Articles tagged: Incident Response
23 articles on Incident Response from the Top Floor insights library.
2026-08-25
Incident Response for Small Businesses: What You Can Actually Get
A company with no security team can get real incident response, and most of it is already paid for or free: the panel inside its cyber policy, a retainer with no annual fee, the FBI and CISA reporting channels, and counsel who hires the investigator. What each one gives you, and the order to use them in.
2026-08-23
How to Write an Incident Response Plan (NIST SP 800-61r3)
The authoritative reference changed in April 2025, and most plans still teach the withdrawn model. Six questions a plan has to answer, what NIST puts in the policy instead, and the paragraph on containment authority that nearly every template omits.
2026-08-23
Should You Pay the Ransom? The Legal and Practical Answer
Paying is not generally illegal, but OFAC penalties are strict liability, so not knowing who received the money is not a defense. What payment actually buys, the four facts that decide it, and why reporting early is the single cheapest thing you can do.
2026-08-23
What Is a Tabletop Exercise, and What Does It Actually Prove?
NIST defines a tabletop as a discussion-based exercise that deploys no equipment, typically running two to eight hours. That boundary is the whole definition, and it is also the honest limit on what the exercise can tell you.
2026-08-23
Is It a Reportable HIPAA Breach? The Four-Factor Test
Every impermissible use or disclosure of unsecured PHI is presumed to be a breach. You are not deciding whether to notify; you are deciding whether you can document your way out of a presumption, and the burden of proof is on you.
2026-08-22
Digital Forensics vs Incident Response: Which Do You Need?
Incident response stops the attack; forensics proves what happened to someone who does not trust you. NIST defines both, most firms sell them bundled, and buyers rarely find out which half they paid for. Here is where the line sits.
2026-08-22
Incident Response vs Disaster Recovery vs Business Continuity
Incident response contains, disaster recovery restores, business continuity keeps the company trading. NIST's actual taxonomy has eight plan types, and the document most companies call a DR plan is not one under that definition.
2026-08-22
How Long Does Ransomware Recovery Actually Take?
Survey data puts most organizations back within a week and the average at about three weeks, but the distribution is wide and more than one factor widens it. What 'fully recovered' leaves out, and the clocks that keep running after systems come back.
2026-08-22
How to Run a Post-Incident Review That Actually Changes Things
NIST moved lessons learned out of the closing phase and into continuous improvement, and said to share them as soon as they are identified. Four artifacts to leave with, why blameless is a technique rather than a mood, and the two audiences that make this non-optional.
2026-08-21
Red Team vs Penetration Test: Which Does Your Company Need?
A penetration test finds as many vulnerabilities as possible in a defined scope. A red team tests whether anyone notices an attack in progress. CISA's own red team went undetected for an entire assessment at a mature organization, which is the argument for building detection before you buy the exercise that measures it.
2026-08-21
10 Questions to Ask Before Hiring a Digital Forensics Firm
There is no credible ranking of forensics firms, so the buyer has to supply the criteria. Ten questions covering examiner certifications, testimony history, chain of custody, insurer panels, and who owns your evidence afterward.
2026-08-21
How to Answer a Cyber Insurance Questionnaire Honestly
Carriers treat application answers as warranties. Travelers went to federal court in 2022 to rescind a ransomware policy over an overstated MFA answer, and the policyholder agreed to the rescission. Here is how to answer without voiding your own cover.
2026-08-20
Is Your Breach Forensic Report Privileged? Probably Not
Capital One and Clark Hill both lost the fight to keep their forensic reports out of plaintiffs' hands. Routing the invoice through a law firm is not the answer; here is what the courts actually looked at, and what to settle before the examiner starts.
2026-08-20
The EU CRA Reporting Clock: 24 Hours, 72 Hours, Then a Final Report
Article 14 obliges manufacturers to report actively exploited vulnerabilities and severe incidents on a 24-hour, 72-hour and final-report clock, from 11 September 2026. It is the first CRA obligation to bind, and it reaches products you shipped years ago and have not touched since.
2026-08-19
How a Business Email Compromise Investigation Actually Works
A BEC investigation answers four questions, and whether they are answerable was decided by your logging tier months ago. The artifact list, the wire-recall clock, and the honest reason these investigations end inconclusive.
2026-08-18
How Long Does a Digital Forensics Investigation Take?
The 247-day figure everyone quotes measures dwell time and containment, not the engagement. Here is what each stage of an investigation actually consumes, the four variables that set your calendar, and the deadlines that will not wait for your report.
2026-08-16
DORA Incident Reporting: The 4, 24, and 72 Hour Clocks
Three reports on three clocks, set by Commission Delegated Regulation (EU) 2025/301. The four-hour one is the surprise, because it starts at classification rather than at containment.
2026-08-02
How Much Does Incident Response Cost in 2026?
Retainers run $10K to $100K a year, emergency response hits $1,500 an hour, and the average US breach now costs $11.5 million. Here is the worked math, the cost drivers nobody itemizes, and when a retainer is the wrong buy.
2026-08-02
Breach Notification Deadlines: Every Clock You Are On
A breach puts you on multiple notification clocks at once, and they start on different trigger events: discovery, awareness, materiality determination. Here is the full crosswalk (SEC, HIPAA, GDPR, all 50 states, CIRCIA) and how to build your response to the shortest binding clock.
2026-08-02
CIRCIA Is Coming: 72-Hour Incident Reporting, Explained
CIRCIA's final rule is now targeted at September 2026 on the Unified Agenda, but the 72-hour incident and 24-hour ransom payment clocks are statutory and aren't going anywhere. A readiness guide: covered-entity self-assessment, the reporting decision tree, evidence capture, and the counsel loop.
2026-08-01
What to Do in the First 24 Hours After a Ransomware Attack
Isolate machines without powering them off, call your insurer before any vendor, and let counsel engage forensics. An hour-by-hour war-room timeline covering the two steps generic guides miss: preserving evidence before it expires and making the insurance-panel call first.
2026-07-31
Is an Incident Response Retainer Worth It?
Every firm answering this question sells retainers, including us. Here is the honest version: what a retainer actually buys, the unused-hours clause vendors hope you won't negotiate, a worked $320K first-incident example, and the two situations where on-demand is the smarter call.
2026-07-29
When Should You Call an Outside Incident Response Firm?
Five escalation triggers mean it's time for outside help: domain admin compromise, staged data, touched backups, regulated data, or extortion. And outside counsel, not IT, should engage the firm; that order can't be undone.