Incident response
Contain the incident, and close it out.
When you have a live or recent security incident, I help you contain it, find anything else exposed the same way, and close it out.
During and after
What working an incident looks like.
Take a subdomain takeover. A DNS record under your domain still points at a service you stopped using, someone else has claimed it, and they now serve content from your name. Here is how I work it with you.
- 01
I advise on what I found
I show you what the attacker controls and what they can do with your name, from running phishing under your own brand to collecting whatever your users enter.
- 02
I find other records exposed the same way
I sweep your DNS for other names still pointing at services you no longer run, so the next takeover does not happen while we fix this one.
- 03
I help revoke the attacker's certificates
Any certificate the attacker obtained for your name gets revoked, so they can no longer prove to a browser that they are you.
- 04
I close it and keep it closed
We remove or repoint the record so the name is yours again, and I advise on or build guardrails that flag dangling records early and stop a released name from being claimed again.
- What you keep
- A close-out report
- A runbook for incidents like this one
- A post-mortem template
The lifecycle
Prepare, detect, contain, recover, review.
Every incident moves through the same phases. Here is where the work above fits.
Prepare
- Incident response plan
- Tabletop exercises
Detect
- Advise on what the finding means and how far it reaches
Contain
- Find other records exposed the same way
- Revoke the attacker's certificates
Recover
- Remove or repoint the record so the name is yours again
Review
- Guardrails against the next one
- A runbook and a post-mortem template
The business case
An incident costs the most while it stays open. Closing it out with a report, a runbook, and guardrails gives customers, insurers, and auditors the documentation they will ask for.
The compliance case
Supporting evidence for:
- SOC 2 CC7.4, CC7.5
- HIPAA §164.308(a)(6)(ii)
- HITRUST Domain 15
- ISO 27001 A.5.26, A.5.27
- NIST CSF RS.MI-01, RS.MI-02, RS.AN-03
- NIST 800-53 IR-4
References are to the 2017 Trust Services Criteria for SOC 2, the HIPAA Security Rule at 45 CFR Part 164, the HITRUST CSF assessment domains, ISO/IEC 27001:2022 Annex A, NIST CSF 2.0, and NIST SP 800-53 Rev. 5.
Pricing
One-off help starts at $2,000.
The fee depends on the size of the incident. It covers containing it, finding related exposure, and the close-out report, runbook, and post-mortem template.
Before an incident
Set it up ahead of time.
To have this in place before anything goes wrong, with an assessment first and prepaid hours that roll into readiness work like incident response plans and tabletop exercises, see the incident response retainer.
Start with a conversation.
The right engagement depends on what you’re building and where the gaps are. A 30-minute call gets us to whether and how I can help.