Incident Readiness Review
What the review examines
The review requires access to relevant documentation, architecture notes, and conversations with the people who would actually respond. Not a questionnaire. A structured working process that surfaces what would happen, not what should happen.
£3,500
Fixed price · + VAT
Delivered in 5 working days
Assessment areas
- Recovery capability across identity and platform failures What recovery actually looks like following realistic failure scenarios: identity platform compromise, ransomware, critical service loss. Measured against actual dependencies and manual steps, not documented timelines.
- Detection and response readiness Whether significant events in identity, email, and cloud infrastructure would produce alerts that the right people would see, understand, and act on within a timeframe that matters. Whether current logging configuration supports the response the plan assumes.
- Authority to act during incidents Who can make calls under pressure without waiting for approval that may not arrive in time. Where authority is delegated, explicit, and understood, and where it is assumed but not tested.
- Single points of failure People, providers, credentials, and systems where loss or unavailability would extend or significantly worsen any incident. These are rarely documented because nobody thought to document them before they became relevant.
- Dependency and escalation paths The external services and human escalation routes the actual response depends on. Third-party providers with out-of-hours procedures that nobody has verified. Vendor support relationships that exist on paper but not in practice.
- Communication readiness under pressure Internal escalation, customer notification, and stakeholder communication capability. Particularly: whether the organisation could notify affected parties within the UK GDPR 72-hour window while simultaneously managing the incident itself.
You receive
- Capability assessment in plain language An honest read on what incident response capability actually looks like today. Not what the plan claims, not what the organisation believes, but what the evidence supports.
- Prioritised gap and risk register Gaps ranked by the combination of likelihood, impact, and remediation effort. Separated into: decisions that sit with the business, decisions that sit with IT, and decisions that require a supplier conversation.
- Focused remediation plan What to address first, what can wait, and which items have quick resolution paths versus structural dependencies that require longer-term planning. Framed as decisions, not tasks.
- Working session (60 minutes) A working call to discuss findings, answer questions from both IT and leadership, and align on what action looks like in this specific organisation with its specific constraints.
- Standalone written report The deliverable belongs to you. It can be shared with leadership, a board, insurers, or an incoming IT provider without dependency on Dettogni.