Security & Compliance

Decide It Now, Not at 2 A.m.

Readiness is the cheap half of incident response: the plan, the roles, the notification clocks, the tabletop that finds the gaps while nothing is burning. We build that, and we’re there if the day comes.

INCIDENT READINESS, FIRST 72 HOURSDECIDED IN ADVANCE
The first 72 hours of an incidentA horizontal timeline divided into six stages, detect, contain, assess, notify, restore, review, with hour markers beneath the line at 0, 4, 12, 24, 48, 60 and 72 hours. Above the line, three brackets show notification windows agreed in advance: the insurer’s policy condition across the first 12 hours, the regulator’s statutory clock across the first 48, and contractual notice to customers from 24 hours onward.NOTIFICATION WINDOWS · AGREED IN ADVANCEINSURER · POLICY CONDITIONCUSTOMERS · CONTRACTUALREGULATOR · STATUTORY CLOCKDETECTCONTAINASSESSNOTIFYRESTOREREVIEW0H4H12H24H48H60H72HSCHEMATIC · EACH OBLIGATION HAS ITS OWN CLOCK
Schematic. Your windows come from your own statutes, contracts and policy conditions.

The problem

The Plan Nobody Has Read Is Not a Plan

Most organizations have an incident response document. Fewer have one that names the person who decides to notify, the counsel who gets called first, the threshold that makes something reportable, or where the backups are proven to restore from.

In a regulated business the clock starts before you understand what happened. HIPAA, state breach statutes, contractual obligations, cyber insurance conditions, and the SEC’s disclosure rules for public filers each carry their own timing and their own audience. Working that out live is how a manageable incident becomes a reportable failure.

How we help

Prepare, Exercise, Respond, Learn

Plan and Playbooks

An incident response plan people can follow under pressure, with playbooks for the scenarios you’re actually exposed to.

Roles and Escalation

Who decides, who speaks, who calls counsel and the carrier, and the authority each of them holds.

Notification Analysis

Your obligations mapped in advance: regulator, customer, partner, insurer, and the clock on each.

Tabletop Exercises

Facilitated, adversarial, and specific to your environment, including an AI-related scenario, which most plans don’t cover.

Response Support

Coordination, technical direction, and evidence discipline when something is live, alongside your counsel and forensics.

After-Action

The lessons written down and turned into controls, which is the only part that reduces the next incident.

Scope

IR plan and playbooks · roles, RACI, and escalation · notification and regulatory obligation mapping · tabletop and functional exercises · retainer-based response support · forensics and counsel coordination · post-incident review · resilience and recovery validation

What you get

A Plan That Has Been Tested

  • An IR plan and scenario playbooks, current and owned
  • A notification decision tree with the clocks on it
  • Exercise findings, and the fixes tracked to closure
  • Contact trees for counsel, carrier, forensics, and key customers
  • A team that has practiced the first hour before living it
Proof

Fourteen years, 1,000+ engagements, and a 100% breach-free record across active vCISO and preventative consulting engagements, the strongest argument we can make for spending on readiness rather than response.

Continuous assurance

The Work Stays Proven after We Hand It Over

The CyRisk platform keeps the plan, the exercise record, and the remediation items live, so the plan on the shelf is the plan in force.

CyRisk is 4A’s sister platform. Where our work for CyRisk appears on this site, we disclose the affiliation.

Be Ready before You Need to Be