Incident Readiness Review
One named incident scenario. A readiness package — not live incident command.
You need a bounded readiness record for one named incident class and environment — preparation, unknowns and open decisions on the package.
Do not send passwords, private keys, API keys, recovery codes, session tokens or other secrets.
Who it is for
Security and operations teams that need a bounded readiness record for one named incident class and environment before an event — not emergency IR.
What you receive
- sanitised readiness observations for the admitted scenario
- posture and findings against preparation questions
- unknowns, exclusions and open decisions
- evidence references where supplied
- named limits on what the review can conclude
How it works
1. Fit check
Name the incident scenario and environment without sending sensitive case files.
2. Authority
Confirm scenario, inputs, price, timing and evidence handling.
3. Review and assembly
Assess preparation against the scenario; keep unknowns and assertions distinct.
4. Delivery
Hand over a readiness package owners can use to close gaps before an incident.
What is claimed
This review produces a readiness report for one defined incident scenario, separating observed preparation, assertions, unknowns, and open decisions. It is not emergency incident response or a 24/7 service.
How to inspect the result
Use the readiness report and named evidence references to inspect the bounded picture and gaps.
Boundaries
- No hack-back, exploitation, destructive testing or live incident command.
- No compromise, root-cause or attribution claim.
- Secrets and customer case material are not accepted until handling is agreed.
- Not a 24/7 service, compliance certification or continuous monitoring.
Not included
- hack-back
- destructive testing
- live incident command
- secret intake before handling is agreed
- guarantee of incident outcome
Start a review
Primary route: /review/request
Fallback contact: engage@mail.witnessops.com
Do not send passwords, private keys, API keys, recovery codes, session tokens or other secrets.