Financial Services Financial Services & Banking Cybersecurity & Operational Resilience

Incident Response

Regulated environments where trust, compliance, and operational resilience are non-negotiable.

Example organizations in this space: Mandiant (Google) Palo Alto Networks IBM Kroll

This interactive experience is the shipped product itself — the same application code customers run in production, mounted read-only in your browser over a real sample journey. Not a video, not a mockup: because the demo and the product are one codebase, it can never drift from the real thing.

Inside this journey
  1. Outcome Discovery

    Align on threat scenarios, regulatory obligations, stakeholders, and the success signals the buyer needs during an incident.

    Discovery Questions

    Quick check: how your leadership sees this right now

    • How concerned is your board about your institution's ability to execute a coordinated breach response right now? Options: Very high, High, Moderate, Low, Not concerned
    • When was the last time your team declared a security incident that required external counsel or a forensics partner? Options: Within the last 3 months, 3 to 12 months ago, More than a year ago, We have never declared one
    • Who on your executive team would be expected to brief the audit committee after a high-impact breach? Options: General counsel, Chief information security officer, Chief risk officer, CEO, Head of operations, Other
    • Describe the single fallout from a recent peer incident that makes your leadership most anxious about your own readiness
    • Which of the following outcomes would make your board demand immediate retainer activation? Options: Regulatory notification delay, Conflicting public statements, Loss of clearing or settlement capability, Rapid customer data exposure, Litigation or class action, Third-party vendor failure, Other
    • Would having a named, on-call incident coach available within two hours change your board's confidence? Options: Yes, Maybe, No

    Who actually owns the two-hour decision and the hard tradeoffs

    • If your team had to activate a retainer at 2 AM on a holiday, which three critical tasks do you expect would still not happen within the first four hours? Options: Containment of affected systems, Forensic imaging of key endpoints, Formal privilege invocation with counsel, Regulatory notification packet prepared, Executive communications draft, Evidence preservation chain-of-custody, Third-party vendor coordination, Other
    • Who currently has authority to sign off on privilege-preserving steps for external investigators, and are backup signers documented? Options: Yes, a single signer is documented, Yes, backups are documented, No, authority is unclear, Legal review is required before activation
    • Walk me through the escalation path when forensics, privilege concerns, and regulator timelines conflict during an incident
    • How many hours of pre-negotiated retainer support does your legal team insist on having guaranteed in writing for a single incident? Options: 0-24 hours, 24-72 hours, 72-120 hours, More than 120 hours
    • If you could not guarantee chain-of-custody in the first 24 hours, would you still proceed with an external retainer model? Options: Yes, we would proceed, No, we would halt, Depends on incident severity

    Where response friction actually appears in practice

    • Walk me through the last incident you declared, from detection to containment, and tell me which step took the longest to reach resolution
    • List the tools and platforms your responders must access during an investigation and who controls those credentials Options: Endpoint detection and response, Network traffic capture, Cloud provider logs and consoles, Email and collaboration logs, Identity provider and SSO, Core payment or ledger systems, Other
    • Are there contracts, change controls, or vendor approvals that routinely delay evidence collection or device imaging? Options: Yes, frequently, Sometimes, Rarely, Never
    • Estimate how long it takes to begin forensic imaging on a critical server or endpoint after you authorize it Options: Under 4 hours, 4 to 8 hours, 8 to 24 hours, More than 24 hours
    • Would you prioritize changing vendor terms to guarantee timely log access before signing a retainer? Options: Yes, we would prioritize contract changes, No, we would proceed with current terms, We would seek limited legal waivers instead

    Regulatory and legal fault lines you cannot ignore

    • What single regulatory outcome would force public disclosure or escalation within 24 to 72 hours for your institution? Options: Immediate public disclosure requirement, Mandatory regulator referral, Criminal investigation referral, Material impact to settlement or clearing, Widespread customer data theft
    • List the regulators and mandatory timelines your team must meet for a material incident Options: Federal banking regulator, Securities regulator, State banking regulator, Data protection authority, Other
    • Tell me which member of your legal team has previously briefed regulators during an incident and what evidence they required first
    • Describe the privilege-preserving retainer structure your counsel prefers and any red lines we must avoid
    • Does your current privilege arrangement prevent disclosure without a court order if regulators request immediate access to forensic images? Options: Yes, privilege prevents disclosure, No, disclosure may be required, It depends on the regulator and legal advice

    Who else you are weighing and what would keep you with them

    • What would have to be true about your current provider or in-house setup for you to decide not to change providers? Options: It consistently preserves chain-of-custody, It meets regulator timelines reliably, It guarantees named responder availability, Internal teams have capacity and legal coverage, Other
    • Please name the internal teams, incumbent firms, or alternative models you are currently evaluating
    • Estimate the likelihood that leadership will push for an internal do-it-yourself approach instead of an external retainer Options: 0 to 25 percent, 26 to 50 percent, 51 to 75 percent, 76 to 100 percent
    • Identify the highest-risk gap in each alternative that would stop you from choosing it
    • Practically speaking, which procurement or approval steps must clear before you could sign a retainer? Options: Budget approval, Legal review and signoff, Procurement RFP or competitive review, Board or audit committee signoff, None, contracting authority already exists

