Post-Incident Remediation
The incident is contained. The response firm has written its report and gone. The thing that let them in is still exactly where it was.
Incident response ends when the attacker is out and the scope is established. That is the right place for it to end, and a specialist firm is the right thing to buy for it. What it leaves behind is a report describing an architecture that permitted what happened, and an organization with no more capacity to change that architecture than it had the week before.
This is the engagement that closes that gap. It is engineering work with a documentation trail attached, and it is the difference between an incident you survived and an incident you learned from.
What this covers
Read the response report against the system
Every recommendation checked against the running configuration rather than against the architecture document. Response reports are written quickly and under pressure, and they describe the environment as it was understood at the time.
The identity layer first
Most paths run through identity: authentication policy, conditional access, privileged accounts, service principals, token lifetimes, and the federation trust nobody remembers establishing. This is usually the fastest meaningful reduction in exposure available.
The architecture that allowed it
Segmentation, blast radius, what a compromised component can reach, and which trust relationships exist because somebody needed something to work on a deadline. This is the slow half and the half that matters longest.
Detection you would actually notice
Logging and alerting aimed at the path that was used and the ones adjacent to it. Not a monitoring product: the specific signals that would have shortened this by weeks.
The remediation record
Each change tied to the finding it closes, with how it was verified and who accepted it. Written as it happens. Your insurer, your customers and possibly a regulator will read this, and reconstructing it later from memory reads exactly like what it is.
What you consciously accept
Some findings will not be fixed, and that is a legitimate answer when it is a decision. A documented accepted risk is a decision; the same risk undocumented is an oversight, and the difference is entirely visible to whoever reads the file.
Stop and call a specialist incident response firm. Containment, scope and preservation are their work and they are good at it. I am not that, I do not offer it, and hiring me instead would cost you the hours that matter most. Come back afterwards.
What usually brings people here
Containment is done and the response firm has handed over a list of recommendations.
Your cyber insurer wants to know what changed before they renew.
Customers have asked what you have done differently, and the honest answer is currently not much.
The same class of finding appeared again, which means the first remediation closed the instance and not the cause.
How the engagement runs
Fixed-price project work with a defined scope and an end date. A response report scopes itself, which makes this one of the easier engagements to quote honestly rather than estimate vaguely.
Where it turns into an ongoing arrangement is when the answer to "who owns this next time" is still nobody. That is a fractional CISO conversation and a separate one.
This sits inside the fractional CISO side of the practice. If what you need is ongoing ownership rather than a defined piece of work, start there instead.
Questions I get asked first
Are you an incident response firm?
No. If you are in an active incident, stop reading and call a specialist response firm. They contain it, establish scope, and preserve what has to be preserved. This service starts after that, when the responders have written their report and gone, and the thing that let the attacker in is still exactly where it was.
Our response firm gave us a list of recommendations. Is that not enough?
It is the input, not the work. A response report tells you what happened and what should change. Turning that into a changed identity configuration, a changed architecture, and evidence that it changed is a separate engagement, and it is the one that decides whether the same path works twice.
How long does it take?
The identity and access work is usually the fast half and the architecture is the slow half. What sets the calendar is how much of the estate turns out to depend on the thing being fixed, which is rarely known at the start. The first pass produces a sequenced plan with that answered.
Our insurer and our customers are asking what we changed.
That is the real deliverable. Not a list of actions taken, but a record that ties each change back to the finding it closes and shows how it was verified. It is the same standard a regulated remediation has to meet, and it is what makes the answer to that question short.
Written on this
Start with a conversation
Tell me what’s going on. If this is the right piece of work I will scope it. If it is not, I will say what is.
Bring your FDA letter, pen test report, audit deadline, or security questionnaire.
Not ready for a call? Send a message instead.
For companies looking to engage BATO. Vendors, please email.