Cyber Incident Readiness

Your incident response plan looks good on paper. But will it work under pressure?

Most organisations have an incident response plan. Far fewer have tested whether it actually works. Cyvra helps organisations assess, build and rehearse their cyber incident response capability so when ransomware, a data breach or account compromise happens, your people know who does what, when and why.

When an incident happens

There is no time to work out the process

In the first hour of a serious incident, uncertainty costs time, money and credibility. Walk through what your organisation would need to do.

00:00
Detection
Suspicious activity identified via SIEM alerts, endpoint tools or staff report. Who receives it? Who decides it warrants attention?
00:10
Triage
Is this a real incident? Who has the authority to declare it? What is the initial classification? Who is in the room?
00:20
Escalation
Technical, legal, management and communications teams engaged. Who calls whom? Are the contact details current?
00:30
Containment
First containment decisions made. Which systems? Which accounts? Who authorises the action? What breaks if you isolate it?
00:45
Assessment
Scope and impact understood. What data is affected? Which systems? What is the likely attacker objective?
01:00
Decisions
Regulatory notifications, customer communications, executive briefing and board notification. All simultaneously. With a clock running.

Would your organisation know exactly what to do at each step? Find out where the gaps are.

How we make you incident-ready

A complete incident readiness programme

Six structured phases that take you from where you are today to a tested, documented and maintained response capability.

01
Assess
Where are you today?
We review your existing incident response capability, documentation, technology, roles, escalation paths and dependencies. You receive a scored maturity report against NIST SP 800-61 and ISO/IEC 27035.
02
Build
Build the right framework
We build or improve your incident response framework around your organisation, threat landscape and regulatory obligations. Not a generic template adapted to fit.
03
Prepare
Create the tools your team needs
We create practical incident playbooks for the threats most relevant to your business, contact trees, escalation procedures, notification templates and communications guides.
04
Rehearse
Test it against realistic scenarios
We run a realistic tabletop exercise with the people who would actually respond, including leadership, legal and communications. Scenarios are built around your real threat landscape.
05
Remediate
Turn findings into actions
You receive a prioritised findings report and remediation roadmap. Every gap identified in the exercise becomes a tracked action with an owner and a deadline.
06
Maintain
Keep the capability current
Annual reviews and exercises keep the capability current as your organisation, infrastructure and threat landscape change. Readiness is not a project state.
And if an incident actually occurs? Cyvra also provides retained incident-response advisory for organisations that want pre-agreed access to specialist guidance when they need it most. See what's included below.
What you receive

Plans, playbooks and procedures you can actually use

Services describe what we do. Deliverables describe what you get. Here is what a full Cyber Incident Readiness programme can produce.

Incident Response Framework
Incident response policy
Roles and responsibilities matrix
Incident classification matrix
Escalation criteria and thresholds
Decision trees for major incident types
Incident Playbooks
Ransomware response
Business email compromise
Account compromise
Data breach
Data exfiltration
Critical supplier compromise
Crisis Communications
Internal escalation procedures
Board communications template
Customer communications template
Regulatory notification procedures
Holding statements
Pre-populated contact directory
Testing and Assurance
Tabletop exercise facilitation
Exercise scenario pack
Facilitator briefing pack
Post-exercise findings report
Prioritised remediation roadmap
Beyond IT

Incident response is a business process, not an IT process

A serious cyber incident demands coordinated action across the whole organisation simultaneously. Your plan needs to reflect that reality.

Function What must happen
IT and SecurityDetect, contain and investigate
LeadershipMake business-critical decisions under pressure
Legal and PrivacyAssess data and notification obligations
CommunicationsManage employees, customers and media
OperationsMaintain or restore critical services
FinanceManage financial exposure and fraud risk
HRSupport affected staff and manage insider considerations
Third partiesCoordinate suppliers, insurers and specialists
What Cyvra's programme delivers across functions
Each function understands its role before an incident, not during one
Escalation paths are tested, not assumed
Tabletop exercises include leadership, legal and communications, not just technical teams
Board-level questions are addressed: what happens to the business while IT deals with the attack?
Communications templates are ready for customers, media and regulators before you need them

Cyvra has worked across hospitality, healthcare, finance, professional services and complex multi-site environments. Senior consultants, no junior delivery teams.

Regulatory requirements

Meet your incident reporting obligations

Multiple regulations impose specific notification deadlines. Getting those procedures wrong after a breach compounds the problem with regulatory penalties on top of breach costs.

