---
title: 'Incident readiness'
url: 'https://triplepoint.org.uk/security/incident-response/incident-readiness'
markdown: 'https://triplepoint.org.uk/security/incident-response/incident-readiness.md'
date: '2026-09-28'
description: 'Incident readiness for UK businesses: an incident response plan, tabletop exercises and a retainer, so you know who to call and what to do before an attack happens.'
---

# Incident readiness

The riskMost businesses first think about incident response during an incident. By then, simple questions become hard: who makes decisions, who tells customers, and who your insurance policy lets you call.

A plan that has never been rehearsed tends to fall apart on first contact with a real incident.

 What it does- An incident response plan written for your business: who does what, and in what order
- Tabletop exercises: a rehearsal of a realistic attack with your team, to find the gaps in the plan
- A retainer that gives you guaranteed access to incident responders, with agreed response times
- Pre-paid service units that can go towards planning and exercises as well as emergency response

 Who it's forBusinesses that want to be prepared rather than improvise, particularly those with cyber insurance, customers who ask about incident handling, or ISO 27001 plans, which expect incident management to be planned in advance.

 How we supply itReadiness services are delivered by Sophos's incident response team and arranged through us. We'll help you work out which ones are worth doing first.

 What's under the hood**Sophos Security Services Retainer** — and Sophos's incident readiness services, delivered by the same team that handles emergency response.

 Questions Do we need this if we have MDR Complete?+MDR Complete already includes incident response for threats on protected systems. A plan and a rehearsal are still worth having, because they cover the decisions only your business can make, such as who speaks to customers and when.

 What is a tabletop exercise?+A structured walk-through of a realistic attack with the people who'd be involved, around a table or on a video call. No systems are touched; the point is to find the gaps in the plan before a real incident does.

 Is this only for big companies?+No. A small business's plan can be short. What matters is knowing who to call and who decides, before you need to.

[← Back to Recover from an attack](https://triplepoint.org.uk/security/incident-response)

## Not sure what you need?

Tell us a little about your business and we'll recommend the controls that matter most for it — no obligation, and no jargon.

[Talk to us →](https://triplepoint.org.uk/contact?about=Incident%20readiness) or [see every security area →](https://triplepoint.org.uk/security)

---

## Navigation

- Parent: [Incident response and recovery](https://triplepoint.org.uk/security/incident-response.md)
- Previous: [Emergency incident response](https://triplepoint.org.uk/security/incident-response/emergency-response.md)
