← All services

Incident Readiness Review

Find gaps in your plan for one incident scenario.

Choose one incident scenario and one environment. Review your preparation, identify gaps and give the responsible team a clear record of open decisions.

Price
€5,000–€25,000 · excluding VAT
Delivery
Confirmed during the non-secret fit check
Scope this review

Start with a short description. We confirm fit and scope before work begins.

See a sample review →

What you get

  • Readiness observations for one agreed incident scenario.
  • Findings and supplied evidence references.
  • A report of gaps, unknowns, exclusions and open decisions.

Scope and limits

Preparation review only. No live incident command, emergency response or compromise claim.

Do not send passwords, private keys, API keys, recovery codes, session tokens or other secrets.

Who it is for

Security and operations teams preparing for one incident scenario in one environment.

Company background

WitnessOps was founded by Karol Stefanski, previously an engineer at Waystone and Nostra. Professional background on LinkedIn →

Your part in the engagement

What do you need from me?

Name one incident scenario, environment and decision. We agree the documents, owners and permitted observations needed to review that scenario.

What access is required?

Only the agreed documents and authorized observations. No destructive testing or production containment is included; do not send incident secrets through the enquiry.

What happens after delivery?

You receive readiness findings, missing evidence and open decisions. Your team owns plan changes and response actions; this is not an emergency incident-response service.

How the engagement works
  1. 1. Fit check

    Name the incident scenario and environment without sending sensitive case files.

  2. 2. Authority

    Confirm scenario, inputs, price, timing and evidence handling.

  3. 3. Review and assembly

    Assess preparation against the scenario; keep unknowns and assertions distinct.

  4. 4. Delivery

    Hand over a readiness package owners can use to close gaps before an incident.

Full scope and exclusions

Quoted after fit check for one defined scenario and environment.

  • No hack-back, exploitation, destructive testing or live incident command.
  • No compromise, root-cause or attribution claim.
  • Secrets and customer case material are not accepted until handling is agreed.
  • Not a 24/7 service, compliance certification or continuous monitoring.

Not included

  • hack-back
  • destructive testing
  • live incident command
  • secret intake before handling is agreed
  • guarantee of incident outcome

Service reference: OFFSEC-INCIDENT-READY

Example and technical details

What the result supports

This review produces a readiness report for one defined incident scenario, separating observed preparation, assertions, unknowns, and open decisions. It is not emergency incident response or a 24/7 service.

How to inspect the result

Use the readiness report and named evidence references to inspect the bounded picture and gaps.

Scope this review

Start with a short description. We confirm fit and scope before work begins.

Incident Readiness Review | WitnessOps