Incident Response Preparedness: Your response is only as good as the preparation behind it.

Theos Cyber develops tailored Incident Response Plans, Frameworks, and Playbooks for regulated enterprises across APAC. Built around your specific environment, your regulatory obligations, and the threats most likely to target your organisation. The documentation your team picks up when an incident occurs and the structure your board can rely on when they need to make decisions fast.

OVERVIEW

What is Incident Response Preparedness?

Incident Response Preparedness is the structured process of developing the documentation, frameworks, and procedures your organisation needs to respond to a cyber incident effectively. It covers three interconnected deliverables: the Incident Response Plan, the Incident Response Framework, and the scenario-specific Playbooks that operationalise both. 

The difference between an organisation that contains a breach quickly and one that spends days establishing command structures, notification responsibilities, and escalation paths is almost always preparation. Theos builds the documentation that makes the difference, and tests it through tabletop exercises before an incident requires it.

  • The governing document covering scope, roles, decision authority, escalation paths, regulatory notification timelines, and communication protocols.
  • Defines the stages of response and required actions: detection, containment, investigation, eradication, recovery, and post-incident review. Calibrated to your environment and regulatory obligations.
  • Practical guidance for specific incident types. Theos develops playbooks across ransomware, malware, DDoS, data exfiltration, BEC, insider threat, and website defacement.
THE CHALLENGE

Most organisations have an incident response plan. Fewer have one that works under pressure.

Documented incident response plans exist in most regulated enterprises. What the documentation frequently lacks is the specificity, the operational grounding, and the testing that makes it useful when an incident occurs. Generic frameworks applied without customisation leave those questions open until a real incident demands the answers under pressure: who makes the call to isolate a production system, when is the regulator notified, who speaks to the media. 

Theos IR Preparedness builds documentation that answers those questions before they arise under pressure. Every plan is built in close collaboration with your team, reflecting your actual environment, your regulatory obligations, and your decision-making structure.

THEOS APPROACH 

Built from practitioner experience. Tailored to your organisation.

Current State Assessment

Theos begins every IR Preparedness engagement with an assessment of your current documentation: what exists, what is current, and what gaps exist against the regulatory requirements governing your organisation. The assessment identifies where the preparedness programme needs to start and what the priority deliverables are.

Collaborative Development

IR Plans, Frameworks, and Playbooks are developed in close collaboration with your team. Theos practitioners work directly with your security team, legal counsel, communications function, and executive leadership to ensure the documentation reflects how your organisation is actually structured, who the decision-makers are, and what the escalation paths look like in practice.

Regulatory Alignment

Every deliverable is aligned to the regulatory obligations governing your organisation. MAS TRM in Singapore requires documented incident response capability with defined notification timelines. HKMA iCAST in Hong Kong carries equivalent requirements. BNM RMiT in Malaysia and BSP frameworks in the Philippines both require documented response procedures. Theos ensures the documentation satisfies those requirements and is structured to support regulatory submission.

Integration with Tabletop Exercises

IR documentation is most valuable when it has been tested. Theos connects IR Preparedness directly to the Tabletop Exercise programme. Plans and playbooks developed through the preparedness engagement are tested through a facilitated tabletop exercise, with the exercise findings fed back into the documentation to close gaps identified under simulated pressure.

Integration with Incident Response

When an incident occurs, the plan Theos developed is the plan the Theos DFIR team executes. For organisations working with Theos across IR Preparedness, Tabletop Exercises, and Incident Response, there is no gap between the plan and the team delivering it. The practitioners who helped build the playbooks are the practitioners who execute them.

THE SEQUENCE

IR Preparedness, Tabletop Exercise, and Incident Response: how the three services connect.

The three Theos response services form a deliberate sequence. IR Preparedness builds the plan. Tabletop Exercise tests it. Incident Response executes it under real conditions.

IR Preparedness

Builds the plan, framework, and playbooks your team needs before an incident.

Tabletop Exercise

Tests the plan under realistic simulated pressure. Findings close the gaps.

Incident Response

Executes the plan under real conditions. The same team that built it, running it.

