Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Service

An incident response plan your team has practiced before it's needed

We help you write an incident response plan that fits your organization and test it through tabletop exercises, so decision-makers know their roles before a real incident.

What we deliver

Incident-readiness services: response-plan development and tabletop exercises.

References
NIST CSF 2.0NIST SP 800-61 Rev. 3

Who it's for

A good fit for

  • Organizations without a written incident response plan, or with one no one has read recently
  • Leadership teams that want to rehearse decisions about communication, escalation, and outside help
  • Companies whose cyber insurer, customers, or regulators expect a documented and tested plan
  • Security and IT teams that want to test how they coordinate with legal, communications, and executives

Not the right fit for

  • Anyone handling an active incident right now
  • Organizations that need ongoing security monitoring or a managed detection service
  • Teams that need forensic investigation, containment, or recovery work performed for them

Problems it addresses

  • The incident response plan is outdated, generic, or unknown to the people named in it.
  • No one is sure who decides when to call the insurer, outside counsel, or law enforcement.
  • Technical staff know how to investigate but not how to escalate to leadership.
  • Notification steps that your counsel has identified aren't reflected in the plan.
  • The team has never practiced a response together.

Scope

Included

  • Writing or revising your incident response plan, with roles, severity levels, escalation paths, and decision points
  • Playbooks for the scenarios that matter most to you, such as ransomware, business email compromise, or a cloud account takeover
  • Contact and escalation lists covering internal roles, your insurer, outside counsel, and key vendors
  • Tabletop exercises for executives, technical teams, or both, built around realistic scenarios for your environment
  • An after-action report with the gaps found and recommended plan updates

Not included

  • Forensic investigation, containment, eradication, or system recovery
  • Security monitoring or managed detection
  • Legal advice on notification obligations
  • We don't provide emergency incident response. If you're dealing with an active incident, contact your cyber insurer's breach hotline, your legal counsel, or law enforcement.

Ways to engage

Incident response plan and tabletop

A project to write or refresh your plan and playbooks and test them through tabletop exercises, finishing with an after-action report and an updated plan.

Price
Incident Response Plan and Tabletop: from $6,500; typical $6,500–$15,000

Priority incident advisory retainer

An annual retainer for organizations that want priority advisory access from practitioners who already know their plan and environment. What's included is set out in the signed retainer.

Price
Priority Incident Advisory Retainer: from $18,000/year; typical $18,000–$60,000/year

Priority advisory for retainer clients, with after-hours paging from 6:00 a.m. to 10:00 p.m. Central Time every day and an acknowledgement target of 60 minutes during the contracted paging window. Not a round-the-clock service. Terms are set by the signed retainer.

The Priority Incident Advisory Retainer provides advisory guidance to clients with a signed retainer. It isn't emergency incident response, security monitoring, forensic investigation, containment, or recovery, and its terms are set by the signed retainer.

Deliverables

  • Incident response plan tailored to your organization
  • Scenario playbooks and escalation contact lists
  • Tabletop exercise materials: scenario, injects, and facilitator guide
  • After-action report with findings and prioritized improvements
  • Updated plan that reflects lessons from the exercise

How the engagement runs

Every engagement begins with a written scope and proposal.

  1. Understand

    We review existing plans, insurance requirements, key systems, and the people who'd be involved in a response.

  2. Write or revise the plan

    We draft the plan and playbooks with your team so roles and decisions are clear and realistic.

  3. Design the exercise

    We build a tabletop scenario around threats relevant to your business, with injects that test decisions as well as technical steps.

  4. Run the tabletop

    We facilitate the exercise and record decisions, delays, and open questions as they come up.

  5. Improve

    We deliver an after-action report and update the plan based on what the exercise revealed.

Standards and methods

  • NIST SP 800-61 Rev. 3, incident response recommendations organized around NIST CSF 2.0
  • NIST SP 800-84 guidance on designing and running tabletop exercises
  • NIST CSF 2.0 Respond and Recover functions

What NIST SP 800-61 Rev. 3 changed

NIST published SP 800-61 Revision 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile, in April 2025. It supersedes Revision 2 from August 2012.

Revision 2 described incident response as its own cycle of four phases: preparation; detection and analysis; containment, eradication, and recovery; and post-incident activity. Revision 3 treats incident response as part of cybersecurity risk management across the organization, and organizes its recommendations around the six CSF 2.0 Functions: Govern, Identify, Protect, Detect, Respond, and Recover.

NIST's reasoning is practical. Incidents now happen often, can be broad, and can take weeks or months to recover from, so lessons learned should be shared as soon as they're identified instead of waiting until recovery ends. NIST also says organizations should use whichever incident response life cycle model suits them best, and that every organization should consider incident response throughout its risk management activities.

Source: NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management

Tabletop scenarios and government exercise material

A tabletop exercise tests a plan by talking through a realistic scenario, so the scenario should reflect risks your organization actually faces.

CISA publishes Tabletop Exercise Packages (CTEPs) to help organizations run their own exercises. Each package provides template exercise objectives, scenarios, and discussion questions, plus references and resources, and covers information sharing before an incident, incident response, and recovery. Cybersecurity scenarios include ransomware, phishing, insider threats, and industrial control system compromises, and there are sector-specific packages, including healthcare.

NIST SP 800-84, Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities (September 2006), covers designing, developing, conducting, and evaluating tabletop exercises, and its appendices include a sample facilitator guide, participant guide, and after action report. Its method applies to any IT plan, including an incident response plan.

Sources: CISA: Tabletop Exercise Packages; NIST SP 800-84: Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities

Prerequisites and your responsibilities

  • An executive sponsor, and leadership participation in the tabletop
  • Your cyber insurance policy details and any incident response requirements it sets
  • Contact details for outside counsel and the key vendors you'd rely on during an incident
  • Participants from IT, security, legal, communications, and operations, as the scenario requires

Pricing

  • Incident Response Plan and Tabletop

    From $6,500

    Typical scoped range: $6,500 to $15,000

    One-time project

  • Priority Incident Advisory Retainer

    From $18,000/year

    Typical scoped range: $18,000 to $60,000/year

    Annual

Non-binding. Final pricing follows a written scope and proposal.

What affects the final price

Pricing depends on environment size, complexity, testing depth, locations, applications, accounts, user roles, compliance objectives, and delivery timeline. Every engagement begins with a written scope and proposal. Taxes, travel, remediation, third-party audit or certification fees, licensing, and emergency work are separate. Readiness services do not include independent certification, attestation, legal advice, or a guarantee of passing.

Compare published prices for every service

Guides

Frequently asked questions

What does a tabletop exercise involve?

Participants work through a realistic scenario that unfolds in stages. At each stage a facilitator adds new information and asks what the group would do, who would decide, and who they'd call. It's discussion-based: no systems are touched, and the goal is to find gaps in the plan, not to grade people.

Who should take part?

It depends on the scenario. Executive exercises focus on decisions about communication, outside help, and business impact. Technical exercises focus on detection, investigation, and escalation. Many organizations run both, or a combined session with separate tracks.

We already have a plan from a template. Is that enough?

A template is a start, but plans break down when they don't match your people, systems, and obligations. We review what you have, keep what works, rewrite what doesn't, and then test it so you know it holds up.

Can the plan include our cyber insurer's requirements?

Yes. Cyber insurance policies often specify who to call first and which vendors to use. We build those steps into the plan and escalation lists so your team doesn't discover them in the middle of an incident.

Primary sources

Talk to a practitioner about incident readiness

Share what’s prompting the work and what you need to decide, and we’ll help you judge whether this service is the right fit.

What happens next

  1. Tell us about your environment and what's driving the request.
  2. Talk through goals, constraints, and options with a practitioner.
  3. Review the proposal and decide whether to go ahead.