Services / 07

Incident Response Consulting

Readiness assessments, playbooks and retainers before an incident; coordination, triage and lessons-learned after one.

PLAYBOOKSRETAINERPOST-INCIDENT
Overview

What the practice does.

Incidents are decided in the first hours by preparation made months earlier: who has authority, which logs exist, who to call, what you are obliged to report and when.

We build that readiness, keep it current under a retainer, and when something happens we coordinate the response alongside your team, your counsel and your insurer.

What you get

Deliverables.

Each item is something you keep: a document, a register, a plan. All of it is scoped and priced before the work starts.

01

Incident response readiness assessment

Plans, roles, logging, backups, access to evidence, legal and regulatory obligations, and the gaps between them. Scored and prioritised.

02

Plans and playbooks

An incident response plan your team can run from, with playbooks for the incidents most likely to hit you: ransomware, business email compromise, data breach, insider action and vendor compromise.

03

Retainer

Pre-agreed terms, contacts and onboarding so the response starts in hours rather than days. Includes an annual readiness review and exercise.

04

Response coordination

Incident command, triage, containment advice, evidence handling, communication with counsel, insurers and regulators, and the breach notification analysis under PIPEDA and provincial law.

05

Post-incident review

Root cause, timeline, what worked, what failed, and the fixes that stop it happening again, written for leadership and the technical team.

How it runs

The four steps, applied.

The method is the same for every practice. This is what each step means here.

01 / SCOPE

Systems, data, obligations and stakeholders in scope, plus the specific incident types to prepare for. Retainer terms agreed in advance.

02 / TEST

Readiness reviews check that plans work in practice: logs exist and are retained, backups restore, contacts answer, and decisions have owners.

03 / VERIFY

Playbooks are walked through with the people who will run them. Findings from an incident are reproduced from evidence before they go in the review.

04 / REPORT

Readiness report and roadmap, plans and playbooks ready to adopt, and after an incident, a post-incident review your board and insurer can rely on.

When to call us

The situations this is built for.

You have no plan, or a plan nobody has read

A response plan exists as a document. It has no named roles, no out-of-band contacts and no connection to how your systems actually work.

Your insurer or a customer requires a retainer

Cyber insurance and enterprise contracts increasingly expect pre-arranged incident response. A retainer puts it in place.

Something is happening now

Retainer clients use their agreed escalation contacts. If you are not yet a client and something is happening now, send the form and mark it urgent in the first line; a consultant will respond as soon as possible.

Questions

Asked before most engagements.

Do you do forensics?

We coordinate the response and handle evidence correctly. Specialist forensic imaging and analysis are brought in when required and coordinated by us, so you deal with one team.

What does a retainer include?

Pre-agreed terms and rates, onboarding of your environment and contacts, an annual readiness review and tabletop exercise, and priority response when you call.

Do you handle breach notification?

We run the analysis of whether an incident is reportable under PIPEDA, provincial legislation and your contracts, and draft the notifications with your counsel. The decision and the legal advice remain with you and your lawyers.

Request a quote

Tell us what you need tested, assessed or governed.

A consultant, not a sales team, replies within one business day with a scope and a fixed price. For self-serve testing, go straight to Frontier Verify.

Start on Frontier Verify