01 · Establish the baseline
Incident Response Capability Validation
Independently verify whether your organisation can coordinate, decide, investigate, contain, communicate, and recover under realistic pressure.
Designed for
An uncertain baseline
When confidence exists, but independent evidence doesn't.
Engagement
Fixed and bounded
A defined assessment, not a sales-led pre-engagement.
Outcome
Defensible clarity
Where capability holds and where attention is required.
The assessment
Test performance, not paperwork.
Capability Validation combines targeted evidence review, executive walkthroughs, and realistic scenario pressure.
The result isn't a generic maturity score. It's an independent baseline showing where preparedness is credible, where it's exposed, and what should be addressed first.
Scope
Eight dimensions of response capability.
Command
Ownership, authority, and escalation.
Decision-making
Choices made with incomplete information.
Investigation
Evidence access, preservation, and analysis.
Containment
Action balanced against consequence.
Eradication
Attacker access, persistence, and exploited weaknesses.
Communication
Executive, legal, and external coordination.
Dependencies
Providers, vendors, and critical third parties.
Recovery
Priorities, evidence, and decision gates.
Deliverables
A clear answer and a practical path forward.
- Independent capability baseline
- Observed structural and procedural gaps
- Prioritised improvement roadmap
- Board-ready summary material
- Evidence for regulator and insurer discussions
Frequently asked questions
Before we begin.
Clear answers to the practical questions that shape an engagement.
What is an incident response capability assessment?
An incident response capability assessment is a structured review and validation exercise designed to determine whether your organisation can effectively respond to a cyber incident under real conditions.
It tests plans, decision-making, coordination, and technical response to establish a clear, defensible baseline of your current capability.
What does the validation process involve?
The process combines structured review and scenario-based validation activities to assess how your organisation performs under realistic conditions.
In many cases, this highlights gaps between documented plans and actual capability that are only visible under pressure.
What outcomes should we expect?
You will receive a clear understanding of your current incident response capability, including identified gaps, areas of risk, and where improvements are required.
The outcome is a structured, prioritised path forward to strengthen readiness and move toward defensible assurance.
How is this different from a traditional security assessment?
Traditional assessments often focus on controls, compliance, or documentation.
Capability Validation focuses on whether your organisation can actually respond effectively during an incident, testing performance under realistic conditions rather than theoretical readiness.
Who is this designed for?
This engagement is designed for organisations that need confidence their incident response capability will hold under real conditions.
It is particularly relevant for regulated and high-consequence environments where response effectiveness is subject to scrutiny.
What happens after validation?
Following validation, most organisations move into a structured Readiness Program to address identified gaps and improve capability over time.
Where ongoing assurance is required, this can progress into a continuous Assurance Program.
How do we get started?
Engagements begin with a short discussion to understand your current environment and confirm scope.
If you are evaluating your incident response capability, this is the most effective starting point.
Why do organisations start with validation instead of going straight to a retainer?
Without a clear baseline, organisations often invest in ongoing services without knowing whether their core capability is effective.
Validation ensures that any subsequent investment is targeted, structured, and aligned to real-world requirements.
Next step
A confidential review of your current position.
A focused discussion to understand your environment, current assurance requirements, and whether our operating model is appropriate.