TOWERVECTOR

05  Service

Incident Readiness.

What happens when prevention fails, planned in advance so the response is never improvised under pressure.

All services

01  Overview

The plan, under load.

Nearly every organization has an incident plan. Very few have run it. This work establishes whether yours could actually be executed, and how much of it would be improvised on the day.

The gap between those two states is where incidents become expensive: not in the intrusion, which is usually over quickly, but in the hours afterwards spent deciding who is allowed to make decisions.

02  Engagements

Run the plan before you need it.

If you have never exercised a plan, start with a tabletop. It reliably finds more than a document review does, because it surfaces the disagreements a document cannot.

Incident Response Plan Review

Does the plan survive contact

Reading the plan against how your organization actually works. Most plans fail on the same things: they name people who have left, assume systems that will be unavailable during the incident, and skip the decisions that turn out to be hardest: who can authorize taking production offline, and who speaks to customers.

Tabletop and Crisis Exercises

Rehearsal, with the people who would be there

A scenario walked through in real time with the group who would actually run it, including the executives. What the exercise produces is the arguments that surface, the decision nobody realized they owned, and the assumption two teams held differently.

Ransomware Readiness Assessment

The scenario most likely to happen

Working backwards from the outcome that would hurt most: what an attacker would need to reach in your environment to make encryption effective, and whether you could restore without paying. Covers detection, containment, backup integrity, and the decision nobody wants to make in the moment, which is whether to pay.

Backup and Recovery Resilience Review

Whether recovery is real

The question is whether your backups restore. We look at whether they are reachable from a compromised network, whether the credentials that manage them are in the same identity domain as everything else, and whether anyone has recently restored from them at the scale an incident would demand.

Compromise Assessment

Point-in-time, are they already here

A structured look for evidence of intrusion that has already happened: persistence, anomalous identity activity, unexpected outbound traffic, artifacts of known tooling.

03  Process

How an engagement runs.

We facilitate these sessions, and the work depends on the right people being in the room.

  1. 01

    Understanding what you would lose

    Before anything else, which systems and data would actually stop the business. This sounds obvious and is usually contested: the list operations gives and the list finance gives are rarely the same, and resolving that is half the work.

  2. 02

    Reviewing what exists

    The plan, the runbooks, the contact lists, the contracts with anyone you would call. We read them the way an attacker's timeline would, looking for the steps that assume something which will not be true at 3am on a Sunday.

  3. 03

    Exercising it

    A scenario built from how your environment is actually laid out, run in real time, with the decisions actually made.

  4. 04

    Capturing and fixing what broke

    Every point where the exercise stalled, every decision that took too long, every assumption that turned out to be held by one person. That list is the actual output, and it is usually uncomfortable reading. The parts that failed then get rewritten with the people who own them.

  5. 05

    Re-running it

    Six to twelve months later, with a different scenario. The first exercise tells you where you stand. The second tells you whether anything changed.

04  Deliverable

What you receive.

  • A written account of what happened in the exercise, including what stalled
  • Gaps ordered by how much time each would cost during a real incident
  • Rewritten plan sections for the parts that failed
  • Decision authority mapped, so nobody is looking for permission mid-incident
  • A briefing for the board or executive team, written for that audience
  • A scenario you can re-run yourselves without us

05  Questions

Common questions.

Do you provide 24/7 incident response?

No. We do readiness, exercises, and point-in-time compromise assessment.

We think we are compromised right now. Can you help?

Contact us if you want a second pair of eyes on triage and scoping, or help working out what the incident responders are telling you.

Who needs to be in a tabletop exercise?

The people who would actually be in the room: technical responders, whoever can authorize taking systems offline, legal, communications, and at least one executive.

How long does an exercise take?

The session itself is usually half a day. Preparation takes longer, because a scenario built from your actual architecture is worth considerably more than a generic one, and that requires understanding your environment first.

Is a compromise assessment the same as monitoring?

No. It is a point-in-time look for evidence of intrusion that has already happened.

06  Contact

Tell us what you need.

TowerVector will assist you in taking your security strategy to the next level. Please feel free to contact us: