Be ready for a security incident — and have help when one starts.
We write your incident response plan and playbooks, set up the reporting paths and rehearse them with your leaders, so everyone knows their part when something goes wrong. On a retainer, we also run the escalation with you and do hands-on containment and investigation.
Readiness for a security incident: a plan, playbooks, reporting paths and a rehearsal. On a retainer, hands-on help when an incident starts.
Why it matters
CERT-In, the Indian Computer Emergency Response Team, gives many organizations in India six hours to report a listed incident. There is no time to write a plan once that clock is running.
What you get
A plan your people can follow, reporting paths that already work, and leaders who have rehearsed the calls they would have to make.
Incident response readiness, for any client
A plan, reporting paths that work and a rehearsal, ready before you need them.
Each piece is something the first hours of an incident will need, whoever responds. You don't need a retainer to buy it.
A plan people can follow
An incident response plan that names who declares an incident, on what criteria, and who has authority to act. Playbooks and runbooks (step-by-step guides) cover incidents such as ransomware and data breaches, with rules for preserving evidence.
Reporting paths that already work
A register of the reporting clocks that bind you, and a point of contact for CERT-In checked against who holds the role today. ICT (information and communications technology) system logs are switched on and kept where they can be produced. Threat detection and log analysis checks that those logs would show an incident at all.
A rehearsal before the real thing
An executive tabletop, a rehearsal held as a discussion, takes your leaders through a ransomware or data breach scenario using the plan as written. Wherever the room stalls, on who decides or on what goes to CERT-In, the plan gets revised. Technical teams rehearse in Blue Team exercises and incident response drills.
Before the first alert
The first hours of an incident are settled before it starts.
CERT-In issued Directions on 28 April 2022 under section 70B(6) of India's IT Act, 2000. They require service providers, intermediaries, data centers, bodies corporate and government organizations to report listed cyber incidents by the end of the sixth hour after noticing them or being told about them.
Those hours go on working out what happened and reporting it. Both depend on logs that were switched on long before anyone noticed. So the clock shapes what you should want from an incident response company.
Two halves you can buy
Readiness, for any client. The plan, playbooks, reporting paths and rehearsal described above, bought on their own.
Response, on a retainer. On either of our two retainer tiers, mid-market / growth or enterprise, we work the incident with your team. Direct board-level reporting comes with the enterprise tier.
How our work lines up with NIST's incident response guidance.
NIST, the US National Institute of Standards and Technology, publishes incident response guidance as SP 800-61 Rev. 3. It maps the older four-phase incident life cycle onto the NIST Cybersecurity Framework (CSF) 2.0, so a plan built on those phases can be traced into the current model. The table shows each phase and where we work in it.
Source: NIST SP 800-61 Rev. 3, Table 1. SecWiz added the third column.
Log and alert readiness for any client; investigation on retainer
Containing, eradicating, recovering
Respond, Recover; Identify (Improvement Category)
Escalation coordination and containment, on retainer
Following up after the incident
Identify (Improvement Category)
Plan revisions and the next tabletop
During an incident
What we do when a retainer client has an incident.
Coordination and hands-on work both come with the retainer. Some decisions stay with your leadership.
01
The alert arrives
It may come from the logging and alerts your team runs, including any we helped set up. It may also come from your staff, a supplier or a customer.
02
Escalation begins
We run the escalation plan with you: bringing in leadership, coordinating with regulators such as CERT-In, and keeping suppliers and other parties working from the same facts.
03
Containment
We do hands-on containment in your environment, limiting the incident's effects so the investigation is not chasing a spreading attack. Steps your plan reserves for leadership wait for leadership's call.
04
Investigation
We investigate how the incident started, which systems and data it reached, and whether the attacker still has access. What leadership and regulators hear then rests on evidence.
05
Follow-up
Afterwards, the plan is revised where it fell short, and the next tabletop tests the change.
Before you sign a retainer
What to settle in writing with any incident response company.
Each point belongs in the retainer, agreed while nobody is under pressure.
Coverage. Which systems, sites and cloud accounts the retainer covers, and what happens when an incident starts outside them.
Reaching the provider. How quickly response starts and how the provider is reached, written into the retainer itself.
Taking a service offline. Who can approve taking a critical service offline outside business hours, and who decides if that person is unreachable.
Regulator reports. What the provider prepares for your report to CERT-In or a sector regulator, and who signs it off.
Access from the start. Whether investigators can reach your logs and consoles straight away, or must wait for access mid-incident.
Staff reporting. How staff report a suspicious email or call, and whether training has taught them that route.
What readiness work does not include. Hands-on response. That comes only with a retainer, on the terms written into it. SecWiz does not operate a security operations center, and it is not a law firm, so it gives no legal advice.
Retainers, CERT-In reporting, NIST's guide and legal advice. For anything else, ask us directly.
SecWiz helps set up the logging and alerts your team runs. SecWiz does not operate a security operations center. Where a managed security retainer includes security monitoring, its coverage hours and escalation path are agreed in writing. Incident response comes with a retainer. When a retainer client has an incident, SecWiz contains it and investigates hands-on, and runs the escalation plan that brings in leadership, regulators and other parties. How SecWiz is reached, and when response begins, is written into each retainer.
Incident response is part of a SecWiz retainer, so the retainer's term applies: at least 6 months, and 12 months by default. Clients who do not want a retainer can still buy readiness work on its own, covering the plan, playbooks, reporting paths and an executive tabletop to rehearse them before an incident.
CERT-In's May 2022 FAQ says any entity that notices a cyber security incident must report it, and that this duty cannot be transferred to another party, even by contract. Hiring a provider does not move that duty off your organization. A retainer changes the work around it: SecWiz coordinates with regulators while running your escalation plan, and its investigation supplies the facts.
No. NIST withdrew SP 800-61 Revision 2, the Computer Security Incident Handling Guide first published in August 2012, on April 3, 2025, and Revision 3 replaces it. A plan still built on Revision 2 cites a withdrawn document. Beyond the citation, read the plan against Revision 3 at its next review, starting with how its phases map to CSF 2.0.
CISA, the US Cybersecurity and Infrastructure Security Agency, publishes free Tabletop Exercise Packages for organizations to run their own exercises, and says more than 100 are available. Each is customizable, with template objectives, scenarios and discussion questions. No package can supply your own plan, the people it names or your regulators' reporting deadlines, so write those in before the exercise starts.
SecWiz does not give legal advice, after a breach or at any other time, because it is not a law firm. For a retainer client its part is containment, investigation and running the escalation plan with regulators and other parties. That produces the facts your lawyers need; liability, contracts and what must be disclosed to whom belong with your own counsel.
Let's talk
Send the plan you have, or tell us there is none.
Send your incident response plan, if one exists, with the date it was last exercised and the regulators you report to. Say whether you want readiness work alone or a retainer. How you reach us during an incident, and when response begins, is written into each retainer. We reply within one working day.