Navigate
What We Do Company Resources Careers Contact Contact

The breach readiness checklist every operator needs

When an incident hits, you will not rise to the occasion — you will fall to the level of your preparation. Here is how to make sure that level is high.

Security operations monitoring during an incident

Breach readiness is the difference between an incident that is contained in minutes and one that becomes a headline. The work that determines the outcome happens long before the alert fires. Use this checklist to gauge how ready your organisation really is.

Before an incident

  • Asset inventory. Do you have a current map of your systems, data, and — critically — your OT devices? You cannot protect or recover what you have not catalogued.
  • Defined roles. Is it crystal clear who leads the response, who can authorise containment, and who handles communications and legal?
  • