R

Advisory / Incident Response Readiness Assessment

If something fails
tomorrow, who decides,
who responds, and
how long does recovery
actually take?

Plans describe what
should happen.
This review assesses
what would.

Most organisations have something that resembles an incident response capability. A documented plan. A named contact. An IT provider with an out-of-hours number. Backups that run on a schedule. Logging that is switched on.

None of that constitutes readiness. Readiness is whether the right person would see a significant event quickly enough to act. Whether that person has the authority to make the call required without waiting for three levels of approval. Whether recovery from an identity failure, ransomware event, or critical system loss would take hours or weeks. Whether anyone has actually tested those assumptions.

This review is an honest assessment of capability and reality, not a review of documentation. The question is not whether the plan says the right things. It is whether the organisation can do what the plan describes, under pressure, on a Tuesday evening.

Four places where
capability quietly fails.

The findings that matter most in incident readiness reviews rarely appear in the documentation. They appear in the gap between what is written and what would actually happen.

i

Common gap

Authority is unclear under pressure

Who can make the call to take a system offline, reset all credentials, or notify customers without escalating through three people who are not available? Incidents happen at inconvenient times. Authority needs to be pre-delegated, not negotiated in the moment.

ii

Common gap

Detection would not surface the event

Logging is enabled. Alerts are configured. But nobody has confirmed that a significant event in identity, email, or cloud infrastructure would produce an alert that anyone would see, understand, and act on within a useful timeframe. Most would not.

iii

Common gap

Recovery depends on a single person

The person who knows where the backup credentials are. The provider whose out-of-hours number only one internal person has. The admin account whose MFA is registered to a phone that someone left the company with. Single points of failure are rarely documented because nobody thought to document them.

iv

Common gap

Recovery time is assumed, not measured

Leadership believes recovery from a significant event would take hours. The actual dependencies, manual steps, and re-provisioning work required would take days. The gap between assumed and actual recovery time is one of the most commercially significant findings this review produces.

Six assessment areas.
One honest capability read.

The review is structured around realistic failure scenarios relevant to the organisation's actual environment and dependencies. It is not a theoretical exercise. The scenarios are drawn from real failure modes, not hypothetical edge cases.

What this engagement
deliberately does not include.

The Incident Readiness Review assesses capability, not configuration. It does not include:

  • - Deep identity or cloud configuration assessment (that is the Microsoft Identity Assessment)
  • - Penetration testing or red-team exercises
  • - Tabletop exercise facilitation or simulation
  • - Incident response plan writing or documentation creation
  • - Compliance audit or certification work
  • - Remediation, implementation, or ongoing retainer services

The review produces a decision-grade capability assessment and a prioritised gap register. Implementation of the recommended changes is the organisation's decision. Advisory engagements end. They do not become programmes.

What buyers
ask before engaging.

  • Q

    We already have a documented incident response plan. Why would we need this review?

    A plan describes what should happen. This review assesses whether it would. The most consistent finding in incident readiness reviews is that the plan exists and the capability it assumes does not: the escalation contact is no longer current, the backup restore process has never been tested, the authority to act has not been pre-delegated. Untested plans are not readiness.

  • Q

    How does this differ from the Microsoft Identity and Cloud Security Assessment?

    The Microsoft Identity Assessment examines how controls are configured and where risk sits in the environment. The Incident Readiness Review examines what happens when something goes wrong: who has the authority to act, whether detection would surface the event, and whether recovery would take the time leadership assumes. One assesses posture. The other assesses capability. They address different questions and are often relevant to the same organisation.

  • Q

    What documentation and access does this require?

    Documentation relevant to the review: existing incident response plans, business continuity documentation, IT provider contracts with out-of-hours terms, backup configuration and schedules, and architecture notes where available. Conversations with key contacts: the person who would lead an incident response, the person with authority to make decisions under pressure, and where relevant the IT provider. No system access is required.

  • Q

    Can the output be shared with our board or insurers?

    Yes. The capability assessment and gap register are written to be understood by non-technical leadership. The deliverable can be used in board reporting, as evidence in a cyber insurance application or renewal, or shared with an incoming IT provider as a baseline for their engagement.

  • Q

    Why does this review cost £3,500?

    Because the review prices against downtime, not documentation. The commercial cost of an incident is set by how long recovery takes and whether obligations like the UK GDPR 72-hour notification window are met. A recovery that takes days instead of the hours leadership assumed, or a missed notification deadline, costs multiples of £3,500 in any organisation this engagement fits. The review closes the gap between assumed and actual capability before it is measured live.

  • Q

    Should we do the Security Posture Baseline first?

    If you already know that incident response capability is the specific question you need answered, no. The Security Posture Baseline is for buyers who do not yet know where their risk sits. If a near-miss, a board conversation about resilience, or an insurance requirement has already pointed toward response capability as the gap, this review addresses that directly.

Begin here

Know your real
response capability
before you need it.

The first step is a short Discovery Call. Twenty minutes. Used to confirm fit, understand the environment and existing documentation, agree on key contacts, and set the start date.

The review is carried out personally by Alex Ulfeldt, the security engineer who operates Dettogni. No handoffs, no junior analysts.

If the Incident Readiness Review is not the right engagement for your situation, the call will surface that before any commitment is made.

Book a Discovery Call See all advisory engagements

Dettogni advisory is fixed in scope, fixed in price, and designed to end.
United Kingdom · Remote engagements