Cybersecurity — Incident Response
Incident response services for New York businesses
The middle of an incident is a bad time to exchange business cards. We write the playbooks before, contain and coordinate during, and keep your insurer, counsel, and regulatory clocks in view throughout.
Most of incident response happens before the incident
The outcome of a security incident is largely decided in advance: whether the logs exist to show what happened, whether the backups restore, whether anyone holds written authority to isolate machines at 2 a.m., and whether the insurance carrier was called inside its notice window. None of that can be improvised well while a ransomware note is on the screens.
So the readiness engagement does the deciding early. We write an incident response plan for your firm — who declares an incident, who calls whom, in what order, what gets disconnected and by whose say-so — plus playbooks for the events most likely to actually happen: business email compromise, ransomware, a lost or stolen device, a vendor breach. Then we run a tabletop exercise, because the exercise always finds what the paper missed.
Incident response closes the loop of our managed cybersecurity practice: MDR hands it contained hosts and a timeline; it hands back root causes for patching and policy.
Readiness: what’s included
An IR plan written for your firm
Decision authority, contact order, and disconnection criteria specific to your environment — not a template binder with your logo on page one.
Scenario playbooks
BEC, ransomware, lost device, vendor breach — each with first-hour actions, owners, and the questions that must be answered before anyone says “resolved.”
Contact and decision tree
Carrier hotline, breach counsel, leadership, key vendors — with out-of-band channels, because the incident may own your email.
Insurer alignment
Your policy’s notice deadlines and approved-vendor requirements are read before the incident and written into the playbook, not discovered during it.
Evidence and log readiness
Retention and access checked against the log pipeline so investigators have a record to work from, not a shrug.
Tabletop exercises
A structured walkthrough with your leadership on a realistic scenario. Uncomfortable in the conference room, cheap compared to the alternative.
When something happens
Report and triage
One channel to reach us. An engineer scopes it fast: what is affected, is it spreading, is it contained — facts before conclusions.
Contain
Isolate hosts, disable accounts, block senders, revoke sessions — under the standing authority agreed in your MDR scope, so containment moves at machine speed, not meeting speed.
Notify and coordinate
Your carrier’s notice clause and panel requirements kick in early. We work alongside panel forensics and breach counsel, not around them — and we preserve evidence rather than trampling it.
Eradicate and recover
Rebuild what cannot be trusted, restore from tested backups, rotate credentials, and verify the attacker’s access is actually gone before declaring it so.
Meet the clocks
Regulatory timelines run during recovery — NYDFS requires notice of qualifying cybersecurity events within 72 hours, with additional obligations around extortion payments. Counsel determines the legal duty; we assemble the facts it depends on.
Review
A written post-incident review: what happened, what worked, what did not — feeding fixes back into patching, identity policy, and training.
Your insurer is part of the response
Cyber policies are operational documents, not just financial ones. Many require notice within days of discovery, route forensics and breach counsel through approved panels, and expect the insured not to run up costs the carrier has not authorized. Late notice or unapproved spend can complicate a claim at the exact moment you need it paid. The time to read those clauses is before the incident — so we read them with you and build their requirements into the playbook.
Our role is deliberately bounded: we are the operational team — containment, investigation support, recovery, coordination. We are not breach counsel, and when legal-grade forensics is required, it is done by the carrier’s panel or a counsel-retained firm while we keep your business running. Clear lanes make faster incidents.
Keep beside the plan
Carrier hotline and policy number
Breach counsel contact
Who can authorize disconnection
Out-of-band contact channels
Location of the last restore test
Common questions
Who do we call first — you or the insurance carrier?
In practice, both within the first hour: containment starts immediately, and your policy’s notice clause gets honored fast. The playbook we write makes this a checklist rather than a debate, and we will never advise sitting on carrier notice — that decision has claim consequences we do not gamble with.
Are you a digital forensics firm?
No. We do operational incident response: containment, scoping, recovery, and coordination. When an incident needs forensics that will stand up in litigation or a regulatory inquiry, that work belongs to the carrier’s panel or a firm retained by counsel — and our job is to preserve evidence and keep your operations moving while they do it.
What does NYDFS require after an incident?
Covered entities must notify the superintendent within 72 hours of determining that a qualifying cybersecurity event occurred, and the amended rules add obligations around extortion payments, including prompt notice and a written explanation. Whether a given event is reportable is a legal judgment for you and counsel; our part is the timeline, the scope, and the evidence that judgment depends on. Details on our NYDFS Part 500 page.
Can we call you mid-incident if we are not a client?
You can, and we will help if we have the capacity — but honestly: firms already under our management start faster, because access, logs, and containment authority exist from day one. For everyone else, that first day is discovery. The readiness engagement exists precisely so hour one is execution instead.
How fast do you respond?
We publish the escalation path, paging procedure, and containment authority in each client’s agreement rather than advertising a response-time number. A new firm quoting dramatic SLA figures it has never been tested against should worry you — we would rather show you the mechanism than the marketing.
Write the playbook while things are quiet.
A readiness engagement now beats a business-card exchange mid-incident.