Service
Virtual CISO
Security leadership without a full-time hire
Service
We help you write an incident response plan that fits your organization and test it through tabletop exercises, so decision-makers know their roles before a real incident.
What we deliver
Incident-readiness services: response-plan development and tabletop exercises.
A project to write or refresh your plan and playbooks and test them through tabletop exercises, finishing with an after-action report and an updated plan.
An annual retainer for organizations that want priority advisory access from practitioners who already know their plan and environment. What's included is set out in the signed retainer.
Priority advisory for retainer clients, with after-hours paging from 6:00 a.m. to 10:00 p.m. Central Time every day and an acknowledgement target of 60 minutes during the contracted paging window. Not a round-the-clock service. Terms are set by the signed retainer.
The Priority Incident Advisory Retainer provides advisory guidance to clients with a signed retainer. It isn't emergency incident response, security monitoring, forensic investigation, containment, or recovery, and its terms are set by the signed retainer.
Every engagement begins with a written scope and proposal.
We review existing plans, insurance requirements, key systems, and the people who'd be involved in a response.
We draft the plan and playbooks with your team so roles and decisions are clear and realistic.
We build a tabletop scenario around threats relevant to your business, with injects that test decisions as well as technical steps.
We facilitate the exercise and record decisions, delays, and open questions as they come up.
We deliver an after-action report and update the plan based on what the exercise revealed.
NIST published SP 800-61 Revision 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile, in April 2025. It supersedes Revision 2 from August 2012.
Revision 2 described incident response as its own cycle of four phases: preparation; detection and analysis; containment, eradication, and recovery; and post-incident activity. Revision 3 treats incident response as part of cybersecurity risk management across the organization, and organizes its recommendations around the six CSF 2.0 Functions: Govern, Identify, Protect, Detect, Respond, and Recover.
NIST's reasoning is practical. Incidents now happen often, can be broad, and can take weeks or months to recover from, so lessons learned should be shared as soon as they're identified instead of waiting until recovery ends. NIST also says organizations should use whichever incident response life cycle model suits them best, and that every organization should consider incident response throughout its risk management activities.
Read the full guide: Incident response plan guide: write it, then test it
A tabletop exercise tests a plan by talking through a realistic scenario, so the scenario should reflect risks your organization actually faces.
CISA publishes Tabletop Exercise Packages (CTEPs) to help organizations run their own exercises. Each package provides template exercise objectives, scenarios, and discussion questions, plus references and resources, and covers information sharing before an incident, incident response, and recovery. Cybersecurity scenarios include ransomware, phishing, insider threats, and industrial control system compromises, and there are sector-specific packages, including healthcare.
NIST SP 800-84, Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities (September 2006), covers designing, developing, conducting, and evaluating tabletop exercises, and its appendices include a sample facilitator guide, participant guide, and after action report. Its method applies to any IT plan, including an incident response plan.
Sources: CISA: Tabletop Exercise Packages; NIST SP 800-84: Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities
From $6,500
Typical scoped range: $6,500 to $15,000
One-time project
From $18,000/year
Typical scoped range: $18,000 to $60,000/year
Annual
Non-binding. Final pricing follows a written scope and proposal.
Pricing depends on environment size, complexity, testing depth, locations, applications, accounts, user roles, compliance objectives, and delivery timeline. Every engagement begins with a written scope and proposal. Taxes, travel, remediation, third-party audit or certification fees, licensing, and emergency work are separate. Readiness services do not include independent certification, attestation, legal advice, or a guarantee of passing.
Participants work through a realistic scenario that unfolds in stages. At each stage a facilitator adds new information and asks what the group would do, who would decide, and who they'd call. It's discussion-based: no systems are touched, and the goal is to find gaps in the plan, not to grade people.
It depends on the scenario. Executive exercises focus on decisions about communication, outside help, and business impact. Technical exercises focus on detection, investigation, and escalation. Many organizations run both, or a combined session with separate tracks.
A template is a start, but plans break down when they don't match your people, systems, and obligations. We review what you have, keep what works, rewrite what doesn't, and then test it so you know it holds up.
Yes. Cyber insurance policies often specify who to call first and which vendors to use. We build those steps into the plan and escalation lists so your team doesn't discover them in the middle of an incident.
Share what’s prompting the work and what you need to decide, and we’ll help you judge whether this service is the right fit.