Incident Readiness

Prevention eventually fails, and what happens in the first hour afterwards determines most of the damage. Readiness is not a document. It is knowing who decides to disconnect a system, who calls the Information Regulator, whether the logs needed to reconstruct events even exist, and whether anyone has ever rehearsed any of it.

1

Review

The plan as written

2

Authority

Who can decide what

3

Logging

Can you reconstruct it

4

Exercise

Rehearse a real scenario

5

Improve

Close what surfaced

How We Assess

01

Response Plan Review

We assess whether the plan could be followed by whoever is actually on duty, at the worst possible hour, without its author. Plans referring to systems long retired and people long departed are common.

02

Authority and Escalation Mapping

The most damaging delays are decision delays. Somebody has to be able to disconnect a production system at two in the morning without convening a committee, and that authority has to be written down beforehand.

03

Logging and Forensic Readiness

After an incident the question is always what happened and for how long. If the logs were never retained the honest answer is that nobody knows, which is the worst position to be in with a regulator.

04

Tabletop Exercise

We facilitate a scenario with the people who would actually respond. Ransomware encrypting the finance system during year end surfaces more gaps in two hours than a document review does in a week.

05

Findings and Improvement

A ranked list of what would have gone wrong, with the plan updated rather than merely criticised. Communication templates get drafted in advance, because nobody writes well under that kind of pressure.

What You Receive

Indicative Timeline

A readiness review with one tabletop exercise runs two to four weeks. Scheduling the exercise around executive availability is normally the constraint rather than the work itself.

What Readiness Covers

Readiness spans the decisions and evidence a response depends on, not only the technical containment.

Detection

Whether anything would alert you, and whether an alert reaches a person who acts on it.

Decision Authority

Who can isolate systems or halt operations, and whether that is written down before it is needed.

Communication

What is said to staff, clients and regulators, drafted before the pressure rather than during it.

POPIA Notification

The obligation to notify the Information Regulator and affected data subjects, and who owns that call.

Forensic Evidence

Whether logs exist, are retained long enough, and survive an attacker with administrative access.

Recovery Interface

How response hands over to recovery, and whether the backups are reachable from a compromised network.

Frequently Asked Questions

The organisations that handle incidents well are the ones that prepared before having one. Readiness work is inexpensive relative to a poorly handled breach, and the exercise alone usually surfaces gaps nobody suspected.

A facilitated discussion where a realistic scenario unfolds and the actual response team works through what they would do. No systems are touched. The value is in exposing the decisions nobody had thought about, particularly who has authority to act.

POPIA requires notification to the Information Regulator and, in defined circumstances, to affected data subjects, as soon as reasonably possible. Knowing who makes that determination and how quickly is exactly the kind of thing readiness work establishes in advance.

Technical responders, an executive with authority to make business decisions, and whoever handles communications. Running it with IT alone misses the decisions that cause the longest delays in a real incident.

Long enough to investigate an incident detected months after it began, which is common. Ninety days is a frequent minimum and twelve months is safer for critical systems. Cost is the trade off and it is a business decision.

This engagement is readiness. Where you need retained response capability we will say so honestly and help you scope it, including whether a specialist retainer is warranted for your risk profile.

Related Services

This sits inside our Cyber Security Assessments practice. Related work: Disaster Recovery and Continuity Review for the recovery side, and POPIA Readiness for the notification obligations a breach triggers.

Discuss incident readiness