Back to services

Incident Readiness Review

One named incident scenario. A readiness package — not live incident command.

You need a bounded readiness record for one named incident class and environment — preparation, unknowns and open decisions on the package.

Do not send passwords, private keys, API keys, recovery codes, session tokens or other secrets.

Who it is for

Security and operations teams that need a bounded readiness record for one named incident class and environment before an event — not emergency IR.

What you receive

  • sanitised readiness observations for the admitted scenario
  • posture and findings against preparation questions
  • unknowns, exclusions and open decisions
  • evidence references where supplied
  • named limits on what the review can conclude

How it works

  1. 1. Fit check

    Name the incident scenario and environment without sending sensitive case files.

  2. 2. Authority

    Confirm scenario, inputs, price, timing and evidence handling.

  3. 3. Review and assembly

    Assess preparation against the scenario; keep unknowns and assertions distinct.

  4. 4. Delivery

    Hand over a readiness package owners can use to close gaps before an incident.

What is claimed

This review produces a readiness report for one defined incident scenario, separating observed preparation, assertions, unknowns, and open decisions. It is not emergency incident response or a 24/7 service.

How to inspect the result

Use the readiness report and named evidence references to inspect the bounded picture and gaps.

Boundaries

  • No hack-back, exploitation, destructive testing or live incident command.
  • No compromise, root-cause or attribution claim.
  • Secrets and customer case material are not accepted until handling is agreed.
  • Not a 24/7 service, compliance certification or continuous monitoring.

Not included

  • hack-back
  • destructive testing
  • live incident command
  • secret intake before handling is agreed
  • guarantee of incident outcome

Start a review

Primary route: /review/request

Fallback contact: engage@mail.witnessops.com

Do not send passwords, private keys, API keys, recovery codes, session tokens or other secrets.

Incident Readiness Review | WitnessOps