Incident response readiness
The worst moment to discover that nobody knows who can authorize taking a production system offline is the moment somebody has to. Incident readiness is the unglamorous work of settling those questions while everyone is calm, in writing, and then rehearsing until the answers are boring.
The short version: planning and exercising, done beforehand
If you are in an incident now, this is not the page you need: call your counsel and an appropriately licensed incident responder first, and come back to readiness work afterwards. What this engagement produces is the plan, the playbooks, the rehearsal and the improvement register — everything that makes the response possible. It is not the response itself, and the page says so rather than leaving a reader to assume otherwise.
The reference used is NIST’s SP 800-61 Rev. 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management, which treats incident response as part of an organization’s risk management rather than as a standalone playbook exercise.
The plan: who is allowed to make the call at 2am
A plan that lists phone numbers and nothing else is an address book. The plan written here settles the questions that otherwise stall a response for hours:
- Roles, not names — incident lead, technical lead, communications, legal liaison, executive sponsor, scribe — each with a named primary and an alternate, because incidents do not wait for holidays to end.
- Declaration criteria — what makes something an incident rather than a ticket, and who can declare one. Under-declaration is the more common failure.
- Severity levels — three or four, each tied to a concrete consequence and to what it triggers.
- Decision authority — specifically, who can take a production system offline, who can authorize unbudgeted spending, and who speaks to a customer, a regulator or the press. In writing, in advance.
- Escalation and external contacts — counsel, insurer and broker, the responder you would call, and the notification paths you may need. Insurance policies frequently constrain who may be engaged; the plan records that constraint rather than discovering it mid-incident.
Playbooks for the scenarios you are actually likely to meet
Not a playbook for every threat, which nobody reads. Four to six, for the scenarios your environment and sector make plausible: business email compromise, ransomware or destructive attack, exposure of personal information, a compromised administrative account, a third-party or supplier breach that reaches you, and — increasingly — an incident involving a system with a model in it, which is covered separately on AI incident readiness.
Each playbook opens with the first actions and the evidence to preserve before anything is changed, because the instinct to fix destroys the record that later matters. What that period demands in practice is set out in the first 24 hours of an incident.
The tabletop exercise, and what comes out of it
The people who would really be in the room: an executive who can authorize spending, whoever runs technology, whoever handles communications, the person who calls counsel, and somebody who knows how the systems actually work. Two to three hours, facilitated remotely, against a scenario written for your environment rather than a generic one.
The exercise runs on injects: the situation changes on a timer, the way it does in reality. A customer emails to say their data is for sale. A journalist calls. The backup that was going to solve this turns out to be four days old. An executive is on a flight. Injects are what separate an exercise from a discussion, and they are where the plan’s gaps surface.
The output is an after-action report with a numbered improvement register: what was missing, what the change is, who owns it, and by when. A tabletop without that register is an afternoon that felt productive.
Why a plan written once decays
People leave. Systems change. The document that named a platform you no longer run points responders at a console that no longer exists. Re-runs are scheduled deliberately — commonly annually, and always after a real incident, a significant architecture change or a change of leadership — with a different scenario each time so the exercise tests the plan rather than the memory of the last exercise.
Security awareness and phishing simulation programme design
Awareness delivered as a single annual video is a compliance artifact, not a control. Content is written by role, because the finance team’s exposure is payment fraud and supplier impersonation, the developers’ is credential and token handling, and the executives’ is targeted impersonation of themselves. Short, specific, and tied to something the person actually does.
No. The programme, the metrics, the content and the escalation path are designed here, and the simulations themselves are run by you or by the platform you already license. What the design covers is the metrics that mean something — report rate rather than click rate, and time to first report rather than raw volume — the difficulty progression, and above all a no-blame escalation path. A programme that punishes clicking produces employees who hide their mistakes, which is the opposite of the capability you are buying.
What is deliberately not here
No pretext phone calls, no impersonation of named staff and no physical entry or site visits are performed. Those are excluded as a standing boundary on this practice. Investigation and forensic work is delivered with appropriately licensed partners where the law requires it, and never presented as something this practice performs on its own. How live response is organized with those partners is set out on incident response and digital forensics.
The line also holds on the legal side. Whether an incident must be reported, to whom, and when, is a determination for your counsel. The plan records the decision points and who owns them; it does not pre-empt them. The British Columbia position on reporting is set out in breach reporting in British Columbia, and the surrounding privacy programme work is Canadian privacy readiness.
What you receive
| Deliverable | What it is for |
|---|---|
| Incident response plan | Roles, declaration criteria, severity, decision authority and external contacts |
| Scenario playbooks | Four to six, opening with first actions and evidence preservation |
| Tabletop and after-action report | A facilitated exercise with injects, and a numbered improvement register |
| Awareness and simulation programme design | Role-based content, metrics that mean something, and a no-blame path |
The technical half of surviving a destructive incident — hardening, privilege, segmentation, immutable backups and restore drills — is on ransomware readiness and resilience. The plan and the technical readiness are two halves of one capability and are usually scoped together.
How the work is bounded
The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.
Investigation and forensic work is delivered with appropriately licensed partners where the law requires it.
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
Questions we are asked
What if we are in an incident right now?
Your insurer may also require that a responder from their panel is engaged, which is one of the reasons the plan records insurance constraints in advance.
Who should be at the tabletop?
Six to ten is the workable range. The exercise is worth far less without an executive present, because the decisions that stall a real response are the ones only an executive can take.
Do you run the phishing simulations?
Keeping the design and the operation separate also keeps the metrics honest, since nobody reporting on the programme is also being measured by it.
Can you decide whether we must notify?
No. Whether an incident triggers a notification obligation is a legal determination and it rests with your counsel; this practice works alongside them and does not make that call. Nothing on this site is legal advice. The plan makes sure the question reaches counsel quickly and with the facts attached, which is the part that usually goes wrong.
Settle the questions while everyone is calm
Describe who would run an incident today and what you have written down. The reply says what a plan, a playbook set and a tabletop would cover — see also all security services.