Organizations usually discover the state of their preparation during an incident. This engagement finds the gaps first, closes them, and proves they are closed.
Why this matters
A national registrar, a standards bureau, a state energy company, a financial services regulator and a stock exchange have all been attacked, and a lender's customer data appeared on the dark web while its clients were still unaware. All publicly reported, all within three years, and all in organizations that believed their controls were in place.
The question for most organizations is not whether something will happen. It is whether the response would be improvised.
What organizations find at 2am
01
Written once, never revised, and describing an environment that has since changed.
02
Numbers that no longer work, for people who no longer hold the role.
03
Containment stalls while people work out who has the authority to take a system offline.
04
Discovered at the moment somebody needs to be called, rather than before.
What we do
We establish whether you could actually contain an incident, who authorizes what, whether you would know which records were accessed, how far back your logs go, and who you would call out of hours. Against evidence, not against intentions.
A complete response set, written and tailored: the plan, playbooks for the scenarios most likely to affect you, evidence-collection procedures, a severity matrix, and the templates for briefing executives, regulators and insurers when there is no time to draft from scratch.
Ninety minutes in your boardroom with your own people, walking one realistic scenario end to end. Facilitated, not tested. No blame, no devices, and nobody rescues the scenario with resources you do not have.
It generates its own findings, and those findings are more persuasive than anything we could tell you, because the room discovers them.
Incident triage and response courses for the people who would actually respond, with hands-on labs and recorded completion.
We confirm the gaps found in the assessment and the exercise have actually been closed, against the criterion agreed for each.
What you end up with
Assessed against NIST SP 800-61r2, so a customer, an insurer or a board can see what standard the work was done to.
Detection, containment and recovery controls are assessed from the evidence your team produces, not by us logging in. You export it, we examine it, and the finding records the population and any limitation on it. That is the same standard applied to every other control, and it is why a finding survives being questioned by somebody who was not in the room.
The log source inventory against your asset list, retention settings, and a sample export proving the events you assume are being collected actually are. Gaps here are usually not a tooling problem but an unmanaged asset nobody had on a list.
Agent coverage as a full population against the asset inventory rather than a percentage from a dashboard, the privileged account list in full, and the segmentation policy as exported. Small enough in most organizations to examine entirely.
Backup immutability and isolation as configured, the identity rebuild procedure, and the restore test record. A backup nobody has restored from is an assumption, and the record either exists or it does not.
One thing genuinely out of scope. We do not run purple team or adversary simulation exercises. Those need hands on keyboard against live systems and a different kind of engagement. Everything else here is established from evidence you produce, with your team in the room, because a control your own people cannot evidence to us is one they will not be able to evidence to a customer either.
An honest boundary
We do not provide out-of-hours incident response. If something happens at 2am on a Sunday you need somebody who can answer, and that is not us.
What we will do is tell you plainly that you need that arrangement, help you put it in place, and confirm in writing that it exists and what it commits to. Most organizations discover they do not have one at the worst possible moment.
Start with the free plan
We publish a complete eight-page incident response plan at no charge. Adapt it, get it approved, and you will have closed the first gap yourself. If you want the exercise and the verification behind it, that is what this engagement adds.