Named IR lead, defined RTO/RPO targets, tested runbooks. Tier-1 threat intelligence feeds and dark-web monitoring for your domain and exec team. Tabletop exercises every quarter, so when an incident lands, it isn't the first time you've rehearsed it.
Four phases. The first month gets you to a baseline; the program after that keeps you ahead of it.
Stack inventory, control map, threat-model workshop. Two weeks to a documented baseline.
Quick-wins shipped immediately. Pen test runs in parallel. SOC onboarding starts.
24×7 monitoring live. Incident-response retainer active. Weekly hygiene reports.
Quarterly retests, tabletop exercises, compliance evidence rolling forward continuously.
Every capability below is delivered as part of one managed program, scoped to your business, executed by our partner network, and managed by your Katalor Security lead. One contract, one point of contact, one report.
On-call IR engagement with defined SLAs, named lead, and pre-negotiated rates. Avoids the worst case of negotiating an IR contract while actively under attack.
Memory and disk forensics, log-timeline reconstruction, indicator extraction. For incidents that need root-cause clarity, not just containment. Court-admissible chain of custody if required.
Hypothesis-driven hunts in your data lake for adversary behaviors that bypass automated detection. Maps to MITRE ATT&CK tactics; outputs detections that get added to the SOC ruleset.
Scenario-driven exercises with your leadership team: ransomware, data-loss event, insider, supply-chain compromise. Tests the playbook on paper before you test it under fire.
Curated intelligence for your industry and stack. IOCs, TTP changes, dark-web mentions of your brand or executives. Routed into the SIEM, not delivered as a monthly PDF.
Pulse Check doesn't include IR. For that, the Monthly Retainer adds incident response on call with pre-negotiated rates, tested runbooks, and an annual tabletop exercise. Avoids negotiating an IR contract while you're actively under attack.
See small-business plans →For mid-market & enterpriseRetained or Co-managed engagements include a named senior IR lead, defined RTO/RPO, court-admissible forensics if required, and quarterly tabletop exercises. Threat intelligence routed into your SIEM as detections, not delivered as a monthly PDF.
See engagement models →Schedule a 30-minute scope call with Katalor Security. We'll walk your stack, identify the top three exposures, and propose the right MSP tier. No cost.