We have launched Cyber Incident Readiness, a service built to do one job: keep your business operating when a cyberattack, data breach, or ransomware incident hits, not just help you recover from one afterwards.
We built it because AI is changing how fast an attack moves, not the fundamentals of incident response. The National Cyber Security Centre's 2025 Annual Review is clear that AI is mainly accelerating the tactics attackers already use, reconnaissance, phishing, and exploiting known vulnerabilities, rather than inventing new ones. That is still enough to compress the time a business has to notice and respond, and most businesses only find out how ready they actually are once the incident is underway. Cyber Incident Readiness gives you the plans, playbooks, and rehearsed decision-making to change that, covering everything from who has the authority to take a system offline to how you keep taking payments while it is down.
Why now: attacks are faster and harder to spot
The incidents driving demand for this service are the same ones that have driven incident response for years: ransomware, business email compromise, account compromise, data breaches, and supply-chain compromise. What has changed is how fast they move and how convincing they have become, largely because attackers now have AI doing part of the work:
- AI-written phishing and business email compromise: emails with no spelling errors, no awkward phrasing, and language tuned to match how your organisation actually writes internally
- Deepfake voice and video fraud: a cloned voice authorising a wire transfer, a fabricated video call requesting urgent access, both convincing enough to bypass staff who were trained to spot the older, clumsier version of this attack
- AI-accelerated ransomware: AI speeds up the reconnaissance and vulnerability exploitation stages of an attack, and NCSC warns the gap between a vulnerability being disclosed and being exploited is narrowing, shrinking the window your team has to detect and contain an intrusion before it spreads
- Attacks on the AI tools you use: prompt injection, data poisoning, and over-permissioned AI agents aimed at the AI systems your own business has adopted, a category almost no incident plan written before 2024 accounts for, alongside "Shadow AI", staff using AI tools IT has never assessed or approved
None of this replaces the fundamentals. Account compromise, data breach, and supplier compromise still need the same playbooks they always did. AI just compresses the time between first compromise and full business impact, and NCSC expects that trend to continue. A plan that assumes you have a day to respond before it matters is a plan that increasingly does not match how these incidents actually unfold, AI-driven or not.
A plan is not the same as being ready
Every organisation we assess has some version of an incident response document. Most have not opened it in over a year. Fewer still have tested whether the people named in it actually know what they are supposed to do, or whether the technical steps still match the systems currently in production.
Incident response is a business process, not an IT process. The document matters less than whether your leadership team, your comms function, and your technical staff have actually rehearsed making decisions together under pressure. A tabletop exercise reveals gaps that a written plan hides: who has authority to take a system offline, who talks to customers, who decides whether to pay a ransom, and how long the business can actually run in a degraded state before revenue or safety is affected.
What Cyber Incident Readiness covers
Keeping the business operating during an incident, not just eventually recovering from one, means covering a few things most plans skip. This is what the service is built to deliver:
- Manual fallback procedures for the processes that break first when systems go down. In hospitality that is often the PMS, POS, key-card and booking systems; in healthcare it is patient records, clinical systems and pharmacy; in financial services it is payment processing, authentication and trading systems. Whatever keeps the business moving without the software you normally rely on
- A communications plan written in advance, including holding statements for customers, staff, and regulators, so nobody is drafting a public statement for the first time while also fighting the incident
- Backups that are actually tested, isolated from the systems an attacker would compromise, and restorable within a timeframe the business can survive
- Named decision-makers with real authority, agreed before the incident, not improvised during it
- Regulatory reporting timelines built in, since NIS2, DORA, and UK reporting obligations all carry short statutory windows that do not pause for a crisis
It starts with an Incident Readiness Assessment and does not stop at a document to file away. You get plans, playbooks, and a rehearsed team that knows what to do the moment the alert comes in, whether that is an attack, a breach, or a ransomware note.
AI does not make traditional incident response obsolete. It makes tested incident response more important, because there is less time than there used to be to work out the plan as you go. For the fundamentals of building a plan, see our incident response plan guide and ransomware response guide. For what changes in detection, containment and investigation when AI is involved, see our guide on AI incident response. For the source behind the AI figures in this article, see the NCSC's Annual Review 2025.