    Can you operationalize this quickly, or will practical constraints block it

    • When your incident response plan is executed in reality, what single dependency usually fails and blocks activation?
    • Name the systems, APIs, and cloud tenants we must integrate with during the first engagement session Options: Primary cloud provider console, SIEM or centralized log store, Endpoint management console, Identity provider and SSO, Core payment or ledger systems, Network forensics appliance, Other
    • Are there service agreements, change control windows, or legal approvals that will prevent remote evidence collection without 48 hours notice? Options: Yes, frequently, Sometimes, Rarely, No, we have immediate authority
    • Identify the role responsible for credentialing forensic collection tools and providing emergency access within two hours Options: Security engineering, IT operations, Cloud platform team, Third-party vendor, Legal
    • Quantify the headcount and technical skillset you can dedicate to a single high-priority incident for the first 30 days
    • Does lack of pre-authorized access to cloud logs disqualify the engagement under your legal requirements? Options: Yes, this disqualifies the engagement, No, we can proceed with controls, Requires a legal waiver or amendment

    How you will judge success and when you will move to the next step

    • Provide the three measurable signals you would present to the board within 72 hours to show the incident response succeeded
    • Name the stakeholders who must sign off on successful evidence preservation for you to consider the retainer effective Options: Board, Audit committee, General counsel, CISO, Risk office, Operations, Other
    • Within what cadence do you prefer scheduled readiness drills after activation to maintain confidence? Options: Monthly, Quarterly, Biannual, Annual, Ad hoc after incidents
    • Explain the governance step that most reliably speeds remediation when a post-incident review surfaces a procedural gap
    • Should the first live exercise fail to preserve chain-of-custody evidence, do you expect to pause the retainer and require renegotiation? Options: Yes, we would pause and renegotiate, No, we would iterate operationally and continue, We would consider limited scope changes
  2. Response Experience

    Walk through the incident response lifecycle in the buyer's context, mapping roles, communications, and evidence-preservation steps across realistic breach scenarios.

    Solution Experience

    • Response Experience Walkthrough
    • Confirm the current state and its cost
    • You confirm the mapped roles and timelines eliminate the ambiguity that currently causes duplicated or delayed actions during incidents.
    • Deliver a tailored incident timeline that maps named roles, escalation phone trees, and two-hour activation checkpoints for your environment.
    • You agree that the demonstrated evidence-preservation steps meet your legal team's expectations for chain-of-custody and privilege protection.
    • Scenario walkthrough — payment/settlement system compromise
    • Share a draft privileged-retainer clause that preserves attorney-client privilege over forensic findings and outlines activation triggers.
    • You accept the two-hour activation expectation and identify any remaining barriers to approving a privileged retainer for board presentation.
    • Scenario walkthrough — ransomware affecting endpoints and backups
    • Provide the current list of legal and SOC contacts, and the top 10 critical assets to include in the tailored timeline and evidence-preservation plan.
    • Evidence preservation and communications choreography
    • Confirm whether a brief orientation of the end-to-end retainer lifecycle is required at the session start for any attendees unfamiliar with this engagement model.
    • Validation: confirm this maps to your needs
    • Response Experience Walkthrough
    • Response Experience Deck
    • Response Experience Solution Brief
    • meeting
    • slides
    • document
  3. Tabletop Exercises

    Run structured simulations with legal, security, and executive stakeholders to surface timing gaps, escalation paths, and regulatory communication triggers.

