Fortellar

Incident Response & Resilience. The work you do before, during, and after the call.

Fortellar runs incident response as one program across three engagements. Plans rehearsed before the incident, senior command running the live response, and recovery designed so the business survives the disruption. One operating model, three modes.

Why This Matters

The first hour is decided long before it starts.

Most organizations meet their incident response program at 2 a.m. on a Tuesday. The plan was written for an audit. The playbook references a tool that was retired last year. The retainer is unsigned. The recovery time on paper has never been measured. The first hour is spent finding the contact list, negotiating engagement letters, and reconstructing the playbook from memory. The decisions that determine the next thirty days get made in that fog.

Fortellar operates incident response as a single program across three engagements. Planning and readiness builds the playbooks, retainers, and rehearsed muscle memory. Breach response runs the live incident with senior command and forensic discipline. Business continuity keeps the business operating through the disruption. The program you run during the incident is the program you built and tested before it.

By the Numbers
$2.66M
average savings on the cost of a breach for organizations with an incident response team that tests its plan regularly.
IBM · Cost of a Data Breach Report 2024
54 days
faster identification and containment for organizations with strong cyber resilience plans.
IBM · Cost of a Data Breach Report 2024
76%
of organizations experienced at least one ransomware attack in the past 12 months.
Veeam · Data Protection Trends Report
Start where you are

Three moments bring people here. Each one has a different first step.

Find the sentence that sounds like your situation, and start there.

The moment
What's actually at risk
Where to start

Something is happening right now

“Files are encrypting and nobody knows who is running this call.”

The first hour sets the cost of the whole incident. Containment done wrong destroys the evidence the investigation and the notification decision depend on.

Start hereBreach Response & Forensics

Senior command in the room, investigation under counsel.

The plan exists on paper and has never been tested

“We have an IR policy. I could not tell you who calls the lawyer.”

An unrehearsed plan fails at the moment it is needed, and an untested plan is a finding auditors and cyber insurers both write up.

Start hereIncident Response Planning & Readiness

Playbooks, rehearsals, and retainers in place before the call.

Recovery commitments have outrun tested capability

“We promised a four-hour RTO. I do not think we have ever measured it.”

Untested recovery times are commitments you cannot keep. The gap shows up during an outage, in front of customers and regulators.

Start hereBusiness Continuity & Disaster Recovery

Impact analysis with the business in the room, then recovery designed to it.

How the practice operates

One framework, three modes, the same operating model.

Incident response, breach forensics, and operational resilience are one program run in three modes. They share retainers, escalation paths, and operating cadence: planning builds the muscle memory a live response runs against, a live response surfaces the gaps that planning and continuity absorb afterward, and continuity work hardens the recovery design a future incident will test. Whichever mode you enter through, the discipline is the same.

Stage 01

Plan & Rehearse

Playbooks written to your environment, retainers signed, communications drafted, tabletops run with executive, legal, and external partner participation. The first hour is rehearsed before it is needed.

Stage 02

Command & Contain

A named senior incident commander in seat within the hour, with defined decision authority. Containment and forensic investigation run concurrently, so nothing the investigation needs is destroyed on the way to stopping the bleeding.

Stage 03

Notify & Communicate

SEC, NYDFS, HIPAA, state AG, and contractual customer clocks tracked with counsel from hour one, staffed independently of the technical response. Customer, regulator, board, and internal messages are pre-drafted and legally reviewed, so the first hour is spent on facts rather than first drafts.

Stage 04

Recover & Harden

Operations restored without skipping the root cause, recovery time validated against the commitments you have made, and after-action reports written for the audiences that need them. Findings fold back into playbooks, tabletops, and continuity work.

What this practice covers

What we plan for, and where we respond.

Obligations & standards

The clocks and standards the program is built to

Playbooks, notification decisions, and recovery commitments are written against the obligations that actually reach your environment, so the response is defensible to every party asking.

SEC cyber disclosureNYDFS Part 500HIPAA Breach NotificationState AG notification lawsGDPR Article 33PCI DSSNIST SP 800-61NIST SP 800-34ISO 22301Cyber insurance conditionsCustomer contractual notice terms
Environments & scenarios

Where the response and recovery reach

Command, forensics, and recovery cover the estate the mid-market actually runs, and the scenarios most likely to land in it.

AWSAzureMicrosoft 365Google WorkspaceOn-premise & hybridSaaS dependenciesIdentity compromiseRansomware & extortionBusiness email compromiseInsider & third-party incidentsVendor outage & supply chain
Expertise This Work Draws On

The expertise behind this practice.

Cybersecurity & Compliance

Incident Command

A named commander with defined decision authority, in seat within the hour. The single source of truth for the executive team while the response runs.

See expertise
Cybersecurity & Compliance

Regulatory Notification & Disclosure

SEC, NYDFS, HIPAA, and state AG clocks tracked with counsel from hour one, staffed independently of the technical response.

See expertise
Technology & Security Operations

Detection Engineering & Incident Triage

The detection-to-response handoff is the first link in the chain. Escalation paths are rehearsed, and evidence is captured in the pipeline the investigation will use.

See expertise
Cloud & Technology Infrastructure

Recovery Architecture

Recovery designed across cloud, on-premise, hybrid, and SaaS dependencies, with the recovery time you commit to measured rather than assumed.

See expertise

The first hour decides the next thirty days.

If the incident is in motion, call the incident line. If it isn't, bring the playbook and the retainer status — thirty minutes with a senior partner will tell you what would actually hold at 2 a.m.