IONSEC

Readiness engagement

Cyber Preparedness

Most organizations discover the gaps in their readiness during an incident, when the cost of finding them is highest. Cyber Preparedness front-loads that work: we map what you actually have across IT, cloud, AI, OT and IoT, establish the visibility and access an investigation depends on, and rehearse the response until it is routine rather than improvised.

The problem with finding out later

Readiness is invisible until it is tested. The missing log source, the EDR blind spot on the OT segment, the escalation path that routes to someone who left last year — none of these announce themselves, and all of them surface at the worst possible hour. An engagement that finds them on a quiet Tuesday costs a fraction of one that finds them mid-incident.

How we work

We start from what you actually have rather than what the architecture diagram says. We inventory assets and network paths across IT, OT and IoT, the cloud and SaaS control planes and identity providers behind them, and the AI agents, assistants and LLM integrations now wired into your data, then check whether the telemetry an investigation depends on is being produced and retained, and pressure-test the response plan against your real threat model. Where we find gaps we prioritise them by what they would cost you during an incident, not by generic severity.

Then we rehearse it

A plan nobody has run is a hypothesis. We take your team through tabletop exercises and live simulations built on the techniques we see in our own incident response and research work, so the first time your people execute the plan is not the first time it matters.

How a readiness engagement runs

We measure the coverage you actually have across each asset class, name the shortfall rather than averaging it away, and close it. The gap is the deliverable — an assessment that comes back uniform is an assessment nobody ran.
  • Coverage found
  • Gap
  • Closed

What you get

  • Asset and network visibility map across IT, cloud, AI, OT and IoT
  • Cloud, SaaS and identity provider log coverage and retention gap list
  • Inventory of AI agents, assistants and LLM integrations with the data each can reach and the audit trail each leaves
  • Security maturity assessment scored against your threat model
  • Prioritised remediation roadmap with effort and impact estimates
  • Incident response plan and role-specific playbooks
  • Exercise report with observed gaps and follow-up actions

Who it is for

  • Organizations running converged IT and OT environments
  • Cloud-first and SaaS-heavy estates where the audit trail sits with the provider
  • Teams putting AI agents and LLM integrations next to production data
  • Teams with an IR plan on paper that has never been exercised
  • Security leaders who need an honest baseline before budgeting
  • Companies facing regulatory or customer readiness requirements

Common questions

What is cyber preparedness?

Cyber preparedness is the work done before an incident so that the response to one is fast and effective: mapping assets and network paths, confirming the telemetry an investigation depends on is actually being produced and retained, writing incident response plans and playbooks, pre-authorising access and tooling, and rehearsing all of it. It is distinct from incident response, which is the work done during and after an attack.

What is the difference between cyber preparedness and incident response?

Cyber preparedness happens before an incident and reduces how long the response takes; incident response happens during and after one. Organizations that skip preparedness discover their visibility gaps, missing log sources and stale escalation paths mid-incident, when the cost of finding them is highest.

How long does a preparedness engagement take?

Most run four to eight weeks depending on estate size and how many sites are in scope. Visibility mapping is the longest phase; exercises are typically scheduled after the remediation roadmap is agreed.

Do you need to install agents on our network?

No. We work with the telemetry and tooling you already run wherever possible, and part of the assessment is telling you where that coverage is not enough.

Can you cover OT without disrupting production?

Yes. OT work is passive by default — traffic analysis, configuration review and interviews — and anything active is scoped and scheduled with your engineering team first.

Do you cover cloud and AI environments as well as IT, OT and IoT?

Yes. Preparedness work covers cloud and SaaS control planes, identity providers, and the AI agents, assistants and LLM integrations connected to your data, alongside the IT, OT and IoT estate. In practice that means confirming the audit logs an investigation would need are enabled and retained for long enough, and recording which data each AI integration can reach and what trail it leaves.

What is a tabletop exercise?

A tabletop exercise is a discussion-based rehearsal in which an organization walks through its response to a simulated incident scenario, without touching production systems. It tests whether the incident response plan, the escalation paths and the decision-making actually work under pressure, and surfaces the gaps that only appear when people try to execute the plan.

Talk to the team that does the work

Tell us what you are protecting and we will tell you honestly whether Cyber Preparedness is what you need first.

Or email us directly at[email protected]