    Exercise Sessions

    • Exercise Kickoff and Scenario Selection
    • Detection to Escalation Tabletop
    • Legal Privilege and Regulatory Notification Drill
    • Executive Communication and Press Coordination Tabletop
    • After-Action Review and Playbook Update Decision
    • A clear sign-off path and timing requirements for any public statement or press engagement.
    • Recap scenario facts and legal posture assumptions
    • A decision tree that defines when to assert attorney-client privilege and when to commence regulator notification.
    • A documented evidence handling protocol that preserves chain of custody and privilege assertions.
    • Publish the privilege decision tree and the regulator notification triggers derived from the drill.
    • Produce an evidence handling checklist aligned to privilege assertions and chain-of-custody requirements.
    • Set objectives for executive and board communications
    • A scripted executive briefing for the first 72 hours with explicit escalation decision points.
    • Confirm scope and rules of engagement
    • Produce the 72-hour executive briefing script with placeholders for case-specific facts.
    • Document the sign-off steps and timing for public statements and regulator disclosures.
    • Present consolidated findings and gap list
    • An approved exercise report that consolidates findings and prioritizes playbook updates and remediations.
    • A timeline and verification plan for each prioritized remediation and a schedule for recurring exercises.
    • Publish the final exercise report with prioritized playbook changes and remediation timelines.
    • Schedule the next tabletop exercise and define the readiness metrics to be tracked before that exercise.
    • A ratified list of 1 to 3 scenarios to exercise with a brief rationale for each.
    • Documented rules of engagement that define what will be simulated and what is out of scope.
    • Defined success criteria and explicit decision gates for each selected scenario.
    • Publish the final exercise scope, selected scenarios, rules of engagement, and participant list.
    • Distribute scenario scripts and timelines to participants for prework and review.
    • State the scenario and baseline assumptions
    • A documented minute-by-minute incident timeline for the exercised scenario with annotated timing gaps.
    • A ratified escalation path with clear thresholds that will trigger retainer activation and executive notification.
    • Record and distribute the annotated incident timeline with identified timing gaps.
    • Update the retainer activation checklist with confirmed escalation thresholds.
    • Walkthrough detection, triage, and escalation steps
    • Prioritize remediation and playbook changes
    • Walk through the 72-hour executive notification timeline
    • Select and prioritize scenarios
    • Run decision drills at key timeline points
    • Identify timing gaps and bottlenecks
    • Map evidence preservation steps that preserve privilege and chain of custody
    • Define success criteria and decision gates
    • Decide owners, timelines, and verification steps
    • Simulate external communications and press statement approvals
    • Confirm recurring exercise schedule and readiness metrics
    • Confirm participants, roles, and logistics
    • Validate regulator notification ladder and template needs
    • Confirm escalation thresholds and interim communications
    • Confirm readiness criteria for public statements
  4. Retainer Scope

    Define retainer coverage: guaranteed response SLAs, forensic depth across endpoint/network/cloud, included modules, out-of-scope items, and regulatory support levels.

    Scope Configuration

    • Rapid retainer response activation
    • Endpoint forensic imaging
    • Network traffic capture and analysis
    • Cloud environment forensics
    • Malware and threat artifact analysis
    • Live incident containment and isolation
    • Threat eradication and host remediation
    • Chain-of-custody evidence packaging
    • Suspicious Activity Report (SAR) support
    • Regulatory notification and disclosure coordination
    • Legal-privilege evidence segregation
    • Expert witness and litigation support

    Scope Questions

    Rapid retainer response activation

    • After you declare a security event, what guaranteed response SLA (minutes) must we commit to for on-call acknowledgement and initial arrival to remote triage? Options: 15 minutes, 30 minutes, 60 minutes, 120 minutes, Custom
    • Who on your incident response decision team is authorized to activate the retainer and declare a formal incident for escalation (example: your general counsel, CISO, or head of operations)?
    • Which communication channels are pre-approved for immediate activation (examples: encrypted call bridge, SOC secure chat, designated escalation phone tree)? Options: Encrypted call bridge, SOC secure chat, Escalation phone tree, Email + phone, Other
    • How many concurrent incident activations can you tolerate before you require confirmation of provider capacity (to account for vendor handling multiple customers)? Options: 1, 2, 3, 4+
    • List any blackout windows or restricted operational periods when we should not initiate remote imaging or in-person work without executive sign-off (example: board meetings, end-of-day clearing windows).
    • Specify the pre-authorized access level we have after activation (examples: read-only access to SIEM and logs, remote forensic imaging, console access to production payment switch). Options: Read-only logs and SIEM, Remote forensic imaging only, Limited console access with approval, Full console access with counsel present, Other

    Endpoint forensic imaging

    • Which endpoint classes require forensic imaging in-scope (examples: workstation endpoints, Windows domain controllers, Linux payment switch hosts, virtual machine images in hypervisor pools)? Options: Workstations (Windows/macOS), Servers (Linux/Windows), Domain controllers / Active Directory, Virtual machine images, Other
    • How many endpoints do you expect to require full disk imaging in a single incident (approximate count)? Options: 1-10, 11-50, 51-200, 200+
    • Identify your current endpoint detection and response (EDR) coverage status and vendor-agnostic footprint so we can plan imaging methods (examples: EDR installed on 95% of endpoints, selective coverage on branch teller PCs). Options: EDR on >90% endpoints, EDR on 50-90% endpoints, EDR on <50% endpoints, No EDR deployed
    • Specify whether volatile memory (RAM) capture is required by your legal or investigative standards for compromised servers involved in payment processing or SWIFT hosts. Options: RAM capture required for servers, RAM capture required for workstations, RAM capture not required, Case-by-case with counsel
    • Describe the preferred forensic image format and hashing standard you require for evidentiary use (examples: E01 with MD5/SHA256, raw dd with SHA256).
    • Indicate whether remote forensically-sound imaging is acceptable for branch or remote-office endpoints, or whether physical media collection is required for those locations. Options: Remote imaging acceptable, Physical media collection required, Hybrid by device type

