Heights Consulting Group

Incident Response and Breach Retainer

An incident response retainer puts a response team, a contact path and an agreed authority to act in place before an incident, so that when one happens the first hours go to containment and recovery rather than to finding help, and the notifications that follow are handled on the deadlines that apply.

What you receive

Part of
Finding out what an attacker could do before one tries, and being ready to act when one does.
Engaged as
A defined piece of work, or as part of an ongoing vCISO engagement.
Sits under
Executive ownership of the cybersecurity program.

The service

What this engagement is

Who it is for

  • Organizations whose response plan names a role no one has actually filled.
  • Companies whose cyber-insurance policy expects a response arrangement to be in place.
  • Businesses that have had a near miss and do not want to improvise the next one.
  • Leadership teams that want a single number to call and a known person on the other end.

A standing arrangement: a named team that knows your environment, a contact path that works at any hour, authority to contain agreed in advance with leadership, and a response process that runs through investigation, eradication and recovery to the after-action review.

The retainer is engaged before anything has happened. Onboarding covers the environment, the contacts, the insurance and legal relationships, and the notification obligations, so that on the day nobody has to be briefed.

Scope

What Heights does

  • Onboarding and readiness

    Environment, contacts, authority and obligations captured up front, reviewed on a fixed cadence.

  • Triage and containment

    Rapid assessment of what is happening and what to isolate, under the authority agreed in advance.

  • Investigation and eradication

    Establishing how access was gained, what was reached, and removing it, with evidence preserved for counsel and insurers.

  • Recovery

    Restoring systems in an order that reflects what the business needs first, and verifying they are clean before they return.

  • Notification and communication

    Regulatory, contractual, insurer and customer notifications handled on the deadlines that apply, with counsel where required.

  • After-action review

    What happened, what worked, what did not, and the changes to plan, controls and contracts that follow.

The problem

Why this comes up

The first hours of an incident are spent, in most organizations, finding someone to call, agreeing what they may touch, and explaining the environment to them. Every one of those hours is time an attacker keeps.

The second cost arrives later. Regulators, insurers, customers and counsel each have notification expectations and deadlines, and an organization discovering them during the incident discovers them late.

Timing

When organizations engage this

  • A phishing compromise, ransomware note or unexplained outage has already happened once.
  • The response plan assigns duties to an outside party that has never been engaged.
  • An insurer, customer or regulator asks who would respond to an incident and how quickly.
  • The organization holds data with notification deadlines measured in hours or days.
  • Leadership is not confident who has the authority to shut something down.

What you receive

  • A retainer agreement with contact path, response commitments and authority to act
  • An onboarding record of the environment, contacts and notification obligations
  • Incident documentation preserved for counsel, insurers and regulators
  • An after-action report with remediation actions tracked to closure

Alignment

Frameworks this work touches

Establishing which of these apply to you

NIST CSF
A widely used structure for organizing a security program around outcomes rather than products. Its current version adds an explicit governance function, which is why it maps well onto executive-level work.
HIPAA
The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates.
PCI DSS
Prescriptive control requirements imposed through payment brand agreements wherever cardholder data is stored, processed or transmitted. Scope reduction is usually the highest-leverage decision available.
SOC 2
An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant.
CMMC
NIST SP 800-171 sets the security requirements for protecting controlled unclassified information in non-federal systems. CMMC is the program under which contractors demonstrate that implementation, by self-assessment or third-party assessment depending on level.

The flagship

Response is what happens when prevention has not held. The vCISO owns the plan the response runs on, the decisions leadership must make during it, and the changes to the program afterward. With both under one leadership, an incident becomes evidence rather than only damage.

Read about vCISO leadership

First steps

How an engagement begins

The same three steps whichever service you start with.

  1. A confidential conversation

    What prompted the enquiry, what you are obliged to do, and what leadership is being asked to answer for. No cost, no obligation.

  2. Scope agreed in writing

    What Heights will do, what stays with you, the working rhythm, and how progress will be reported.

  3. Work begins

    Delivered by your team, your providers or Heights, with expectations and acceptance criteria stated up front.

FAQ

Questions we are asked about this

Broader questions about executive security leadership are answered on the vCISO page.

What is the difference between the retainer and incident readiness planning?

Readiness planning writes and exercises the plan: roles, criteria, escalation, tabletops. The retainer is the team that acts on it when an incident is real.

They are separate engagements because some organizations already have a plan and need responders, and others have responders under contract and need a plan those responders can follow.

Does the retainer work with our cyber-insurance panel?

It is set up to. Onboarding records the carrier, the policy notification requirements and any panel obligations, and the response process is written to preserve coverage rather than jeopardize it.

Where a policy requires the carrier's own responders or counsel to be engaged, the retainer coordinates with them rather than competing with them.

Who decides to shut a system down during an incident?

The person leadership named during onboarding, within the limits leadership set. Containment authority is agreed before the retainer goes live, including what may be isolated immediately and what needs a call first.

That decision made in advance is the difference between containing an incident in minutes and debating it for an afternoon.

Schedule a Confidential Consultation

Four questions, answered by the person who would be at your table. If Heights is not the right fit for what you need, you will hear that in the first conversation.

In Central Florida? Make it coffee, breakfast, lunch or a drink at the end of the day. Dan buys. Say so in the message and name a part of town.

A short description is enough, what prompted you to get in touch, and what a useful outcome would look like.

Sign in to the employee portal

For Heights employees. Accounts are created by Heights; if you expected one and it has not arrived, contact us.