macc /
EN FR
Book a meeting
Back to services
06 CRISIS

CSIRT

Prepare, detect, contain, eradicate, recover. Incident response capability available to you — before, during, after.

Frameworks we work with
  • NIST 800-61
  • ENISA IR Good Practice
  • MITRE ATT&CK
  • FIRST PSIRT Services
  • TLP
  • STIX/TAXII

When we step in

  • 01

    You have just discovered a compromise — and you need a clear framework, fast, without panic.

  • 02

    Leadership wants an incident response plan — and nobody knows where to start.

  • 03

    CCB, CERT-EU or a regulator has notified you — and you need to coordinate response + regulatory comms.

Sub-services

  • Custom Incident Response Plan (IRP)
  • Per-scenario playbooks: ransomware, exfiltration, BEC, supply chain
  • DFIR retainer: 24/7 availability on incident
  • Tabletop exercises (realistic crisis simulation)
  • Post-mortem + lessons learned + remediation
  • Coordination with CCB · CERT-EU · ANSSI · sector regulators

Methodology

Duration
IRP setup: 2–4 weeks · Retainer: annual · Response: per incident scope
Deliverable
IRP + playbooks + on-call number + post-incident report
Team
MACC lead consultant + DFIR specialists on call
Book a meeting Reply within 48 working hours