Skip to content
All services
Security hardening & assuranceBuild

NIS2 incident readiness

An incident response plan, cloud runbooks and forensic readiness that help you prepare for the NIS2 reporting deadlines, tested in a tabletop exercise with your team over two to three weeks.

When you need it

You fall under NIS2, or your customers expect you to act as if you do. Your incident process was written before it, and nobody is sure who decides an incident is significant, who sends the 24-hour early warning or whether the logs you would need still exist.

What sets the quote

  • Two weeks cover one cloud, up to 3 critical services and runbooks for up to 5 incident types.
  • Three weeks cover up to 2 clouds, 6 critical services and 8 incident types.
  • One tabletop exercise of up to 3 hours, with up to 10 participants.
  • Larger scopes are quoted after sizing.

What changes

  • Your team knows who decides an incident is significant, who reports it and what each report contains.
  • The early warning, the notification and the final report each have an owner, a template and a deadline.
  • The logs and disk snapshots an investigation needs exist, are kept long enough and can be collected without destroying evidence.
  • A tabletop exercise has shown where the plan holds and what to fix, before a real incident does.

What you get

  • Incident response plan with roles, severity levels, the escalation path and the decision on significance
  • Runbooks for the incident types in scope, such as a compromised admin account, ransomware on a server or data exposed in cloud storage
  • Reporting runbook and templates for the early warning within 24 hours, the notification within 72 hours and the final report within one month of the notification
  • Contact list for authorities, customers and suppliers
  • Cloud forensic readiness, with log retention settings and snapshot and isolation procedures, tested with your team on one system
  • Tabletop exercise on a realistic cloud incident, with the reporting clock running
  • After-action report with prioritised fixes, and the plan updated to match

This is technical and operational readiness work, not legal advice. Your legal counsel confirms whether and how NIS2 applies to you under your country’s law. The cloud alerting baseline pairs well with it: its alerts start the runbooks written here.

Not included

  • Legal advice, including whether and how NIS2 applies to you
  • NIS2 compliance assessments, audits or certification
  • Handling a live incident, forensic investigation, or filing reports with authorities for you
  • 24/7 security monitoring (SOC or MDR)

What we need from you

  • Your legal counsel's view on whether NIS2 applies to you and which authority you report to.
  • Your current incident process, the list of critical services and the contacts of key suppliers.
  • Read-only cloud access: SecurityAudit and ViewOnlyAccess on AWS, Reader and Security Reader on Azure, or Viewer and Security Reviewer on Google Cloud.
  • Your security, legal and communications leads for the runbook sessions, and up to 10 people for the tabletop exercise.

How it works

  1. Free 30-minute call, then a written fixed quote.

  2. Review your incident process, critical services and cloud logging against the reporting deadlines.

  3. Write the plan, runbooks and templates with your security, legal and communications leads, and test the snapshot procedure with your team.

  4. Run the tabletop exercise on a realistic cloud incident, with the reporting clock running.

  5. Deliver the after-action report and update the plan with what the exercise showed.

At a glance

Duration
2–3 weeks
Price
Fixed quote after a free 30-minute call
Delivered by
Our lead architect
Assess Popular

Zero Trust assessment

In 1–2 weeks, a review of identity for people, devices and workloads, cloud guardrails and CI/CD, with every control checked as declared, refused and in effect, ending in a maturity rating per area and a roadmap.

Duration:1–2 weeks
Assess

Threat modelling workshop

A STRIDE threat model of one system or major feature, built with your team in two half-day sessions over one to two weeks, with a data-flow diagram, trust boundaries and prioritised mitigations in your backlog.

Duration:1–2 weeks
Build Popular

OS hardening baseline

Linux and Windows Server hardened to CIS Benchmarks Level 1 in two to six weeks, built as code with golden images, enforced settings, drift checks and compliance evidence for every host.

Duration:2–6 weeks

Not sure where to start?

Book a free 30-minute call. We learn what you need and tell you honestly whether and how we can help. There is no obligation.