Incident Response Readiness
The worst time to design your response is during one. We build and rehearse the plan while nothing is on fire.
- Typical duration
- 3–6 weeks
- Primary audience
- Both
- You leave with
- A response your team has already run once, before it counts.
Three phases, start to finish.
- 01 Detection gap analysis What you can actually see, mapped against MITRE ATT&CK. The plan is built on your real telemetry rather than an idealised one. Coverage assessed technique by technique against ATT&CK Log sources and retention checked against the scenarios that matter Gaps ranked by what an intruder would reach for first
- 02 Plan, runbooks and escalation The IR plan, the runbooks and the escalation tree, written against your org chart instead of a template someone else’s org filled in. Runbooks for the incident types your sector actually sees Escalation tree with named people and out-of-hours routes Legal, comms and regulator notification paths written in — OPC breach reporting, and the CCSPA 72-hour route where it applies
- 03 Tabletop and handover Two exercises — one for the executive team, one for on-call — then the whole pack is yours to run again without us. Executive tabletop focused on decisions, not tooling Technical tabletop against a scenario drawn from your own gaps Retainer options with defined response SLAs
Why readiness, not response
Retainers matter, but most of the damage in an incident is done in the first two hours — before any external responder is fully briefed. Readiness work moves those two hours into a rehearsal, where mistakes cost nothing.
The engagement
- Detection gap analysis mapped to MITRE ATT&CK, scoped to the techniques that match your threat profile
- Runbooks for the incident types you are actually likely to face, written for the people who will run them
- An executive tabletop: disclosure, regulator timelines, customer communication, and who decides what
- A technical tabletop: containment decisions, evidence preservation, and the tooling gaps that surface under pressure
- A prioritised remediation plan with owners and dates
The worst time to design your response is during one.
Incident Response Readiness: the questions we get asked.
We already have an incident response plan. Is this still worth it?
Usually, yes — because most plans have never been run. The gap that surfaces in a tabletop is almost never the plan itself; it is that the escalation contact left, the out-of-hours route goes to a shared inbox, or nobody has authority to disconnect a production system at 2am.
Do you provide incident response retainers?
Yes, with defined response SLAs. Readiness work comes first regardless — most of the damage in an incident is done before any external responder is fully briefed.
What are our breach reporting obligations in Canada?
Under PIPEDA, organisations must report breaches of security safeguards involving a real risk of significant harm to the Office of the Privacy Commissioner and notify affected individuals as soon as feasible, and keep records of all such breaches. Provincial and sector rules can add to that. The notification path, the decision owner and the record format are written into your runbooks rather than looked up during an incident.
Does this help with Bill C-26 and the CCSPA?
Yes, and for designated operators it is the most direct route to the obligation. The Critical Cyber Systems Protection Act enacted by Bill C-26 requires a designated operator to establish a cyber security programme within 90 days of designation, to manage supply-chain and third-party risk within it, to report cyber security incidents, and to keep records of compliance. The programme, the third-party risk process and the incident reporting path are the substance of this engagement; if you operate in telecommunications, finance, energy, transportation or nuclear, start here.
Who should attend the tabletop exercises?
Two different rooms. The executive exercise needs whoever can authorise disclosure, spend and downtime — typically the CEO, legal, comms and finance. The technical exercise needs on-call engineering and whoever owns your logging and identity systems.
Other lines of work
All servicesTell us what triggered the search. We will scope to that.
We reply to every assessment request within one business day.
