Incident Readiness Review
Find gaps in your plan for one incident scenario.
Choose one incident scenario and one environment. Review your preparation, identify gaps and give the responsible team a clear record of open decisions.
- Price
- €5,000–€25,000 · excluding VAT
- Delivery
- Confirmed during the non-secret fit check
Start with a short description. We confirm fit and scope before work begins.
What you get
- Readiness observations for one agreed incident scenario.
- Findings and supplied evidence references.
- A report of gaps, unknowns, exclusions and open decisions.
Scope and limits
Preparation review only. No live incident command, emergency response or compromise claim.
Do not send passwords, private keys, API keys, recovery codes, session tokens or other secrets.
Who it is for
Security and operations teams preparing for one incident scenario in one environment.
Company background
WitnessOps was founded by Karol Stefanski, previously an engineer at Waystone and Nostra. Professional background on LinkedIn →
Your part in the engagement
What do you need from me?
Name one incident scenario, environment and decision. We agree the documents, owners and permitted observations needed to review that scenario.
What access is required?
Only the agreed documents and authorized observations. No destructive testing or production containment is included; do not send incident secrets through the enquiry.
What happens after delivery?
You receive readiness findings, missing evidence and open decisions. Your team owns plan changes and response actions; this is not an emergency incident-response service.
How the engagement works
1. Fit check
Name the incident scenario and environment without sending sensitive case files.
2. Authority
Confirm scenario, inputs, price, timing and evidence handling.
3. Review and assembly
Assess preparation against the scenario; keep unknowns and assertions distinct.
4. Delivery
Hand over a readiness package owners can use to close gaps before an incident.
Full scope and exclusions
Quoted after fit check for one defined scenario and environment.
- No hack-back, exploitation, destructive testing or live incident command.
- No compromise, root-cause or attribution claim.
- Secrets and customer case material are not accepted until handling is agreed.
- Not a 24/7 service, compliance certification or continuous monitoring.
Not included
- hack-back
- destructive testing
- live incident command
- secret intake before handling is agreed
- guarantee of incident outcome
Service reference: OFFSEC-INCIDENT-READY
Example and technical details
What the result supports
This review produces a readiness report for one defined incident scenario, separating observed preparation, assertions, unknowns, and open decisions. It is not emergency incident response or a 24/7 service.
How to inspect the result
Use the readiness report and named evidence references to inspect the bounded picture and gaps.
Start with a short description. We confirm fit and scope before work begins.