Let's talk
Incident Response Planning

Clear steps when a security incident happens.

We build on your existing procedures with clear response steps, communication plans and realistic exercises, so your team is better prepared to act.

Services

  1. 01

    Security Incident Response Plan

    A security incident would bring urgent decisions, but the response still depends on people working out the process as they go.

    What changes

    A shared response plan your team can work from when decisions need to be made quickly.

    What we deliver
    • A response plan built around your business, existing procedures and available people or providers.
    • Clear stages, responsibilities and decision points, from the first report through recovery coordination and review.
    • Contact details, initial evidence guidance and a walkthrough of how to use and maintain the plan.
    View service: Security Incident Response Plan
  2. 02

    Incident Classification Matrix

    Reports arrive with different levels of detail, making it hard to judge which need urgent action.

    What changes

    A consistent way to judge incident severity and decide what should happen next.

    What we deliver
    • Incident categories and severity levels based on potential business impact.
    • Practical examples and criteria for making an initial assessment when information is incomplete.
    • A mapping from each level to the required response, escalation and reassessment steps.
    Ask about this service: Incident Classification Matrix
  3. 03

    Security Escalation Workflow

    An urgent security concern can stall because nobody is sure who to contact or who can make the decision.

    What changes

    A clear route to the people who need to act, with a fallback when the first contact is unavailable.

    What we deliver
    • Escalation triggers and a workflow linked to your incident severity levels.
    • Named contacts, deputies and decision owners, with agreed contact methods.
    • A walkthrough of the handoffs, including missed responses and unavailable contacts.
    Ask about this service: Security Escalation Workflow
  4. 04

    Tabletop Exercise

    You have a response plan, but the team has not worked through a realistic incident together.

    What changes

    A chance to practise decisions together and find gaps before a real incident adds pressure.

    What we deliver
    • A realistic security scenario tailored to your business, systems and response arrangements.
    • A facilitated discussion that works through decisions, handoffs and communication as the scenario develops.
    • A debrief with observed gaps, agreed lessons and a prioritized improvement list.
    View service: Tabletop Exercise
  5. 05

    Post-Incident Review Template

    Once an incident is over, lessons and follow-up actions are easy to lose in messages and meeting notes.

    What changes

    A reusable structure for capturing what happened, what helped and what should change.

    What we deliver
    • A tailored review template covering the timeline, business impact, response decisions and available evidence.
    • Prompts to explore contributing factors and lessons without turning the review into a search for blame.
    • An action log with owners and review dates, plus guidance for running the review.
    Ask about this service: Post-Incident Review Template
  6. 06

    Breach Response Readiness Review

    If sensitive information were exposed, you would need to assess the impact and coordinate a response quickly.

    What changes

    A clearer view of your readiness to respond, with the gaps and first priorities explained.

    What we deliver
    • A review of response arrangements for agreed information exposure scenarios.
    • Checks of how the team would establish facts, preserve relevant records and involve decision makers or specialists.
    • Prioritized findings covering response gaps, communication decisions and questions requiring legal or specialist input.
    View service: Breach Response Readiness Review
  7. 07

    Security Incident Playbook Sprint

    The overall plan is clear, but your team still needs practical steps for a specific type of security incident.

    What changes

    A focused playbook that makes the next actions and decision points easier to follow under pressure.

    What we deliver
    • A playbook for the agreed scenario, built around your systems, available people and existing response plan.
    • Action checklists covering initial checks, approvals, escalation, evidence and coordination with technical responders.
    • A walkthrough with the relevant team, with unclear steps and dependencies recorded for follow-up.
    Ask about this service: Security Incident Playbook Sprint
  8. 08

    Incident Communication Plan

    During an incident, staff, customers and providers need updates while the facts are still changing.

    What changes

    Clear update and approval steps, so communication is coordinated and based on confirmed information.

    What we deliver
    • An audience and contact map covering the people and organizations likely to need updates.
    • Message ownership, approval steps and communication channels, with alternatives if normal tools are unavailable.
    • Adaptable update templates and a decision log for what was communicated, when and by whom.
    Ask about this service: Incident Communication Plan
Working together

Know what to expect before we start.

We agree scope, pricing and timing before work begins, then take responsibility for the agreed work and keep you informed.

We take care of

The agreed planning, reviews and exercises, with practical response documents and clear follow-up actions.

Your input

Your business priorities, input from the people involved in a response, and approval of the agreed arrangements.

Get in touch

What do you need
taken care of?

An informal 30-minute call to discuss your needs and see how we could work together.