Resilience & Response
Incident Response
Before, during and after an incident — with legal-grade evidence.
Readiness when it counts, a calm hand under pressure, and lessons the board can act on.
- Independent and agnostic
- Evidence-driven analysis
- Clear, actionable recommendations
- Senior attention, end to end
The challenge
The first hour decides most of what follows.
When an incident hits, the early decisions — what to isolate, what to preserve, who to tell — shape the cost, the recovery and the legal position for months. Made in a panic, without a plan or preserved evidence, they tend to be the wrong ones: systems wiped that held the answer, disclosure mishandled, downtime extended. Preparation and evidence discipline are what separate a contained event from a crisis.
What I do
Calm response, preserved evidence.
Get ready, take charge when it happens, and turn the aftermath into durable improvement.
How I workReadiness & Playbooks
Playbooks and tabletop exercises before the event.
Response Retainer
Contracted availability under retainer when you need it most.
Containment
Decisive action to limit the damage.
Forensic Investigation
Legal-grade evidence, properly preserved.
Recovery
A path back to operations, with priorities agreed.
Board Report & Lessons
What happened, what it means, and what changes.
My approach
A disciplined response, under pressure.
Preparation and evidence discipline change the outcome.
Explore my method- 01
Prepare
Playbooks, exercises and a retainer with contracted availability.
- 02
Detect
Establish what happened and how far it reaches.
- 03
Contain
Limit the damage while preserving evidence.
- 04
Recover
Restore operations against agreed priorities.
- 05
Learn
Board-ready findings and durable improvements.
- A rehearsed plan and clear roles, so the first hour is not improvised.
- Contracted availability under retainer, ready before you need it.
- Evidence preserved to a legal standard, keeping your options open.
- A board-level account of what happened, what it means and what changes.
Case study
Ransomware Response for an Omnichannel Retailer
Containment, preserved evidence and priority-led recovery after warehouse and point-of-sale systems were encrypted.
Read the case study
Work & insights
What I’ve done
Incident ResponseThe first 60 minutes of an incident: what to do (and what not to do)
Containing the attack without destroying the evidence you will need later.14 Dec 2025 · 4 min read
RansomwareRansomware: pay or don’t pay is the wrong question
The decision is prepared months earlier, while you are not yet on fire.22 Nov 2025 · 4 min read
Incident ResponseThe incident response retainer: why preparation changes the outcome
A contract already signed, a plan already rehearsed, roles already assigned.18 Oct 2025 · 4 min read
Frequently asked
Questions I get asked.
Do we need a retainer, or can you help during an incident?
Both. A retainer gives you contracted availability and someone who already knows your environment. I can also engage during a live incident, though preparation always widens the options.
Why does evidence handling matter so early?
Because the actions taken to stop an incident can destroy the evidence needed to understand it — or to support a claim, a disclosure or a dispute later. Containing the damage and preserving evidence are done together, not in sequence.
What happens after the incident is contained?
I move to recovery against agreed priorities, then to a board-level report: what happened, how far it reached, and the specific improvements that stop a repeat.
Do you work with our legal and communications teams?
Yes. Response decisions have legal and disclosure consequences, so I work alongside your legal counsel and communications, not around them.
Ready to start?
Let’s talk about your case.
Every situation is unique. Tell me the context and I’ll help you define the best approach.
Book a consultation