Sales: (651) 415-2266 Service: (651) 482-8718

Incident response

The time to plan your breach response is before the breach.

The worst time to figure out who to call, what to shut down, and who to notify is during an active attack. Incident response is the discipline of preparing for that moment — and executing calmly when it arrives. Gryphon helps Minneapolis and Twin Cities organizations build a real incident response plan, pressure-test it, and get expert help on the line when minutes matter.

Why it matters

In an incident, preparation beats improvisation every time.

When an attack is unfolding, every decision is faster, higher-stakes, and harder to reverse. Teams without a plan lose critical time arguing about who is in charge, powering off the wrong systems, and destroying the evidence they will later need. Teams with a tested plan move calmly through known steps — isolate, assess, communicate, recover — and come out with far less damage and downtime.

Incident response is not one product; it is readiness. It is the plan, the runbooks, the practice, and the expertise on call — so a bad day stays a bad day instead of becoming an existential one.

What it covers

From plan to practice to response.

We meet you wherever you are — whether you need a first plan, a tune-up, or help in the middle of an event. Common areas include:

01

IR plan development

A documented, role-based plan that spells out who does what, who has authority to act, and who to notify — internally and externally — when an incident hits.

02

Scenario runbooks

Step-by-step playbooks for your most likely events: ransomware, business email compromise, account takeover, and data exposure.

03

Tabletop exercises

Guided walkthroughs that pressure-test the plan with your leadership and technical teams before a real attacker does.

04

Containment & eradication

Hands-on help to isolate affected systems, remove the attacker, and stop the spread while preserving what you need for investigation.

05

Recovery & BCDR alignment

A path back to normal operations that ties your response to your backup and business-continuity plans.

06

Post-incident review

An honest look at what happened and why, turning a bad day into concrete improvements to controls and process.

The response lifecycle

A calm, repeatable sequence — even under pressure.

The same lifecycle the best security teams follow, built to fit how your organization actually operates.

01

Prepare

Build the plan, define roles and authority, write runbooks, and line up the contacts you will need under pressure.

02

Detect & triage

Recognize an event quickly and size it — what is affected, how urgent, and who needs to be in the room.

03

Contain & eradicate

Isolate the problem, remove the attacker, and stop further damage without destroying evidence.

04

Recover

Restore systems and data in a controlled order and confirm the environment is clean before returning to normal.

05

Learn & improve

Review the incident, close the gaps it exposed, and strengthen the program for next time.

What you get

Readiness you can prove — and use.

A plan that lives in the business, not a template downloaded and forgotten.

  • A documented, role-based incident response plan
  • Runbooks for your most likely scenarios (ransomware, BEC, account compromise)
  • Tabletop exercises that expose gaps before attackers do
  • A defined escalation path and expertise on call
  • A post-incident review that turns a bad day into a stronger program

Common reasons to get ready now

Requirements, insurance, and the simple math of ransomware.

Frameworks like CMMC and NIST SP 800-171 require a documented, tested incident response capability, and cyber-insurance carriers increasingly expect the same. Beyond the checkbox, the reason is practical: ransomware and business email compromise are now everyday events, and the organizations that recover fastest are the ones that practiced.

A penetration test tells you where you are exposed; incident response prepares you for the day something gets through. Paired with Gryphon's cybersecurity and managed IT services, you get both the plan and the team to execute it.

FAQ

Incident response questions, answered.

What is the difference between incident response and disaster recovery (BCDR)?

Incident response is how you contain and manage a security event — a ransomware hit, a business email compromise, a breach. Disaster recovery and business continuity (BCDR) is how you restore operations and data afterward. They overlap and should be planned together, but a good backup does not, on its own, tell you how to respond to an active attacker.

Do we even need an IR plan if we have solid backups?

Backups help you recover, but they do not answer the questions that decide how bad an incident gets: who has authority to act, what you shut down first, when you involve legal, insurance, and law enforcement, and what you are legally required to disclose. A plan answers those before the pressure is on.

What is a tabletop exercise?

A tabletop is a guided walkthrough of a realistic scenario — say, ransomware discovered on a Monday morning — with your leadership and technical teams. It exposes the gaps in your plan (unclear ownership, missing contacts, untested assumptions) while the stakes are still hypothetical.

What should we do first if we think we are breached right now?

Do not power everything off or start deleting — that can destroy evidence and make recovery harder. Isolate affected systems from the network, preserve what you can, and get expert help on the line. If you have cyber insurance, your policy likely requires you to notify them early. A prepared plan makes these first moves automatic.

Does our cyber-insurance policy require this?

Increasingly, yes. Many policies now expect a documented incident response plan and periodic testing, and some tie coverage or premiums to it. We can align your plan to what your policy and your compliance obligations require.

Can you help during an active incident?

Yes. Beyond planning and tabletop exercises, we provide response support to contain, eradicate, and recover — and because Gryphon also runs managed IT and cybersecurity, we can help rebuild and harden the environment afterward.

Next step

Make your next technology decision with better information.

Talk with an advisor about your current environment, risk, support model, and business priorities.

Start a conversation