Your incident response plan looks good on paper. But will it work under pressure?
Most organisations have an incident response plan. Far fewer have tested whether it actually works. Cyvra helps organisations assess, build and rehearse their cyber incident response capability so when ransomware, a data breach or account compromise happens, your people know who does what, when and why.
There is no time to work out the process
In the first hour of a serious incident, uncertainty costs time, money and credibility. Walk through what your organisation would need to do.
The trigger varies. Ransomware, a data breach, or account compromise. AI-enabled fraud, a deepfake call, or an attack on the AI tools your business has adopted. The response discipline that keeps the business running is the same regardless of the cause.
Two categories matter here: AI used by an attacker to move faster, and AI woven into your own attack surface, including a tool, agent or third-party AI provider you rely on becoming the thing that fails.
Would your organisation know exactly what to do at each step? Find out where the gaps are.
A complete incident readiness programme
Six structured phases that take you from where you are today to a tested, documented and maintained response capability.
Plans, playbooks and procedures you can actually use
Services describe what we do. Deliverables describe what you get. Here is what a full Cyber Incident Readiness programme can produce.
Incident response is a business process, not an IT process
A serious cyber incident demands coordinated action across the whole organisation simultaneously. Your plan needs to reflect that reality.
| Function | What must happen |
|---|---|
| IT and Security | Detect, contain and investigate |
| Leadership | Make business-critical decisions under pressure |
| Legal and Privacy | Assess data and notification obligations |
| Communications | Manage employees, customers and media |
| Operations | Maintain or restore critical services |
| Finance | Manage financial exposure and fraud risk |
| HR | Support affected staff and manage insider considerations |
| Third parties | Coordinate suppliers, insurers and specialists |
Cyvra has worked across hospitality, healthcare, finance, professional services and complex multi-site environments. Senior consultants, no junior delivery teams.
Meet your incident reporting obligations
Multiple regulations impose specific notification deadlines. Getting those procedures wrong after a breach compounds the problem with regulatory penalties on top of breach costs.
72-hour notification to the ICO
UK law: Any personal data breach posing a risk to individuals must be reported to the ICO within 72 hours of becoming aware of it. Notification to affected individuals is required where the risk to them is high. Records of all breaches must be maintained regardless of whether notification is required.
GDPR compliance guide24-hour early warning, 72-hour full report
EU law: NIS2 only reaches a UK organisation if it provides essential or important services within the EU, directly or through an EU subsidiary or branch. Where it applies, significant incidents require an early warning within 24 hours and a full notification within 72 hours, and Article 21 requires documented incident response procedures as a mandatory security measure.
NIS2 compliance guide4-hour early warning for major incidents
EU law: DORA only reaches a UK financial entity if it operates as a financial entity within the EU, directly or through an EU-authorised branch or subsidiary. Where it applies, once a major ICT-related incident is classified, an initial notification is due within 4 hours, or by 10am the next business day if the classification occurs outside business hours, an intermediate report follows within 72 hours, and a final report within one month. DORA also mandates regular digital operational resilience testing.
DORA gap analysis guideNotification without undue delay to the relevant CA
UK law: The UK NIS Regulations 2018 require operators of essential services and relevant digital service providers to notify the appropriate competent authority of incidents with a significant impact on service continuity. The UK government has committed to extending these obligations to a wider range of organisations and digital service providers. Verify the current legislative status for the latest position on your sector.
UK Cyber Security and Resilience BillYou may need an Incident Readiness Assessment if...
If you ticked two or more, your plan probably needs testing.
Request an Incident Readiness AssessmentExperience where it matters
What changes when you are genuinely prepared
The objective is not a better document. It is a better response.
Choose where to start
Every engagement is scoped individually. These three structures cover the most common starting points.
With a Cyvra IR Retainer, the relationship is already in place when you need it. No onboarding calls at midnight. No explaining your environment under pressure.
Talk to us about a retainerMany insurers increasingly expect organisations to demonstrate that incident response arrangements exist and have been tested. Cyvra can help you document and evidence what they may ask for.
How ready is your organisation?
Find out where your incident response capability stands and what needs to change before you need it.