new business line, or infrastructure change outdates the existing plan
AGREED AROUND YOUR ENVIRONMENT

What the scope can include.

  • Review of the incident response policy, plan, playbooks, continuity plans, insurance policy, and monitoring provider contracts

  • Interviews with security, IT, legal, privacy, communications, HR, finance, and the executive sponsor

  • Inventory of every reporting obligation in play across defense contracts, PCI DSS, HIPAA, securities and state regulators, and customer contracts

  • Severity matrix and activation criteria tied to business impact, data sensitivity, and recovery difficulty

  • Playbooks for ransomware, business email compromise, credential compromise, cloud account compromise, and third-party compromise

  • Evidence-preservation runbook and chain-of-custody form, with the retention that defense contracts require for sensitive government data

TRANSPARENT PRICING

What it typically costs.
One rate: $150/hour.

Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.

Small
$6,000–$9,000

Under 50 employees, IT run by an outside provider, few reporting obligations

About 40–60 hours
Mid-size
$10,500–$15,000

50–250 employees, in-house IT plus a monitoring provider, one or two regulators or key contracts

About 70–100 hours
Large
$18,000–$25,500

250–1,000 employees, several business units, multiple regulators and contract reporting deadlines

About 120–170 hours
WHAT MOVES THE PRICE
  • Number of playbooks beyond the core five (ransomware, email fraud, stolen credentials, cloud account, vendor breach)
  • How many regulators, contracts, and states set reporting deadlines you must track
  • Number of stakeholders and business units to interview
  • Whether an existing plan is rewritten or one is built from nothing
TYPICAL TIMELINE

2–4 weeks for small scopes; 4–6 weeks for mid-size; 6–10 weeks for large

Get a fixed quote for your scope

Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.

TANGIBLE DELIVERABLES

What you take forward.

  • Incident response policy and plan with defined roles, activation criteria, severity matrix, and escalation paths
  • Checklist playbooks per incident type, notification decision tree, and a clock sheet naming each trigger and owner
  • Evidence runbook, chain-of-custody template, contact directory, and recovery priorities
  • Gap register with owners and a recorded walkthrough of the finished plan

Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.

SERVICE-SPECIFIC QUESTIONS

Before we get started.

We have an MDR provider and cyber insurance. Do we still need our own plan?

Yes. Your MDR provider contains what it sees inside the tooling it monitors, and the carrier supplies a panel of breach coaches and forensic firms once you file a claim. Neither decides whether to pay a ransom, whether a state breach law or a securities disclosure rule applies, what to tell customers, or when to restore. Those decisions stay with you, and the plan records who makes them, in what order, and whom they call. We also check the policy for prior-consent clauses so your preferred retainer is approved before you need it.

Does this satisfy PCI DSS, HIPAA, or CMMC incident response requirements?

The plan is written so its contents line up with what those frameworks ask for. That means the PCI DSS plan elements and annual test, HIPAA incident procedures, and the incident response requirements behind CMMC. Whether it satisfies an assessor is the assessor’s call, not ours, and readiness work is separate from an independent assessment. We hand you the documents and the evidence that they were walked through; you and your assessor decide what they prove.

REFERENCE POINTS
START AT THE SOURCE

Let’s find your next move.

A focused conversation. A clear scope. A practical path to stronger security.

Let’s talk security