Independent security assurance and editable documentation to keep organizations secure, compliant and resilient Questions? contact@rootguardsecurity.com
Service 02 · Fixed scope, fixed fee

Find the gaps before an incident finds them for you

Organizations usually discover the state of their preparation during an incident. This engagement finds the gaps first, closes them, and proves they are closed.

Standard
NIST SP 800-61r2
Exercise
90 minutes, your team
Ends with
Findings, after-action report, verification
Fee basis
Fixed on agreed scope

Why this matters

It is no longer hypothetical anywhere

A national registrar, a standards bureau, a state energy company, a financial services regulator and a stock exchange have all been attacked, and a lender's customer data appeared on the dark web while its clients were still unaware. All publicly reported, all within three years, and all in organizations that believed their controls were in place.

The question for most organizations is not whether something will happen. It is whether the response would be improvised.

What organizations find at 2am

The same four things, almost every time

01

The plan is out of date

Written once, never revised, and describing an environment that has since changed.

02

The contact list is two years old

Numbers that no longer work, for people who no longer hold the role.

03

Nobody knows who can disconnect

Containment stalls while people work out who has the authority to take a system offline.

04

The IT contract has no out-of-hours obligation

Discovered at the moment somebody needs to be called, rather than before.

What we do

Five parts

1

Readiness assessment

We establish whether you could actually contain an incident, who authorizes what, whether you would know which records were accessed, how far back your logs go, and who you would call out of hours. Against evidence, not against intentions.

  • Log retention and coverage on the systems that hold client data
  • Containment capability and who holds the authority
  • What your IT contract actually commits to out of hours
  • Contractual and regulatory notification periods
2

Response documentation

A complete response set, written and tailored: the plan, playbooks for the scenarios most likely to affect you, evidence-collection procedures, a severity matrix, and the templates for briefing executives, regulators and insurers when there is no time to draft from scratch.

3

Tabletop exercise

Ninety minutes in your boardroom with your own people, walking one realistic scenario end to end. Facilitated, not tested. No blame, no devices, and nobody rescues the scenario with resources you do not have.

It generates its own findings, and those findings are more persuasive than anything we could tell you, because the room discovers them.

4

Training

Incident triage and response courses for the people who would actually respond, with hands-on labs and recorded completion.

5

Verification

We confirm the gaps found in the assessment and the exercise have actually been closed, against the criterion agreed for each.

What you end up with

Some of it is ours. Most of it becomes yours

Assessed against NIST SP 800-61r2, so a customer, an insurer or a board can see what standard the work was done to.

What we produce

  • Readiness findings. Each of the six response phases judged against what exists rather than what is intended: preparation, identification, containment, eradication, recovery and lessons learned. Governance, detection and telemetry, containment tooling, recovery architecture, and your third-party and retainer position, each assessed from evidence with the population and any limitation recorded.
  • A gap register. Every gap found, with a named owner and the criterion that says how it will be verified as closed. Not a list of observations.
  • An after-action report. What happened in the exercise, where the response stalled, which decisions nobody could make, and how long each took. This is the document a board asks for afterwards.
  • A thirty, sixty and ninety day plan. Ordered by what would hurt most if an incident happened before it was done.
  • A verification statement. Confirmation in writing that the gaps found were closed against their criteria, or that they were not.
  • An executive readout. What was found, what it means commercially, and what needs a decision from you.

What we help you establish

  • Your incident response plan. Tailored from our published plan to your environment and obligations. Yours to maintain, and the reason it stays current is that your people wrote the parts only they could write.
  • Playbooks for your scenarios. The incidents your business would actually face, not a generic set.
  • A decision authority matrix. Who can disconnect what, without waiting for someone on holiday. Establishing this is a business decision, so we facilitate it rather than write it.
  • A contact and escalation tree, including the out-of-hours arrangement you may not have yet, and an out-of-band channel for when corporate email is the thing that is compromised.

The technical side, assessed the same way as everything else

Detection, containment and recovery controls are assessed from the evidence your team produces, not by us logging in. You export it, we examine it, and the finding records the population and any limitation on it. That is the same standard applied to every other control, and it is why a finding survives being questioned by somebody who was not in the room.

Would you see it

The log source inventory against your asset list, retention settings, and a sample export proving the events you assume are being collected actually are. Gaps here are usually not a tooling problem but an unmanaged asset nobody had on a list.

Could you contain it

Agent coverage as a full population against the asset inventory rather than a percentage from a dashboard, the privileged account list in full, and the segmentation policy as exported. Small enough in most organizations to examine entirely.

Could you come back

Backup immutability and isolation as configured, the identity rebuild procedure, and the restore test record. A backup nobody has restored from is an assumption, and the record either exists or it does not.

One thing genuinely out of scope. We do not run purple team or adversary simulation exercises. Those need hands on keyboard against live systems and a different kind of engagement. Everything else here is established from evidence you produce, with your team in the room, because a control your own people cannot evidence to us is one they will not be able to evidence to a customer either.

An honest boundary

This is preparedness, not response

We do not provide out-of-hours incident response. If something happens at 2am on a Sunday you need somebody who can answer, and that is not us.

What we will do is tell you plainly that you need that arrangement, help you put it in place, and confirm in writing that it exists and what it commits to. Most organizations discover they do not have one at the worst possible moment.

Start with the free plan

Take the incident response plan and fill it in

We publish a complete eight-page incident response plan at no charge. Adapt it, get it approved, and you will have closed the first gap yourself. If you want the exercise and the verification behind it, that is what this engagement adds.