    Network traffic capture and analysis

    • Which network capture sources are available for in-scope analysis (examples: core switch SPAN/tap, firewall logs, packet capture (PCAP) appliances, virtual private cloud (VPC) flow logs)? Options: Core SPAN/tap, Firewall logs, PCAP appliances, VPC flow logs, Other
    • How many hours or days of raw PCAP retention do you currently have for corporate and payment network segments (examples: 24 hours, 7 days, 30 days)? Options: 24 hours, 72 hours, 7 days, 30 days, Other
    • Specify whether we will have read or full access to your Security Information and Event Management (SIEM) and the expected log retention windows for payment switching and core banking events. Options: Read access to SIEM, retention >=90 days, Read access, retention 30-90 days, Limited log extracts only, No SIEM access
    • Identify any encrypted links or TLS termination points we should plan to access for decrypted traffic analysis (examples: load balancer TLS offload, reverse proxy, HSM-protected termination).
    • Estimate whether live packet capture will risk disrupting clearing and settlement; indicate required approvals or maintenance windows for in-line capture on payment VLANs. Options: Low risk — proceed, Requires approval and maintenance window, Not permitted on payment VLANs
    • Provide the name or location of any third-party managed network segments (examples: outsourced datacenter, payment processor cloud segment) we must coordinate with to obtain PCAP or firewall logs.

    Cloud environment forensics

    • Which cloud environments host in-scope assets (examples: public cloud VPCs hosting payment API, SaaS vendor storing customer PII, private cloud running core ledger)? Options: Public cloud VPCs, SaaS providers, Private cloud / co-lo, Hybrid mix
    • Where are audit trails and control plane logs retained for cloud workloads (examples: CloudTrail or equivalent, object storage access logs, host-level auditd), and what is the retention period? Options: Audit logs retained 90+ days, Retention 30-90 days, Retention <30 days, Logs not centralized
    • Indicate whether we will have console-level access or need to route requests through your cloud provider support to obtain snapshots, instance metadata, and object storage artifacts. Options: Console access granted, Provider-assisted collection required, Read-only API keys available, Other
    • Specify the number of cloud storage buckets or object containers that may require forensic collection in an incident involving customer PII or payment files. Options: 1-5, 6-20, 21-100, 100+
    • Describe any cloud-native identity sources in scope (examples: Azure Active Directory, federated identity providers) and whether access to identity logs is available for correlation.
    • Identify whether you require preservation of cloud snapshots as evidence and whether snapshot fees or provider egress costs are the buyer's responsibility. Options: Snapshots preserved — buyer pays fees, Snapshots preserved — discuss cost allocation, Snapshots not required

    Malware and threat artifact analysis

    • Do you permit malware detonation in an isolated lab for behavioral analysis of samples originating from your environment (examples: payment file malware, ransomware binary)? Options: Yes — isolated lab allowed, No — static analysis only, Case-by-case with written approval
    • Which sample handling and storage policies must we follow for binary artifacts that may become evidence in regulatory matters or prosecution?
    • How should indicators of compromise (IOCs) discovered during analysis be pushed into your detection stack for containment (examples: SIEM IOC feed, EDR IOC blocklist)? Options: SIEM IOC feed, EDR blocklist, Manual IOC deliverable only, Other
    • Specify turnaround expectations for initial malware triage and a written artifact summary for executive and legal review for incidents affecting customer payment data. Options: Immediate triage within 4 hours, Same day summary, 48 hour summary, Custom
    • Provide required cryptographic hashing standards for delivered artifacts (examples: SHA256 digest, timestamped hash manifest) when artifacts will be used in regulatory filings or litigation. Options: SHA256 + timestamp, MD5 + SHA1, Other
    • Indicate whether we should coordinate with your malware threat intelligence subscriptions or submit samples to your internal intel team before public disclosure. Options: Coordinate with internal intel, Submit after analysis, Do not share externally

    Live incident containment and isolation

    • Who within your escalation tree has the authority to approve immediate network isolation actions that could impact payment processing or customer-facing systems?
    • Which containment techniques are acceptable on production payment systems (examples: network VLAN isolation, host quarantine via EDR, hypervisor snapshot and freeze)? Options: VLAN isolation, EDR host quarantine, Hypervisor snapshot, Service-level shutdown with approval
    • When isolating an affected host, do you require prior sign-off from legal counsel before disconnecting systems that are involved in clearing and settlement? Options: Legal sign-off required before isolate, Isolate immediately then notify legal, Case-by-case
    • Estimate acceptable maximum downtime for a single payment switch or clearing node in minutes/hours to guide containment decisions. Options: <15 minutes, 15-60 minutes, 1-4 hours, 4+ hours
    • Describe any automated controls that must not be triggered during containment (examples: automatic customer notification, transaction replay, auto-scaling in cloud).
    • Identify any secondary systems (examples: reconciliation engines, batch job schedulers) that must be preserved or isolated together with primary hosts.

