Your incident response plan looks good on paper. But will it work under pressure?
Most organisations have an incident response plan. Far fewer have tested whether it actually works. Cyvra helps organisations assess, build and rehearse their cyber incident response capability so when ransomware, a data breach or account compromise happens, your people know who does what, when and why.
There is no time to work out the process
In the first hour of a serious incident, uncertainty costs time, money and credibility. Walk through what your organisation would need to do.
Would your organisation know exactly what to do at each step? Find out where the gaps are.
A complete incident readiness programme
Six structured phases that take you from where you are today to a tested, documented and maintained response capability.
Plans, playbooks and procedures you can actually use
Services describe what we do. Deliverables describe what you get. Here is what a full Cyber Incident Readiness programme can produce.
Incident response is a business process, not an IT process
A serious cyber incident demands coordinated action across the whole organisation simultaneously. Your plan needs to reflect that reality.
| Function | What must happen |
|---|---|
| IT and Security | Detect, contain and investigate |
| Leadership | Make business-critical decisions under pressure |
| Legal and Privacy | Assess data and notification obligations |
| Communications | Manage employees, customers and media |
| Operations | Maintain or restore critical services |
| Finance | Manage financial exposure and fraud risk |
| HR | Support affected staff and manage insider considerations |
| Third parties | Coordinate suppliers, insurers and specialists |
Cyvra has worked across hospitality, healthcare, finance, professional services and complex multi-site environments. Senior consultants, no junior delivery teams.
Meet your incident reporting obligations
Multiple regulations impose specific notification deadlines. Getting those procedures wrong after a breach compounds the problem with regulatory penalties on top of breach costs.
72-hour notification to the ICO
UK law — Any personal data breach posing a risk to individuals must be reported to the ICO within 72 hours of becoming aware of it. Notification to affected individuals is required where the risk to them is high. Records of all breaches must be maintained regardless of whether notification is required.
GDPR compliance guide24-hour early warning, 72-hour full report
EU law — may apply to UK organisations with EU operations — NIS2 applies to organisations providing essential or important services within the EU. Significant incidents require an early warning within 24 hours and a full notification within 72 hours. Article 21 also requires documented incident response procedures as a mandatory security measure.
NIS2 compliance guide4-hour early warning for major incidents
EU law — may apply to UK financial entities with EU operations — DORA applies to financial entities operating in the EU. Once a major ICT-related incident is classified, an initial notification is due within 4 hours, or by 10am the next business day if the classification occurs outside business hours. An intermediate report follows within 72 hours and a final report within one month. DORA also mandates regular digital operational resilience testing.
DORA gap analysis guideNotification without undue delay to the relevant CA
UK law — The UK NIS Regulations 2018 require operators of essential services and relevant digital service providers to notify the appropriate competent authority of incidents with a significant impact on service continuity. The UK government has committed to extending these obligations to a wider range of organisations and digital service providers. Verify the current legislative status for the latest position on your sector.
UK Cyber Security and Resilience BillYou may need an Incident Readiness Assessment if...
If you ticked two or more, your plan probably needs testing.
Request an Incident Readiness AssessmentExperience where it matters
What changes when you are genuinely prepared
The objective is not a better document. It is a better response.
Choose where to start
Every engagement is scoped individually. These three structures cover the most common starting points.
With a Cyvra IR Retainer, the relationship is already in place when you need it. No onboarding calls at midnight. No explaining your environment under pressure.
Talk to us about a retainerMany insurers increasingly expect organisations to demonstrate that incident response arrangements exist and have been tested. Cyvra can help you document and evidence what they may ask for.
How ready is your organisation?
Find out where your incident response capability stands and what needs to change before you need it.