Home › Incident Response and Crisis Management

Incident Response and Crisis Management

When an incident occurs, the first hours determine how much it ultimately costs. We lead the response alongside your counsel and insurer: taking command of the effort, establishing what happened, managing extortion demands, determining notification obligations, and directing the remediation that follows.

Organizations that establish a retainer in advance begin response immediately, with engagement terms, confidentiality, and pre-payment already in place. Before an incident, the same team builds the plans, playbooks, and exercises that make the response faster when it counts.

Services in this practice

  • Incident Response Retainer. Contract before the crisis: a committed response time, prepaid response hours, and a responder who already knows your environment.

  • Incident Command and Executive Advisory. Incident command and decision support for executives and boards, coordinating counsel, insurers, forensics, and technical teams under pressure.

  • Digital Forensics and Investigation. Forensic investigation that establishes what happened: defensible evidence preservation, timeline, initial access, lateral movement, and exfiltration.

  • Ransomware and Extortion Response. End-to-end ransomware and extortion response: threat actor assessment, negotiation, sanctions analysis, settlement facilitation if chosen, and recovery.

  • Breach Notification Analysis. Determine breach notification obligations across states and regimes, identify affected parties, and meet statutory deadlines in coordination with counsel.

  • Post-Incident Assessment and Root Cause Analysis. Independent post-incident review of root cause, control failures, and response performance, with findings suitable for boards, regulators, and insurers.

  • Post-Incident Remediation Program Management. Direct remediation after an incident, from containment and hardening to root cause fixes, with the evidence trail regulators and customers expect.

  • Incident Response Plan and Playbook Development. An incident response plan and scenario playbooks for ransomware, business email compromise, exfiltration, insider events, and third-party compromise.

  • Tabletop Exercises. Technical, executive, and board tabletop exercises built on realistic scenarios from your environment, exposing decision gaps before an incident does.

  • Ransomware Readiness Assessment. Test your resistance to and recoverability from ransomware: access vectors, privileged access, backup isolation, recovery time, and decision framework.

  • Business Continuity and Disaster Recovery Assessment. Evaluate continuity and recovery capability, including business impact analysis, tested recovery objectives, dependency mapping, and exercise programs.

  • Threat Intelligence and Exposure Monitoring. Monitor leaked credentials, extortion site mentions, brand impersonation, and attack surface changes, with threat briefings relevant to your sector.

How engagements work

Every engagement is scoped individually and conducted under a master services agreement and mutual confidentiality terms. Work begins with a scoping conversation to understand your objectives, constraints, and deadlines, followed by a written statement of work defining scope, deliverables, and timeline. Both parties retain the right to decline an engagement where the fit is not right.

Frequently asked questions

What is an incident response retainer?

An incident response retainer is an agreement established before an incident that commits a responder to a defined response time and prepaid response capacity. Because contracting, confidentiality, and environment familiarization are complete in advance, response begins immediately. Unused capacity is applied to readiness work such as tabletop exercises and plan development.

Should we pay a ransom?

Whether to pay is a business and legal decision that depends on recoverability, the data involved, the threat actor, sanctions exposure, and insurance terms. Payments to sanctioned parties may be unlawful, so sanctions screening and legal analysis are essential before any payment. We advise on the full decision set, including not paying, and document the analysis behind the decision.

We are experiencing an incident right now. What should we do?

Preserve evidence, avoid wiping or rebuilding affected systems until they have been imaged, notify your counsel and cyber insurer, and contact us through the emergency incident response page. We establish confidentiality and engagement terms immediately so response can begin.

Services in this practice

12 services. Each has its own page describing scope, who it is for, and what you receive.

Incident Response Retainer

Contract before the crisis: a committed response time, prepaid response hours, and a responder who already knows your environment.

Incident Command and Executive Advisory

Incident command and decision support for executives and boards, coordinating counsel, insurers, forensics, and technical teams under pressure.

Digital Forensics and Investigation

Forensic investigation that establishes what happened: defensible evidence preservation, timeline, initial access, lateral movement, and exfiltration.

Ransomware and Extortion Response

End-to-end ransomware and extortion response: threat actor assessment, negotiation, sanctions analysis, settlement facilitation if chosen, and recovery.

Breach Notification Analysis

Determine breach notification obligations across states and regimes, identify affected parties, and meet statutory deadlines in coordination with counsel.

Post-Incident Assessment and Root Cause Analysis

Independent post-incident review of root cause, control failures, and response performance, with findings suitable for boards, regulators, and insurers.

Post-Incident Remediation Program Management

Direct remediation after an incident, from containment and hardening to root cause fixes, with the evidence trail regulators and customers expect.

Incident Response Plan and Playbook Development

An incident response plan and scenario playbooks for ransomware, business email compromise, exfiltration, insider events, and third-party compromise.

Tabletop Exercises

Technical, executive, and board tabletop exercises built on realistic scenarios from your environment, exposing decision gaps before an incident does.

Ransomware Readiness Assessment

Test your resistance to and recoverability from ransomware: access vectors, privileged access, backup isolation, recovery time, and decision framework.

Business Continuity and Disaster Recovery Assessment

Evaluate continuity and recovery capability, including business impact analysis, tested recovery objectives, dependency mapping, and exercise programs.

Threat Intelligence and Exposure Monitoring

Monitor leaked credentials, extortion site mentions, brand impersonation, and attack surface changes, with threat briefings relevant to your sector.

Start with a confidential conversation

Every engagement is scoped individually and begins with a conversation about where your program stands and where it needs to be. Work is conducted under a nondisclosure agreement and a master services agreement.

Consultations are available Monday to Friday, 9:00am to 3:00pm Central.