Breach response and readiness
Someone to call and a plan for the first hour.
$670 per month for readiness, with the hours credited.
Who do you call first when nothing opens in the morning?
Usually a friend who "knows this stuff". Then an hour goes on finding out: who holds the access, where the backups are, who must be told and by when. That hour costs more than everything else. And you spend it again every time.
Who to call is decided in advance
You no longer spend that hour finding out. You hold a plan with roles and phone numbers; we hold the map of your systems, the access and a clear idea of what to bring back first. The conversation starts with the work, not with introductions.
Once a year we run a drill on that plan: who calls, who pulls the plug, who writes to clients and by when. After the drill the plan gets fixed — usually in three places, and they are exactly the three that matter.
The hours do not expire: if a breach happens, they go into the work on it. We prepare the notices on time too — and that deadline is usually shorter than people think.
What readiness includes
- included: A plan on paper: who does what and on which numbers
- included: A map of your systems and access that we keep current
- included: On call: the time we start is written into the contract
- included: A drill once a year, and the plan fixed after it
- included: We preserve the traces of the breach before bringing anything back
- included: Notices to clients and the regulator — we help send them on time
- included: Six hours a month that go into the work on a breach
- paid to the vendor: Lawyer, insurer and data recovery — billed by them
Your price
Readiness, month by month
$670 a month
Six hours a month for the plan, the map and the drill.
What the tier includes
- included: Plan, map of systems, start time in the contract and a yearly drill
- included: The hours count towards the work on a breach
Extras
- not included: Backups and a check that they actually restore$1,340 a year
- not included: We watch for attacks around the clock$18 per endpoint a month
- not included: External penetration test of network and applicationsfrom $4,480
- not included: Fractional chief information security officerfrom $2,500 a month
- not included: Preparing for a cyber policy renewal$2,250 one-off
- not included: Questionnaires your client has sent$1,350 per questionnaire
- not included: Employee computers looked afterfrom $102 per seat
- not included: Patient records kept protected+$40 per seat a month
Questions
What does the response itself cost if we are breached?
The rate sits in the contract, not on a page. People look for this price on the worst day of their life, and haggling that day is not fair — so it is agreed in advance. The hours you pay for every month count towards this work in full.
Nothing has ever happened to us. Why pay every month?
For what gets done in advance and cannot be done on the day it breaks: the plan, the map of systems, the access, the drill. Your insurer and your client ask for those same four things, so the monthly fee covers their questionnaires too. None of it can be assembled after the fact.
How soon will you start?
The time is written into the contract as a number and depends on whether you call by day or by night. We will not promise minutes we cannot hold: the contract carries the time we meet every time, not on a good day.
Who has to be notified, and when?
It depends on whose data is touched: health records have their own deadline, state laws have theirs, your client contract a third. We gather these deadlines in advance and keep them in the plan, so nobody hunts for them on the day there is no time.
Tell us what you run today and who you call first — we will send a quote by email.
We have your request
We answer during the hours listed in the contacts at the foot of the page. The quote and the conversation come first — nothing is signed and nothing is charged.