TOWERVECTOR

05  Service

Incident Readiness.

What happens when prevention fails, planned in advance so the response is never improvised under pressure.

All services

01  Overview

Overview.

Whether your organization could actually execute its incident plan, and how much of it would be improvised on the day.

Nearly every organization has a plan. Very few have run it. The gap between those two states is where incidents become expensive: not in the intrusion, which is usually over quickly, but in the hours afterwards spent deciding who is allowed to make decisions.

02  Engagements

Rehearsal, not theory.

If you have never exercised a plan, start with a tabletop. It reliably finds more than a document review does, because it surfaces the disagreements a document cannot.

Incident Response Plan Review

Does the plan survive contact

Reading the plan against how your organization actually works. Most plans fail on the same things: they name people who have left, assume systems that will be unavailable during the incident, and skip the decisions that turn out to be hardest, who can authorize taking production offline, and who speaks to customers.

Tabletop and Crisis Exercises

Rehearsal, with the people who would be there

A scenario walked through in real time with the group who would actually run it, including the executives. The value is not in whether the plan is followed. It is in the arguments that surface, the decision nobody realized they owned, the assumption two teams held differently.

Ransomware Readiness Assessment

The scenario most likely to happen

Working backwards from the outcome that would hurt most: what an attacker would need to reach in your environment to make encryption effective, and whether you could restore without paying. Covers detection, containment, backup integrity, and the commercial decisions that get made badly under pressure.

Backup and Recovery Resilience Review

Whether recovery is real

Backups that exist are not the same as backups that restore. We look at whether yours are reachable from a compromised network, whether the credentials that manage them are in the same identity domain as everything else, and whether anyone has recently restored from them at the scale an incident would demand.

Compromise Assessment

Point-in-time, are they already here

A structured look for evidence of intrusion that has already happened: persistence, anomalous identity activity, unexpected outbound traffic, artifacts of known tooling.

03  Process

How an engagement runs.

Facilitation rather than testing. The work depends on the right people being in the room.

  1. 01

    Understanding what you would lose

    Before anything else, which systems and data would actually stop the business. This sounds obvious and is usually contested: the list operations gives and the list finance gives are rarely the same, and resolving that is half the work.

  2. 02

    Reviewing what exists

    The plan, the runbooks, the contact lists, the contracts with anyone you would call. We read them the way an attacker's timeline would, looking for the steps that assume something which will not be true at 3am on a Sunday.

  3. 03

    Exercising it

    A scenario built from how your environment is actually laid out, not a generic one. Run in real time, with the decisions made rather than described.

  4. 04

    Capturing what broke

    Every point where the exercise stalled, every decision that took too long, every assumption that turned out to be held by one person. This is the actual output, and it is usually uncomfortable reading.

  5. 05

    Fixing the plan

    Rewriting the parts that failed, with the people who own them. A plan improved by the group that will execute it is followed.

  6. 06

    Re-running it

    Six to twelve months later, with a different scenario. The first exercise tells you where you stand. The second tells you whether anything changed.

04  Deliverable

What you receive.

  • A written account of what happened in the exercise, including what stalled
  • Gaps ordered by how much time each would cost during a real incident
  • Rewritten plan sections for the parts that failed
  • Decision authority mapped, so nobody is looking for permission mid-incident
  • A briefing for the board or executive team, written for that audience
  • A scenario you can re-run yourselves without us

05  Questions

Common questions.

Do you provide 24/7 incident response?

No. We do readiness, exercises, and point-in-time compromise assessment.

We think we are compromised right now. Can you help?

Depending on what you are seeing, we may be able to help with triage and scoping.

Who needs to be in a tabletop exercise?

The people who would actually be in the room: technical responders, whoever can authorize taking systems offline, legal, communications, and at least one executive.

How long does an exercise take?

The session itself is usually half a day. Preparation takes longer, because a scenario built from your actual architecture is worth considerably more than a generic one, and that requires understanding your environment first.

Is a compromise assessment the same as monitoring?

No. It is a point-in-time look for evidence of intrusion that has already happened.

06  Contact

Tell us what you need.

TowerVector will assist you in taking your security strategy to the next level. Please feel free to contact us: