A named response team
Who decides, who communicates, who executes, and who replaces each of them when absent. Names, not job titles.
RISK · CRISIS MANAGEMENT
Knowing who does what in the first two hours changes everything after it.
Most of the damage from a security incident does not come from the attack itself, but from what happens next: hours lost working out who to call, evidence destroyed by powering off a server, clumsy communication that deepens the loss of trust, a notification obligation discovered three weeks too late. Incident response means deciding all of that calmly, while nobody is under pressure.
Telling a false positive from a real incident, and a minor incident from a broad compromise. This triage governs everything that follows.
Stop the spread without destroying evidence. Isolate from the network rather than power off: volatile memory often holds what matters.
Close the entry point, revoke compromised access and remove whatever the attacker left behind. Restoring before this step simply restarts the cycle.
Progressive return to service, with heightened monitoring on affected systems for the following weeks.
What was missing, what worked and what changes in the plan. It is the most frequently skipped phase, and the most profitable.
We find these same gaps in most organisations that have never lived through an incident.
Who decides, who communicates, who executes, and who replaces each of them when absent. Names, not job titles.
What justifies waking someone at night, and what can wait for morning. Without thresholds, everything is urgent or nothing is.
Reconstructing an incident takes weeks of history. Seven-day retention makes the investigation impossible.
Templates for clients, employees and partners, to adapt rather than to draft under pressure.
Under privacy law, a confidentiality incident must be recorded and, depending on the risk of serious harm, notified. That decision path is prepared in advance.
This sequence fits on one page, and that page must be reachable without network and without a computer.
Ask them at a leadership meeting. The silence that follows is usually the answer.
We build your procedure with the people involved, then test it against a realistic scenario.
Prepare our procedure