Monitor & Respond

Incident Response Planning

Retainers, runbooks, and rehearsals, so the response is decided before you need it

  • A plan built round your organisation
  • Runbooks for the scenarios that matter
  • Rehearsals that find the gaps
  • Regulatory obligations built in
  • A retainer with people who know you

The worst time to work out who does what is halfway through an incident. Decisions that would take an hour on a normal Tuesday (whether to isolate a system, who speaks to customers, when the regulator has to be told) get made at speed, by whoever happens to be available, with incomplete information. That is where avoidable damage comes from: not the initial compromise, but the hours that follow it.

Incident response planning settles those decisions in advance. We build a plan that fits how your organisation actually works, write the runbooks your team will reach for under pressure, and then rehearse them so the gaps surface in a meeting room rather than during a live incident.

It joins up with the rest of Cyber.OS. Detection comes from the managed SOC, the personal-data and notification obligations come from our data protection practice, and the scenarios we rehearse are informed by what our testing team actually finds in environments like yours.

Get a quote for Incident Response Planning

Tell us your scope and objectives, and we’ll come back with a clear, fixed proposal, usually the same working day.

Get a Quoteor call +44 (0) 203 393 7795
  • CREST-accredited
  • UK-based specialists
  • Crown Commercial Service supplier

How it works

  1. 01

    Understand what you are protecting

    We map your critical systems, data, and dependencies, and review whatever response material you already have.

  2. 02

    Write the plan

    Roles, decision authority, escalation, and communications: internal, customer, regulator, and, where relevant, insurer.

  3. 03

    Build the runbooks

    Scenario playbooks your team can follow under pressure, written for the tools and people you actually have.

  4. 04

    Rehearse it

    A facilitated tabletop exercise against a realistic scenario, with a findings report and agreed actions.

  5. 05

    Keep it current

    Periodic review and re-rehearsal as your estate, your team, and the threat picture change.

Planning is what makes a retainer worth having

A response retainer guarantees you people when it matters. It is far more valuable when those people already know your estate, your escalation paths, and your reporting obligations, because the first hours are spent responding rather than orientating.

That is why we treat the plan, the runbooks, and the retainer as one piece of work. The rehearsals keep it current: an incident response plan written two years ago and never tested is a document, not a capability.

What you get

A plan built round your organisation

Roles, escalation paths, decision authority, and communications, mapped to the people you actually have, not a generic template.

Runbooks for the scenarios that matter

Step-by-step playbooks for the incidents most likely to affect you: ransomware, business email compromise, data exposure, supplier compromise.

Rehearsals that find the gaps

Tabletop exercises with your leadership and technical teams, so the plan is tested while the stakes are still low.

Regulatory obligations built in

UK GDPR breach assessment and the 72-hour notification clock are part of the plan, drawing on our data protection practice rather than being bolted on afterwards.

A retainer with people who know you

Optional response retainer, so if an incident does happen you reach a team that already understands your environment.

Frequently asked questions

Straight answers to what prospective clients ask us most.

How is this different from your 24/7 incident response?

This is the preparation; 24/7 incident response is the reaction. Planning covers the plan, the runbooks, and the rehearsals so your organisation knows how it will respond. If you are dealing with an incident right now, call us on the emergency line instead. That is a live response, not a planning engagement.

We already have an incident response plan. Is this still worth doing?

Usually yes, though it may be a shorter piece of work. Most plans we review are accurate about technology and vague about decisions: who declares an incident, who can authorise taking a system offline, who talks to customers. A rehearsal will tell you within a couple of hours whether yours holds up.

Do we need a managed SOC to benefit from this?

No. Planning stands on its own, and the plan is written for whatever detection you have. It does work better alongside a SOC, because detection and response are the same process, but the two are bought separately.

Who should be involved from our side?

Technical ownership of your key systems, plus someone who can make decisions on the day, typically IT leadership with a senior sponsor. Legal, communications, and data protection should join the rehearsal, since those are the escalations most plans handle least well.

Ready to talk about incident response planning?

Get a fixed-scope quote, usually the same working day.