Incident Readiness
Prevention eventually fails, and what happens in the first hour afterwards determines most of the damage. Readiness is not a document. It is knowing who decides to disconnect a system, who calls the Information Regulator, whether the logs needed to reconstruct events even exist, and whether anyone has ever rehearsed any of it.
1
Review
The plan as written
2
Authority
Who can decide what
3
Logging
Can you reconstruct it
4
Exercise
Rehearse a real scenario
5
Improve
Close what surfaced
How We Assess
01
Response Plan Review
We assess whether the plan could be followed by whoever is actually on duty, at the worst possible hour, without its author. Plans referring to systems long retired and people long departed are common.
- Plan currency, ownership and approval date
- Severity definitions and declaration criteria
- Contact lists verified as current
- Dependency on named individuals identified
02
Authority and Escalation Mapping
The most damaging delays are decision delays. Somebody has to be able to disconnect a production system at two in the morning without convening a committee, and that authority has to be written down beforehand.
- Authority to disconnect or isolate systems
- Escalation thresholds and decision owners
- Delegation when primary contacts are unreachable
- Legal, regulator and insurer notification paths
03
Logging and Forensic Readiness
After an incident the question is always what happened and for how long. If the logs were never retained the honest answer is that nobody knows, which is the worst position to be in with a regulator.
- Log coverage across critical systems
- Retention periods against realistic detection times
- Log integrity and protection from tampering
- Evidence preservation procedures
04
Tabletop Exercise
We facilitate a scenario with the people who would actually respond. Ransomware encrypting the finance system during year end surfaces more gaps in two hours than a document review does in a week.
- Realistic scenario built around your environment
- Participation from technical, executive and communications
- Decisions and delays recorded in real time
- Gaps identified as they emerge rather than in hindsight
05
Findings and Improvement
A ranked list of what would have gone wrong, with the plan updated rather than merely criticised. Communication templates get drafted in advance, because nobody writes well under that kind of pressure.
- Gaps ranked by likely impact
- Updated plan reflecting what the exercise revealed
- Pre drafted holding statements and notification templates
- Recommended exercise and review cycle
What You Receive
- Response plan review with currency and gap findings
- Authority and escalation map with named decision owners
- Logging and forensic readiness assessment
- Facilitated tabletop exercise with recorded outcomes
- Updated plan and pre drafted communication templates
- Recommended exercise and review cycle
Indicative Timeline
A readiness review with one tabletop exercise runs two to four weeks. Scheduling the exercise around executive availability is normally the constraint rather than the work itself.
- Plan and documentation review: one week
- Authority and logging assessment: one week
- Tabletop exercise: one facilitated session
- Reporting and plan update: one week
What Readiness Covers
Readiness spans the decisions and evidence a response depends on, not only the technical containment.
Detection
Whether anything would alert you, and whether an alert reaches a person who acts on it.
Decision Authority
Who can isolate systems or halt operations, and whether that is written down before it is needed.
Communication
What is said to staff, clients and regulators, drafted before the pressure rather than during it.
POPIA Notification
The obligation to notify the Information Regulator and affected data subjects, and who owns that call.
Forensic Evidence
Whether logs exist, are retained long enough, and survive an attacker with administrative access.
Recovery Interface
How response hands over to recovery, and whether the backups are reachable from a compromised network.
Frequently Asked Questions
We have never had an incident. Is this premature?
The organisations that handle incidents well are the ones that prepared before having one. Readiness work is inexpensive relative to a poorly handled breach, and the exercise alone usually surfaces gaps nobody suspected.
What is a tabletop exercise?
A facilitated discussion where a realistic scenario unfolds and the actual response team works through what they would do. No systems are touched. The value is in exposing the decisions nobody had thought about, particularly who has authority to act.
Does POPIA require us to report a breach?
POPIA requires notification to the Information Regulator and, in defined circumstances, to affected data subjects, as soon as reasonably possible. Knowing who makes that determination and how quickly is exactly the kind of thing readiness work establishes in advance.
Who should take part in the exercise?
Technical responders, an executive with authority to make business decisions, and whoever handles communications. Running it with IT alone misses the decisions that cause the longest delays in a real incident.
How long should we keep logs?
Long enough to investigate an incident detected months after it began, which is common. Ninety days is a frequent minimum and twelve months is safer for critical systems. Cost is the trade off and it is a business decision.
Do you provide incident response itself?
This engagement is readiness. Where you need retained response capability we will say so honestly and help you scope it, including whether a specialist retainer is warranted for your risk profile.
Related Services
This sits inside our Cyber Security Assessments practice. Related work: Disaster Recovery and Continuity Review for the recovery side, and POPIA Readiness for the notification obligations a breach triggers.