BENEFITS 

What Theos IR Preparedness delivers for your organisation.

  • Execution-ready documentation

    Plans and playbooks your team can pick up and use under pressure, on day one of an incident.

  • Regulatory alignment

    Structured to satisfy MAS TRM, HKMA iCAST, BNM RMiT, and BSP notification and documentation requirements.

  • Clear escalation paths

    Every role, every decision, every notification obligation defined before they are needed.

  • Scenario-specific guidance

    Playbooks for the incident types most likely to affect your organisation.

  • Board-ready documentation

    Escalation paths and decision frameworks that give your board clarity on their role.

  • Tested before it is needed

    IR Preparedness connects directly to the Theos Tabletop Exercise programme, so gaps are closed before they matter.

HOW IT WORKS

How a Theos IR Preparedness engagement is delivered.

1

Current State Assessment

Theos reviews your existing incident response documentation, assesses gaps against your regulatory obligations, and agrees the scope and priority of deliverables for the engagement.

2

Stakeholder Workshops

Theos conducts structured workshops with your security team, legal counsel, communications function, and executive leadership. Workshops establish the roles, decision-making authority, escalation paths, and notification obligations that form the foundation of the documentation.

3

Documentation Development

Theos develops the Incident Response Plan, Framework, and Playbooks based on workshop outputs and current state assessment findings. Drafts are reviewed with your team and revised until they accurately reflect how your organisation will respond.

4

Regulatory Review

The completed documentation is reviewed against the specific regulatory requirements governing your organisation. Theos confirms that notification timelines, documentation standards, and escalation requirements meet the expectations of MAS, HKMA, BNM, and BSP where applicable.

5

Tabletop Testing (recommended)

Theos recommends connecting the completed documentation to a tabletop exercise. The exercise tests the plan under simulated pressure, identifies gaps in the documentation, and produces updated versions that reflect what the exercise revealed. Plans that have been tested hold better under real conditions.

6

Handover and Maintenance Guidance

Theos delivers the completed documentation with a handover briefing covering how to maintain it as your environment changes, how frequently it should be reviewed, and what events should trigger a documentation update.

USE CASES

Who Theos IR Preparedness is built for.

Organisations building formal IR documentation for the first time

Building IR documentation from the ground up requires practitioner knowledge of what an incident demands, regulatory expertise to ensure compliance, and collaborative facilitation to produce documentation that reflects how the organisation works. Theos provides all three.

Regulated enterprises preparing for regulatory review

Regulators across APAC examine IR documentation with increasing scrutiny. MAS TRM, HKMA iCAST, BNM RMiT, and BSP frameworks all require documented incident response capability. Theos builds documentation structured to satisfy regulatory review and support the conversations regulators will have with your team.

Organisations following a security incident

A security incident that exposed gaps in the response process is the clearest signal that IR documentation needs to be rebuilt around what the incident revealed. Theos post-incident preparedness engagements rebuild documentation around what the incident revealed: the decision points that were unclear, the escalation paths that broke down, the notification obligations that were uncertain.

Organisations onboarding the IR Retainer

The Theos IR Retainer works best when backed by current IR documentation. For organisations onboarding a retainer for the first time, an IR Preparedness engagement ensures the documentation the Theos DFIR team will use is current, accurate, and reflective of how the organisation is structured. Retainer clients receive priority access to IR Preparedness as part of their proactive service draw-down.

Boards that need clarity on their incident response role

During a significant cyber incident, boards are required to make decisions: when to notify the regulator, when to engage law enforcement, how to communicate with customers and stakeholders. IR Preparedness defines the board’s role, the decision triggers, and the escalation path from the technical response team to executive leadership. Theos connects this directly to the Board Briefings programme, ensuring board members understand their role before they are required to exercise it.

WHY THEOS

Why Theos IR Preparedness.

Built by the team that responds to incidents

Theos IR Preparedness is built by the practitioners who deliver incident response across APAC. The documentation reflects what happens during a real incident: the decisions that need to be made in the first hour, the escalation paths that matter under pressure, and the notification obligations that must be confirmed before an incident occurs.

