NEW SERVICE

Incident Readiness

If your business pays a ransomware demand, you have 72 hours to report it. SOCI entities have as little as 12 hours to notify an incident. These clocks start whether or not your plan is ready, so the useful work happens before the incident. That work is what we do. When something does happen, specialist forensics partners handle the investigation and your plan tells everyone else what to do while they work.

What We Could Do

Incident Response Plan Development
Tabletop Exercises (Executive & Technical)
Ransomware Payment Decision Framework
Regulatory Reporting Playbooks
Board Crisis Briefing
DFIR Retainer Partner Arrangements

The decisions are easier to make on a Tuesday.

In the middle of an incident, someone has to decide whether to pay, who to call, what to tell the regulator, what to tell customers and what to tell the board, all at once and mostly before the facts are in. Every one of those decisions can be roughed out in advance, on a quiet Tuesday, by people who are not frightened. That is the whole argument for readiness work.

The reporting obligations have teeth now. The Cyber Security Act's ransomware payment reporting started on 30 May 2025 and applies to businesses with turnover above A$3 million and every SOCI responsible entity, with 72 hours to report a payment to the Cyber and Infrastructure Security Centre and no grace period. SOCI incident notification runs 12 to 72 hours depending on severity. The OAIC allows 30 days to assess a suspected notifiable data breach, and APRA expects CPS 234 notification within 72 hours. Your playbooks need each clock, each form and each phone number written down before you need them.

We are clear about where we stop. We build plans, run exercises and prepare your people. We do not do digital forensics or incident response operations ourselves. For that we arrange retainers with specialist DFIR firms before you need one, because signing a retainer during an incident is the most expensive way to do it.

  • A response plan your team has rehearsed
  • The pay-or-don't-pay decision framed before anyone is under duress
  • Every regulatory clock, form and contact mapped in advance
  • A DFIR firm on retainer before the day you dial them

Incident Readiness Services

IR Plan & Playbooks

A response plan sized to your organisation, with scenario playbooks for ransomware, data theft and business email compromise. Short enough to be read, specific enough to be followed at 2am.

Tabletop Exercises

Executive tabletops that rehearse the decisions, and technical tabletops that rehearse the containment. Each one ends with a written list of what broke in the exercise, so it doesn't break in the incident.

Regulatory Reporting Readiness

Playbooks for each obligation you carry: Cyber Security Act ransomware reporting, SOCI notification, OAIC notifiable data breaches and APRA CPS 234. Who reports, to whom, by when, with the forms ready.

Written by people who have sat in the room

Our consultants have carried incident and crisis roles inside banks and critical infrastructure operators, where the notification clocks bite and the board wants answers hourly. The plans we write reflect how incidents unfold, including the parts where nobody can reach the one person who knows the system.

Because we do not sell DFIR services, our advice on retainers and escalation is not steering you towards our own response team. We help you pick the partner, then we stay in your corner.

Plans People Can Run

Short documents, clear roles, no laminated binders that nobody opens.

Every Clock Covered

CISC, SOCI, OAIC and APRA obligations mapped to your business, with the forms pre-staged.

Executives Included

The board and executive rehearse their decisions too. Most incident chaos starts above the security team.

No Conflict of Interest

We don't sell the forensics, so the readiness advice serves you, not a services pipeline.

Rehearse Before It Happens

A first tabletop exercise takes half a day and tells you more about your readiness than any document review. Most clients start there.