    Threat eradication and host remediation

    • Which remediation paths do you prefer for compromised hosts that perform financial clearing (examples: rebuild from golden image, in-place remediation with forensic preservation)? Options: Rebuild from golden image, In-place remediation with verification, Hybrid approach, Other
    • How does your change control process handle emergency remediation outside normal maintenance windows for high-risk systems? Options: Emergency patch allowed with post-facto approval, No out-of-window changes without board-level approval, Case-by-case with documented justification
    • Specify rollback or validation criteria you require after remediation on systems handling customer funds (examples: transaction reconciliation matches, no residual IOC in logs).
    • Indicate whether you require us to produce a remediation playbook and runbook for each system class (examples: teller POS, payment gateway, ACH batch server). Options: Yes — full playbook per system class, Yes — summary playbook, No
    • Provide the time window you require for a verified remediation-to-production acceptance test on ledgers or clearing systems before resuming normal processing. Options: Immediate resume after verification, 1 hour, 4 hours, 24 hours
    • Identify whether you expect us to perform post-remediation threat-hunting sweeps across identity stores (example: Active Directory) and transaction logs. Options: Yes — identity and transaction sweep, Only transaction logs, No additional hunting required

    Chain-of-custody evidence packaging

    • What evidence packaging and transfer acceptance criteria will validate chain of custody for regulatory exams or criminal proceedings (examples: hashed image manifest, sealed evidence bags, timestamped transfer logs)?
    • Which hash algorithms and packaging standards do you require for forensic images and logs intended for disclosure to regulators or use in litigation? Options: SHA256 with manifest, SHA1+MD5 legacy, Other
    • Where should collected evidence be retained after acquisition (examples: customer-controlled secure evidence repository, provider-controlled privileged vault, chained S3 bucket with restricted keys)? Options: Customer-controlled repository, Provider privileged vault, Hybrid - initial with provider then transfer
    • Specify the handoff procedure and signed documentation you require when physical media or printed logs are transferred between your team and responders.
    • Indicate preferred methods for transporting physical evidence across sites for multi-branch incidents (examples: secure courier, tamper-evident packaging, bonded transport). Options: Secure courier with chain log, Tamper-evident packaging only, Local collection only
    • Identify any regulatory or internal retention windows that dictate how long images, PCAPs, and log exports must be preserved for potential investigations. Options: 90 days, 1 year, 5 years, As per regulator request

    Suspicious Activity Report (SAR) support

    • Which thresholds or transaction patterns from your transaction monitoring system should trigger SAR support and evidence collection (examples: large outbound wires, anomalous clearing activity, structured deposits)?
    • Who in your anti-money laundering (AML) chain must sign off prior to any SAR filing and what documentation do they require from the investigation (examples: forensic timeline, transaction logs)?
    • When a SAR is expected, what format and level of technical detail do you require for attachment (examples: CSV of affected transactions, timeline with packet captures, hashed forensic images)? Options: CSV transactions + timeline, Timeline + selected PCAPs, Full forensic package
    • Indicate whether we should coordinate directly with your AML counsel and file to the Financial Crimes Enforcement Network (FinCEN) on your behalf if requested. Options: Coordinate with AML counsel, We file, you approve, We do not file
    • Describe any internal SAR escalation timelines you must meet once a potential reportable incident is identified (examples: initial AML review within 24 hours).
    • Identify whether historic transactional reconstitution will be required as part of SAR support and the expected lookback window (examples: 30 days, 90 days, 1 year). Options: 30 days, 90 days, 1 year, Other

    Regulatory notification and disclosure coordination

    • Which regulators must be notified for a material compromise of customer data or payment systems (examples: Office of the Comptroller of the Currency (OCC), Securities and Exchange Commission (SEC), state banking regulator)? Options: OCC, SEC, State banking regulator, Other
    • How soon after evidence of material impact do you require notification drafts to be delivered for counsel approval prior to regulator contact (examples: within 2 hours, same day)? Options: Within 2 hours, Same day, Within 48 hours, As agreed case-by-case
    • Who is authorized to approve regulator notification language on your behalf (example: your general counsel), and which file formats do regulators expect (examples: PDF executive timeline, log extracts)?
    • Indicate whether you require us to coordinate regulator briefings (example: prep and attend OCC briefing calls) and whether attendance by your counsel is mandatory. Options: We coordinate and attend with counsel, We prepare materials only, Do not attend regulator calls
    • List any regulator reporting deadlines or statutory windows that are binding for you in breach events (examples: state breach notification within 30 days, bank regulator immediate notification).
    • Specify whether you require a redlines-ready regulator notification template and whether that template must be approved annually by your legal team. Options: Yes, one-time approval, Yes, annual approval required, No template required
  5. Mutual Commit

    Finalize commercial and legal terms including engagement activation, privilege-preserving retainer structure, chain-of-custody protocols, and billing triggers.

