Incident Response

Incident readiness that turns panic into procedure.

The worst time to build your response is during an attack. SubRosa's incident readiness gets your plans, playbooks, and people ready in advance, so when something goes wrong your team already knows exactly what to do.

Response plans · Playbooks · Training · Tabletop · Gap analysis

Incident readiness, defined

What is incident readiness?

Incident readiness is the work you do before an incident to make sure you can respond well: a tested incident response plan, playbooks for the scenarios most likely to hit you, trained responders, and the tooling and contacts lined up in advance. Rather than reacting from scratch under pressure, a ready organization follows a rehearsed procedure, which is the difference between a contained event and a full-blown crisis.

What we build

Everything you need before the alarm.

We prepare your organization across plans, people, and process.

Response plan development

A clear, tested incident response plan mapped to your environment, roles, and regulatory obligations.

Playbooks & runbooks

Step-by-step playbooks for the incidents most likely to hit you: ransomware, business email compromise, data theft, and more.

Training & tabletop exercises

Hands-on training and facilitated tabletop exercises so your team has run the drill before the real thing.

Readiness gap assessment

An honest assessment of where your current readiness falls short, with a prioritized plan to close the gaps.

How the engagement runs

Readiness work, in the order it matters.

Incident readiness fails in predictable ways: a plan nobody has read, contacts that are out of date, and no agreed authority to make expensive decisions at 3am. This addresses those first.

  1. 01

    Current-state assessment

    We review what exists — plan, playbooks, contacts, prior incidents — and establish what would actually happen today. Most organisations have more documentation than capability, and knowing the gap is the starting point.

  2. 02

    Plan development

    A plan written for your organisation, your systems and your obligations, short enough that someone will read it under pressure. A sixty-page plan is not used during an incident; a clear one is.

  3. 03

    Playbooks for likely scenarios

    Generic plans do not survive contact. We build playbooks for the scenarios you are actually likely to face — ransomware, business email compromise, a compromised supplier — with concrete first steps.

  4. 04

    Roles, authority and contacts

    The most common real failure is nobody knowing who can authorise a shutdown, a ransom decision or a public statement. We define decision authority explicitly, with deputies, and verify the contact list is current rather than assuming it.

  5. 05

    Exercise the plan

    A plan is a hypothesis until it is tested. We run a tabletop against it, which reliably surfaces the assumptions that do not hold.

  6. 06

    Review cadence

    Plans go stale as systems and people change. We agree a review cadence and what triggers an off-cycle update, so the plan stays usable rather than becoming an artefact.

Why SubRosa

Built by people who have run the response.

Real-world plans

Our plans and playbooks come from responders who have handled real breaches, not from a template library.

Tailored to you

Everything is built around your environment, team, and risk profile, not a generic checklist.

Ongoing partnership

We keep your readiness current as your environment and the threat landscape change, and rehearse it with you.

Plans, playbooks, and drills.

Readiness that stays current.

Your plans, playbooks, and exercise results live in Sable, versioned, assigned, and tracked, so readiness is a living program your team can actually reach when an incident hits, not a document nobody can find.

Readiness in Sable
Readiness3 of 5 ready
  • Incident response planReady
  • Ransomware playbookReady
  • Communication templatesGap
  • Tabletop in last 12 monthsGap
  • Escalation & on-call listReady
Plans · playbooks · peopleGaps prioritized

Common questions

What is incident readiness?
Incident readiness is the work you do before an incident to make sure you can respond well: a tested incident response plan, playbooks for the scenarios most likely to hit you, trained responders, and tooling and contacts lined up in advance. A ready organization follows a rehearsed procedure instead of reacting from scratch under pressure.
What does an incident readiness engagement include?
SubRosa builds and tests your incident response plan, develops playbooks for your most likely incident types, trains your team and facilitates tabletop exercises, and runs a readiness gap assessment with a prioritized plan to close the gaps.
What is the difference between incident readiness and incident response?
Readiness is the work done beforehand: the plan, the playbooks, the decision authority, the exercises. Response is what happens during an incident. Readiness is considerably cheaper, and the organisations that handle incidents well are almost always the ones that did it.
We have an incident response plan already. Is that enough?
Possibly not, and it is worth testing rather than assuming. The common failures are a plan nobody has read, a contact list that has gone stale, and no agreed authority to make expensive decisions at 3am. A plan that has never been exercised is a hypothesis.
Who needs to be involved?
More than IT. Legal, communications, HR and an executive decision-maker all have roles in a real incident, and the decisions that cause the most damage are rarely technical. Readiness work that only involves the security team leaves the expensive gaps unaddressed.
How long does readiness work take?
Typically a few weeks depending on what already exists and how many scenarios warrant playbooks. The output is a plan short enough to be used under pressure, playbooks for your likely scenarios, defined decision authority, and a tabletop to test it.

Be ready before it happens.

Let's assess your incident readiness and build the plans, playbooks, and drills that turn a crisis into a procedure.