UK GDPR
Personal Data Breach Notification

72-hour notification to the ICO

UK law — Any personal data breach posing a risk to individuals must be reported to the ICO within 72 hours of becoming aware of it. Notification to affected individuals is required where the risk to them is high. Records of all breaches must be maintained regardless of whether notification is required.

GDPR compliance guide
NIS2 Directive
Significant Incident Reporting

24-hour early warning, 72-hour full report

EU law — may apply to UK organisations with EU operations — NIS2 applies to organisations providing essential or important services within the EU. Significant incidents require an early warning within 24 hours and a full notification within 72 hours. Article 21 also requires documented incident response procedures as a mandatory security measure.

NIS2 compliance guide
DORA
ICT Incident Classification and Reporting

4-hour early warning for major incidents

EU law — may apply to UK financial entities with EU operations — DORA applies to financial entities operating in the EU. Once a major ICT-related incident is classified, an initial notification is due within 4 hours, or by 10am the next business day if the classification occurs outside business hours. An intermediate report follows within 72 hours and a final report within one month. DORA also mandates regular digital operational resilience testing.

DORA gap analysis guide
UK NIS Regulations
Network and Information Systems Incidents

Notification without undue delay to the relevant CA

UK law — The UK NIS Regulations 2018 require operators of essential services and relevant digital service providers to notify the appropriate competent authority of incidents with a significant impact on service continuity. The UK government has committed to extending these obligations to a wider range of organisations and digital service providers. Verify the current legislative status for the latest position on your sector.

UK Cyber Security and Resilience Bill
How ready is your organisation?

You may need an Incident Readiness Assessment if...

If you ticked two or more, your plan probably needs testing.

Request an Incident Readiness Assessment
Why organisations choose Cyvra

Experience where it matters

20+
Years of experience
IT, cybersecurity and resilience consulting across enterprises, regulated industries and complex multi-site environments.
200+
Organisations supported
Across hospitality, healthcare, financial services, professional services and the public sector in the UK, Netherlands and Brazil.
Senior
Consultants, not account managers
No junior delivery teams. The consultants you meet at the start are the ones who do the work. Certifications including CISM and Security+.
Sector experience: We have delivered incident readiness work across hospitality and leisure, healthcare and life sciences, financial services, legal and professional services, and logistics. Organisations with complex supply chains, overseas operations and regulated data environments are where we spend most of our time.
The transformation

What changes when you are genuinely prepared

Before
Roles and responsibilities unclear under pressure
Contact lists untested and outdated
Generic IR plan, not scenario-specific
No rehearsed decision-making process
Notification obligations uncertain when needed
Board and leadership unsure of their role
No documented improvement path after incidents
After
Defined incident command structure
Tested escalation paths with current contacts
Scenario-specific playbooks for your threat landscape
Rehearsed decision-making across all functions
Documented notification procedures with timeline clarity
Board and leadership prepared with clear roles
Prioritised remediation roadmap with tracked actions

The objective is not a better document. It is a better response.

Engagement options

Choose where to start

Every engagement is scoped individually. These three structures cover the most common starting points.

Assess
Incident Readiness Assessment
For organisations that want to understand their current position before committing to a full programme.
Document review and gap analysis
Stakeholder interviews across IT, legal, leadership and communications
Maturity scoring against NIST SP 800-61 and ISO/IEC 27035
Prioritised gap list and 90-day remediation roadmap
OutcomeKnow exactly where you stand and what needs to change.
Get started
Maintain
Incident Readiness Retainer
For organisations that want their response capability to remain current as the organisation evolves.
Annual plan review and update
Annual tabletop exercise
Regulatory change monitoring and plan amendments
Advisory support for incidents and near-misses
Incident activation support if needed
OutcomeReadiness that doesn't decay after the project ends.
Get started
And if the incident happens?
Don't start looking for a response partner after the breach

With a Cyvra IR Retainer, the relationship is already in place when you need it. No onboarding calls at midnight. No explaining your environment under pressure.

Talk to us about a retainer
What's included
Pre-agreed response arrangements
Known escalation contacts on both sides
Immediate access to senior consultants
Incident triage and classification support
Containment decision guidance
Evidence preservation guidance
Regulatory notification coordination
Executive and board-level incident support
Cyber insurance
Supporting your insurance requirements

Many insurers increasingly expect organisations to demonstrate that incident response arrangements exist and have been tested. Cyvra can help you document and evidence what they may ask for.

Incident response procedures
Roles and responsibilities documentation
Escalation processes
Exercise history and reports
Remediation action logs
Response contact directories
Lessons learned documentation
Maturity assessment results

How ready is your organisation?

Find out where your incident response capability stands and what needs to change before you need it.