    Agreement Modules

    • Master Services Agreement (MSA)
    • Statement of Work (SOW) — Retainer Scope
    • Retainer Activation & Billing Terms
    • Privilege Preservation Addendum
    • Chain-of-Custody & Evidence Handling Protocol
    • Service Level Agreement (SLA)
    • Regulatory & Examiner Support Addendum (Financial Institutions)
    • Data Processing Agreement (DPA)
    • Expert Witness & Legal Support Addendum
    • Mutual Non-Disclosure Agreement (NDA)
  6. Deployment

    Lock readiness facts and configuration values before execution begins.

    1. Onboarding Readiness

      Capture concrete operational facts—SOC contacts, legal counsel contacts, escalation phone trees, monitoring access, and evidence custody locations—required before activation.

      Pre-Deployment Questions

      Environment and access

      • Which environments are in-scope for immediate retainer activation? (select all that apply — used to scope access and responder tooling) Options: Production environment(s), Disaster recovery / warm standby, Cloud assets (IaaS/PaaS/SaaS), Network infrastructure (DMZ, core), Endpoint estate only (workstations/servers), Other
      • Can the detection/monitoring team grant emergency read-only access to in-scope monitoring, SIEM, and log platforms within two hours of activation? (so we can triage immediately) Options: Yes — access automated/granted within SLA, Yes — requires manual approval but can be provided within two hours, No — cannot be granted within two hours, Unsure — need confirmation
      • Provide the named owner for each in-scope environment and the team responsible (name and team). (Used to route access requests and approvals.)

      Data and evidence custody

      • Has the buyer designated a secure evidence custody model for incident artifacts (choose the closest match)? Options: On‑premises evidence locker with named custodian, Cloud evidence vault under buyer control, Third‑party evidence handling vendor pre‑contracted, Not yet designated, Other
      • Who is authorized to approve chain-of-custody transfers and removal of artifacts from custody during an incident? (name and role)
      • Are forensic preservation practices and privilege‑preserving templates pre‑approved by legal for use during a live incident? Options: Yes — templates fully approved, Pending — legal review in progress, No — legal approval required at activation, Not applicable / no templates

      People and ownership

      • Provide the primary and secondary SOC on‑call contacts for incident activation, including escalation order and preferred contact method (name, role, escalation order).
      • Has a single legal point of contact for incident response and privilege decisions been named? Options: Yes — internal counsel named, Yes — external counsel named, No — multiple counsels or not named, Unsure
      • List the executives authorized to declare retainer activation and the escalation order (e.g., CISO, GC, CRO). (name and role)

      Timing and constraints

      • Are there blackout windows, regulatory moratoria, or operational constraints that would delay seller mobilization? (select the closest answer — specific dates go in deployment config) Options: No constraints — seller can mobilize any time, Yes — predefined blackout windows exist, Yes — regulatory notification moratoria apply, Unsure — need to confirm
    2. Operational Configuration

      Lock exact configuration values the response team will use—forensic imaging settings, collector endpoints, secure evidence storage details, notification templates, and escalation thresholds.

      Configuration Details

      Operational Configuration — Locking the Values We Will Use

      • Enter the canonical name for this production environment (format: single token, e.g., prod-us-east). Default: prod
      • Select the primary geographic region where incident response activities and data handling will be performed (this drives routing and legal considerations) Options: US-East (United States), US-West (United States), EMEA (Europe / Middle East / Africa), APAC (Asia Pacific), Global / Multiple regions
      • Enter the primary operational timezone to use for all timestamps (format: IANA TZ name or common abbreviation). Default: UTC
      • Enter the single point-of-contact role that will be considered Incident Commander for activation events (format: Role — Example: CISO) Options: CISO, Head of Security / Incident Commander, General Counsel, Head of IT Operations, Other
      • Enter the name and role of the specific individual who will act as the Incident Commander for this configuration (format: Full Name — Role)
      • Default working hours for non-executive escalations (format: HH:MM-HH:MM, timezone is the value above). Default: 08:00-18:00

      Forensic Imaging & Collection — Exact Tooling and Formats

      • Forensic disk image format to use by default for endpoint imaging (choose one). Default: E01 (forensic container) Options: E01 (forensic container), Raw/dd (bit-for-bit), AFF4 (advanced forensic format), Compressed raw (dd + gzip), Custom (enter below)
      • If you selected Custom above, enter the exact custom image format identifier (leave blank if not Custom)
      • Hash algorithm to generate image/verifier hashes (choose one). Default: SHA256 Options: SHA256, SHA1, MD5, SHA512, Other (enter below)
      • If you selected Other for hash algorithm, enter the exact algorithm name (leave blank if not Other)
      • Is memory (RAM) acquisition required as part of the default imaging workflow? Default: Yes Options: Yes, No
      • If memory acquisition is required, enter the memory acquisition tool identifier or method name to use (do not provide a secret)
      • Should imaging use a write-blocker by default for physical drives? Default: Yes Options: Yes, No
      • Maximum acceptable time from acceptance of activation to start of forensic imaging (hours). Default: 2

