IR plan development
A documented, role-based plan that spells out who does what, who has authority to act, and who to notify — internally and externally — when an incident hits.
Incident response
The worst time to figure out who to call, what to shut down, and who to notify is during an active attack. Incident response is the discipline of preparing for that moment — and executing calmly when it arrives. Gryphon helps Minneapolis and Twin Cities organizations build a real incident response plan, pressure-test it, and get expert help on the line when minutes matter.
Why it matters
When an attack is unfolding, every decision is faster, higher-stakes, and harder to reverse. Teams without a plan lose critical time arguing about who is in charge, powering off the wrong systems, and destroying the evidence they will later need. Teams with a tested plan move calmly through known steps — isolate, assess, communicate, recover — and come out with far less damage and downtime.
Incident response is not one product; it is readiness. It is the plan, the runbooks, the practice, and the expertise on call — so a bad day stays a bad day instead of becoming an existential one.
What it covers
We meet you wherever you are — whether you need a first plan, a tune-up, or help in the middle of an event. Common areas include:
A documented, role-based plan that spells out who does what, who has authority to act, and who to notify — internally and externally — when an incident hits.
Step-by-step playbooks for your most likely events: ransomware, business email compromise, account takeover, and data exposure.
Guided walkthroughs that pressure-test the plan with your leadership and technical teams before a real attacker does.
Hands-on help to isolate affected systems, remove the attacker, and stop the spread while preserving what you need for investigation.
A path back to normal operations that ties your response to your backup and business-continuity plans.
An honest look at what happened and why, turning a bad day into concrete improvements to controls and process.
The response lifecycle
The same lifecycle the best security teams follow, built to fit how your organization actually operates.
Build the plan, define roles and authority, write runbooks, and line up the contacts you will need under pressure.
Recognize an event quickly and size it — what is affected, how urgent, and who needs to be in the room.
Isolate the problem, remove the attacker, and stop further damage without destroying evidence.
Restore systems and data in a controlled order and confirm the environment is clean before returning to normal.
Review the incident, close the gaps it exposed, and strengthen the program for next time.
What you get
A plan that lives in the business, not a template downloaded and forgotten.
Common reasons to get ready now
Frameworks like CMMC and NIST SP 800-171 require a documented, tested incident response capability, and cyber-insurance carriers increasingly expect the same. Beyond the checkbox, the reason is practical: ransomware and business email compromise are now everyday events, and the organizations that recover fastest are the ones that practiced.
A penetration test tells you where you are exposed; incident response prepares you for the day something gets through. Paired with Gryphon's cybersecurity and managed IT services, you get both the plan and the team to execute it.
FAQ
Incident response is how you contain and manage a security event — a ransomware hit, a business email compromise, a breach. Disaster recovery and business continuity (BCDR) is how you restore operations and data afterward. They overlap and should be planned together, but a good backup does not, on its own, tell you how to respond to an active attacker.
Backups help you recover, but they do not answer the questions that decide how bad an incident gets: who has authority to act, what you shut down first, when you involve legal, insurance, and law enforcement, and what you are legally required to disclose. A plan answers those before the pressure is on.
A tabletop is a guided walkthrough of a realistic scenario — say, ransomware discovered on a Monday morning — with your leadership and technical teams. It exposes the gaps in your plan (unclear ownership, missing contacts, untested assumptions) while the stakes are still hypothetical.
Do not power everything off or start deleting — that can destroy evidence and make recovery harder. Isolate affected systems from the network, preserve what you can, and get expert help on the line. If you have cyber insurance, your policy likely requires you to notify them early. A prepared plan makes these first moves automatic.
Increasingly, yes. Many policies now expect a documented incident response plan and periodic testing, and some tie coverage or premiums to it. We can align your plan to what your policy and your compliance obligations require.
Yes. Beyond planning and tabletop exercises, we provide response support to contain, eradicate, and recover — and because Gryphon also runs managed IT and cybersecurity, we can help rebuild and harden the environment afterward.
Next step
Talk with an advisor about your current environment, risk, support model, and business priorities.