Tested before it is needed

Theos connects IR Preparedness directly to the Tabletop Exercise programme. Documentation developed through the preparedness engagement is tested through a facilitated exercise, with findings fed back into the plan. Organisations that engage both services have documentation that has been stress-tested before an incident requires it to hold.

Aligned to the regulatory environment your organisation operates in

Theos practitioners understand the incident response documentation requirements of MAS, HKMA, BNM, and BSP. Every deliverable is built to satisfy those requirements and to support the regulatory conversations your organisation will need to have following a significant incident. The documentation is an asset in a regulatory examination. Regulators find what they expect to find.

Connected to the full Theos response programme

IR Preparedness sits at the centre of the Theos response programme. The plan informs the tabletop exercise. The tabletop exercise strengthens the plan. The IR Retainer activates it. The Incident Response team executes it. Board Briefings prepare leadership to own their role within it. For organisations working with Theos across multiple response services, the preparedness engagement is the foundation that makes every other service more effective.

GET PROTECTED TODAY

Security is not a product you buy. It is an outcome you earn.

The first hour of a cyber incident is the most consequential. The decisions your team makes, the escalation paths they follow, and the notifications they send are determined by what your organisation prepared before the incident occurred. Theos builds that preparation.

We deliver outcomes.

Talk to Theos
FAQ

Frequently Asked Questions

What is an Incident Response Plan and why does my organisation need one?

An Incident Response Plan is the governing document that defines how your organisation responds to a cyber incident. It covers roles and responsibilities, decision-making authority, escalation paths, regulatory notification obligations, and communication protocols. Without a current, tested plan, those decisions are made under pressure, for the first time, during the incident itself. Theos builds plans that answer those questions before they arise.

What is the difference between an IR Plan, an IR Framework, and a Playbook?

The Incident Response Plan is the governing document covering who is responsible for what and how decisions are made. The Incident Response Framework defines the stages of response and the actions required at each stage. Playbooks operationalise the framework for specific incident scenarios, providing step-by-step guidance for defined incident types. The three work together: the plan sets the structure, the framework defines the stages, and the playbooks provide the operational detail.

Which incident scenarios do Theos playbooks cover?

Theos develops playbooks for the scenarios most relevant to your organisation and threat landscape. Standard scenarios include ransomware, malware outbreak, DDoS, data exfiltration, business email compromise, insider threat, and website defacement. Scenario selection is agreed during engagement scoping based on your industry, environment, and the threat actors most likely to target your organisation.

How does IR Preparedness connect to the Tabletop Exercise programme?

Theos recommends connecting IR Preparedness directly to a Tabletop Exercise. The exercise tests the completed documentation under simulated pressure, identifies gaps in the plan, and produces an updated version that reflects what the exercise revealed. Organisations that engage both services have IR documentation that has been stress-tested before a real incident requires it to hold.

How does IR Preparedness connect to the IR Retainer?

The IR Retainer is most effective when backed by current IR documentation. For organisations onboarding a retainer, an IR Preparedness engagement ensures the Theos DFIR team is working from documentation that accurately reflects the organisation’s structure, decision-making authority, and escalation paths. Retainer clients receive priority access to IR Preparedness as part of their proactive service draw-down.

How frequently should IR documentation be reviewed and updated?

IR documentation should be reviewed and updated whenever a significant change occurs in your environment, your regulatory obligations, or your organisational structure. As a minimum, Theos recommends an annual review. Following a security incident, a tabletop exercise, or a significant change to key personnel, an earlier review is warranted. Theos provides maintenance guidance as part of every IR Preparedness engagement.

Do regulators require documented incident response plans?

Yes. MAS TRM in Singapore, HKMA iCAST in Hong Kong, BNM RMiT in Malaysia, and BSP frameworks in the Philippines all carry requirements around documented incident response capability. The specific requirements vary by framework and by the regulatory classification of your organisation. Theos builds documentation structured to satisfy those requirements and to support regulatory examination.

LET US HELP YOU!

LET US HELP YOU!