      Collectors & Endpoints — Where and How We Pull Data

      • Enter the primary collector endpoint URL or hostname used for automated artifact collection (format: https://... or host.example.local)
      • Collector authentication method (choose one). Do NOT paste secrets — only select method. Options: Integration service account (username) + secrets manager, Certificate-based service identity (certificate name/ID), IdP-assigned token (SAML/OIDC) via your IdP, None — manual/agentless collection
      • Enter the identifier for the integration service account or certificate name used by the collector (format: service_account_name or cert_name). Do NOT paste credentials
      • Enter the owner (Name — Role) responsible for the collector credential identified above (who will provide the secret at kickoff)
      • Which secure channel will you use to transfer collector secrets at deployment kickoff (choose one) Options: your secrets manager, platform secure upload at kickoff, enterprise ticketing secure attachment, other (describe below)
      • If you selected other for secure channel above, enter the exact channel name or procedure (leave blank if not applicable)
      • Enter the network egress endpoint (IP or CIDR) the collector is allowed to reach for evidence upload (format: IP or CIDR). If multiple, provide the primary value only

      Evidence Storage & Retention — Exact Locations and Limits

      • Primary evidence storage endpoint (enter S3-compatible URL, bucket name, or UNC path exactly as it will be configured). Example: s3://ir-evidence-prod or \\fileserver\evidence
      • Is encryption at rest required for evidence storage? Default: Yes Options: Yes, No
      • Default evidence retention period in days (Default: 365)
      • Maximum allowed evidence volume per incident (GB). Default: 500
      • Evidence transfer method (choose one). This determines how collected artifacts reach the storage endpoint Options: Direct upload to storage endpoint from collector, Seller-managed transfer node (pull), Physical encrypted shipment of drives, Hybrid — small artifacts online, large media shipped, Other (describe below)
      • If you selected Other above, enter the exact transfer method name or procedure (leave blank if not applicable)
      • Enter the designated evidence custodian (format: Full Name — Role). This person signs chain-of-custody custody transfers

      Chain-of-Custody & Logging — Verifiable Records

      • Persistent identifier field name to use as the canonical incident ID across systems (enter exact field name). Example: incident_id
      • Where will chain-of-custody records be stored (enter exact system name or URL — e.g., ticket-system-name or https://host.example/coc)
      • Hash algorithm to record for chain-of-custody verification (choose one). Default: SHA256 Options: SHA256, SHA1, MD5, SHA512, Other (enter below)
      • If you selected Other for chain-of-custody hash algorithm, enter the algorithm name (leave blank if not applicable)
      • Role that will sign chain-of-custody entries by default (choose one) Options: Buyer Legal Counsel, Buyer Evidence Custodian, Incident Commander (buyer), IR Lead (seller), Other
      • If Other above, enter the exact role that will sign entries (leave blank if not applicable)

      Notification Templates & Required Fields — What Alerts Contain

      • Enter the exact identifier or name of the initial incident activation notification template to use (format: template_name or template_id)
      • Primary notification channel for initial activation (choose one) Options: Email, Phone call, SMS, Secure messaging (your secure messaging platform), Pager
      • Primary recipient role for the initial activation notification (choose one) Options: CISO, General Counsel, Head of IT Operations, Incident Response Manager, Other
      • If you selected Other for primary recipient, enter exact role name (leave blank if not applicable)
      • Select which minimum data fields MUST be present in the initial notification (multi-select allowed) Options: incident_id, timestamp (ISO8601), impact summary, activate/standby decision, primary point of contact (Name — Role), initial severity estimate
      • Enter the exact subject-line template for automated notifications (use placeholders {incident_id}, {severity}, {timestamp} as needed). Example: "IR Activation — {incident_id} — {severity}"
      • Enter the exact filename prefix convention for evidence exports (single token, e.g., ir_{incident_id})

      Escalation Thresholds & SLA Numbers — Numerical Limits We Enforce

      • Activation SLA — guaranteed maximum minutes from buyer activation to seller onboarding start. Default: 120
      • Time from activation to first forensic imaging start (hours). Default: 2
      • Time-to-first-technical-report (hours). Default: 8
      • Executive notification escalation threshold (minutes after activation). Default: 180
      • Maximum allowed concurrent incidents under this retainer configuration (numeric). Default: 1
      • If the maximum concurrent incidents above is exceeded, select the default escalation action (choose one) Options: Prioritize by severity (seller discretion), Buyer to authorize resource reallocation, Queue until capacity available, Other (describe below)
      • If Other, enter the exact escalation action text (leave blank if not applicable)

