Incident Response Consulting
Readiness assessments, playbooks and retainers before an incident; coordination, triage and lessons-learned after one.
What the practice does.
Incidents are decided in the first hours by preparation made months earlier: who has authority, which logs exist, who to call, what you are obliged to report and when.
We build that readiness, keep it current under a retainer, and when something happens we coordinate the response alongside your team, your counsel and your insurer.
Deliverables.
Each item is something you keep: a document, a register, a plan. All of it is scoped and priced before the work starts.
Incident response readiness assessment
Plans, roles, logging, backups, access to evidence, legal and regulatory obligations, and the gaps between them. Scored and prioritised.
Plans and playbooks
An incident response plan your team can run from, with playbooks for the incidents most likely to hit you: ransomware, business email compromise, data breach, insider action and vendor compromise.
Retainer
Pre-agreed terms, contacts and onboarding so the response starts in hours rather than days. Includes an annual readiness review and exercise.
Response coordination
Incident command, triage, containment advice, evidence handling, communication with counsel, insurers and regulators, and the breach notification analysis under PIPEDA and provincial law.
Post-incident review
Root cause, timeline, what worked, what failed, and the fixes that stop it happening again, written for leadership and the technical team.
The four steps, applied.
The method is the same for every practice. This is what each step means here.
Systems, data, obligations and stakeholders in scope, plus the specific incident types to prepare for. Retainer terms agreed in advance.
Readiness reviews check that plans work in practice: logs exist and are retained, backups restore, contacts answer, and decisions have owners.
Playbooks are walked through with the people who will run them. Findings from an incident are reproduced from evidence before they go in the review.
Readiness report and roadmap, plans and playbooks ready to adopt, and after an incident, a post-incident review your board and insurer can rely on.
The situations this is built for.
You have no plan, or a plan nobody has read
A response plan exists as a document. It has no named roles, no out-of-band contacts and no connection to how your systems actually work.
Your insurer or a customer requires a retainer
Cyber insurance and enterprise contracts increasingly expect pre-arranged incident response. A retainer puts it in place.
Something is happening now
Retainer clients use their agreed escalation contacts. If you are not yet a client and something is happening now, send the form and mark it urgent in the first line; a consultant will respond as soon as possible.
Asked before most engagements.
Do you do forensics?
We coordinate the response and handle evidence correctly. Specialist forensic imaging and analysis are brought in when required and coordinated by us, so you deal with one team.
What does a retainer include?
Pre-agreed terms and rates, onboarding of your environment and contacts, an annual readiness review and tabletop exercise, and priority response when you call.
Do you handle breach notification?
We run the analysis of whether an incident is reportable under PIPEDA, provincial legislation and your contracts, and draft the notifications with your counsel. The decision and the legal advice remain with you and your lawyers.
Often paired with this.
Tabletop Exercises
Incident response, business continuity and disaster recovery exercises for executives and technical teams, scored against your own plans and run on RiskTrace.
External Security Testing
Network, web, API, cloud and wireless testing run by hand against your real perimeter, with every finding reproduced before it is written up.
Fractional CISO
A named security leader inside your leadership team, part-time: strategy, budget, board reporting and vendor decisions without the full-time hire.
Tell us what you need tested, assessed or governed.
A consultant, not a sales team, replies within one business day with a scope and a fixed price. For self-serve testing, go straight to Frontier Verify.
Start on Frontier VerifyReceived. A consultant will reply within one business day.
You will get a written scope and a fixed price, not a call booking link.