Resilience and emerging technology

Incident Readiness and Response Planning

Incident readiness means the organization knows in advance who declares an incident, who decides on containment and disclosure, who must be notified and within what deadline, and who speaks for the organization, before an incident forces those decisions in real time.

Schedule a Confidential Consultation What you receive

At a glance

Part of
Preparedness for what goes wrong, and governance for what is arriving.
Engaged as
A defined piece of work, or as part of an ongoing vCISO engagement.
Sits under
Executive ownership of the cybersecurity program.

The service

What this engagement is

Who it is for

  • Organizations whose response plan has never been tested with the people named in it.
  • Companies where it is unclear who has authority to declare an incident or notify customers.
  • Businesses whose customer contracts or insurers require evidence of incident readiness.
  • Leadership teams that have recently experienced an incident or a near miss.

A plan written so it can be followed under pressure, short, specific about roles, and explicit about who decides what, combined with an exercise that tests it against the people it names.

The notification analysis is often the most valuable component. Regulatory and contractual deadlines vary by sector, data type and jurisdiction, and identifying them while the clock is not running is materially easier than doing so while it is.

Scope

What Heights does

  • Incident response plan

    Roles, declaration criteria, severity levels and escalation paths, written to be usable under pressure rather than comprehensive on paper.

  • Decision and disclosure authority

    Who decides on containment, on engaging outside counsel and forensics, on customer communication and on regulatory notification.

  • Notification obligations

    The regulatory and contractual notification duties and deadlines that apply to your organization, identified before they are running.

  • Tabletop exercises

    Scenario-based exercises with the executive team and IT, run against the plan exactly as written.

  • Post-exercise remediation

    Findings fed back into the plan, the contact lists, the contracts and the controls, the step most often skipped.

Why this comes up

The technical parts of incident response are usually the parts organizations have partly covered. The gaps are decision authority, notification obligations, legal and communications coordination, and the fact that the plan has often never been read by the people it names.

Those gaps only become visible under pressure, when the cost of resolving them is highest and the time available is shortest.

Timing

When organizations engage this

  • The response plan has never been tested with the executives it names.
  • A customer contract or insurer requires evidence of incident readiness.
  • It is unclear who has authority to declare an incident or notify customers and regulators.
  • A recent incident or near miss exposed coordination problems.
  • The people named in the plan have changed roles or left the organization.

What you receive

  • Incident response plan with roles, severity levels and escalation criteria
  • Notification obligation summary and current contact list
  • Tabletop exercise scenario and a facilitated session
  • Exercise findings report with tracked remediation actions

Alignment

Frameworks this work touches

Establishing which of these apply to you

NIST CSF
A widely used structure for organizing a security program around outcomes rather than products. Its current version adds an explicit governance function, which is why it maps well onto executive-level work.
ISO 27001
An international standard for an information security management system: the governance, risk treatment and continual improvement processes around security, rather than a fixed control list.
HIPAA
The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates.
SOC 2
An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant.
CMMC
NIST SP 800-171 sets the security requirements for protecting controlled unclassified information in non-federal systems. CMMC is the program under which contractors demonstrate that implementation, by self-assessment or third-party assessment depending on level.

A vCISO keeps readiness current as the organization changes, new systems, new obligations, new people in the roles the plan names, and coordinates leadership if an incident actually occurs.

Read about vCISO leadership

Getting started

How an engagement begins

The same three steps whichever service you start with.

  1. A confidential conversation

    What prompted the enquiry, what you are obliged to do, and what leadership is being asked to answer for. No cost, no obligation.

  2. Scope agreed in writing

    What Heights will do, what stays with you, the working rhythm, and how progress will be reported.

  3. Work begins

    Delivered by your team, your providers or Heights, with expectations and acceptance criteria stated up front.

Questions we are asked about this

Broader questions about executive security leadership are answered on the vCISO page.

Who should take part in a tabletop exercise?

The people the plan actually names. That usually means the chief executive or an equivalent decision maker, IT leadership, legal or general counsel, communications, and whoever manages key customer relationships.

An exercise run only with the technical team tests the technical response and leaves the decision-making gaps, which are the ones that most often extend an incident, untested.

Does Heights respond to a live incident?

Under a vCISO engagement, Heights coordinates the leadership response: convening the right people, tracking decisions, managing notification obligations and handling executive and board communication.

Digital forensics and specialist incident response are separate disciplines, and part of readiness work is identifying which firm you would engage and establishing the relationship before you need it.

How often should the plan be exercised?

Annually is a reasonable baseline for most organizations, with an additional exercise after a significant change, a new core system, a merger, or turnover in the roles the plan names.

A plan naming people who left eighteen months ago is not a plan.

Talk through Incident Readiness and Response Planning with us.

Tell us what prompted the enquiry and what the organization is working toward. You will get a straight view of the right scope, including when that is smaller than you expected.