      Access & Integration Points — Exact Identifiers

      • Enter the exact field name in your SIEM that will be used as the canonical incident identifier (do not provide examples — enter exact field)
      • Monitoring access method to provide to the seller (choose one) Options: Read-only SIEM API access (identifier only), Read-only logging S3 access (bucket name), Shared monitoring dashboard read-only (dashboard ID), None — buyer will push artifacts manually
      • If you selected an API or integration above, enter the integration identifier (service account name, dashboard ID, or bucket name). Do NOT paste credentials
      • Enter the owner (Name — Role) who will approve integration access requests for the identifier above
      • Identity provider type for any SSO/token flows (choose one) Options: SAML-based IdP, OIDC-based IdP, None / not used
      • If SSO/IdP is used, enter the entity ID or issuer URL exactly as it should be configured (format: https://... or entity-id). Leave blank if not applicable

      Operational Runbook Values — Names, Templates, and Trees

      • Incident Commander (exact: Full Name — Role). This person will be named in runbooks and notifications
      • Primary legal contact for privilege questions (exact: Full Name — Role)
      • Enter the escalation phone-tree order as a single comma-separated string of roles (highest priority first). Example: CISO, General Counsel, Head of Ops
      • Enter the exact evidence labeling convention string (use {incident_id} placeholder). Example: {incident_id}_device_hostname_timestamp
      • Runbook playbook owner (Name — Role) who will be assigned recurring readiness checks
      • Enter the cadence in days for recurring readiness checks once activated (numeric). Default: 90
    3. Retainer Activation & Exercises

      Execute onboarding tasks, run a live rehearsal or activation drill, schedule recurring readiness checks, and assign named owners for playbook execution.

  7. Success

    Validate operational readiness through recurring reviews, capture lessons from incidents and exercises, and maintain a shared tracker for issues and enhancement requests.

    Success Reviews

    • Go-live Health Check (Week 1-4)
    • First Measurement Review (Weeks 4-10)
    • Acceptance Gate, Operational Readiness Decision (Day 90)
    • Quarterly Operational Review
    • Annual Lessons and Continuous Improvement Review

    Issues & Enhancements

    • Ensure the top three tracker items are assigned target close dates and a verification step scheduled.
    • Deliver a metric reconciliation package showing raw logs and calculation methodology for each reported metric.
    • Add remediation tasks to the shared tracker with target completion dates ahead of the Acceptance Gate.
    • Restate the acceptance criteria and numeric targets
    • Produce a documented acceptance decision with pass/fail per acceptance criterion recorded in Retainer Scope and Mutual Commit.
    • List remediation items for any failed criteria with clear owners and completion dates to remove conditional acceptance.
    • Publish the signed acceptance statement and the acceptance evidence packet to the shared workspace.
    • Add remediation exceptions to the tracker and schedule follow-up verification on or before the agreed completion dates.
    • Quarterly performance trends
    • Confirm that quarterly performance on the named metrics is documented against Retainer Scope targets and that outliers have remediation plans.
    • Re-confirm deployment scope and owners
    • Update the shared tracker with quarter-end metric exports and attach incident evidence summaries for any activations reviewed.
    • Schedule required training or configuration updates and document expected impact on the named metrics.
    • Year-to-date performance summary
    • Agree a prioritized annual improvement plan that addresses recurring failure modes and is tied to measurable metric improvements.
    • Designate the continuous improvement owner and a quarterly check-in schedule to monitor progress on the annual plan.
    • Publish the annual performance and lessons report, including the prioritized enhancement plan and expected metric impact.
    • Add approved enhancement items to the shared tracker with estimated completion windows and verification criteria.
    • Confirm that all critical deployment artifacts listed in Onboarding Readiness and Operational Configuration are present and accessible.
    • Produce a short list of open issues with owners and target resolution dates before the next review.
    • Publish a deployment verification checklist with status and owners for each item.
    • Schedule a follow-up verification within two weeks to confirm remediation actions completed.
    • Present first-period performance data
    • Document where each named metric stands relative to the numeric targets recorded in Retainer Scope and Mutual Commit.
    • Agree a timebound remediation plan for each metric that is not meeting target, with owners and dates.
    • Validate deployment artifacts
    • Present consolidated outcomes
    • Diagnose gaps and root causes
    • Consolidated lessons from incidents and exercises
    • Review incidents and exercise lessons
    • Document pass or fail per criterion
    • Open issues tracker and enhancement backlog
    • Agree corrective actions and ownership
    • Review early adoption and usage signals
    • Prioritize enhancement requests and backlog
    • Capture formal acceptance decision and signatory
    • Confirm readiness for Acceptance Gate
    • Agree short-term operational adjustments
    • Surface open issues and blockers
    • Confirm continuous improvement cadence and owners
    • Agree immediate remediation actions
    • Agree remediation items and resolution timeline
First-Party AI

1-2 minutes please — Your AI agent is working

First-Party AI™ can make mistakes. Always check important information.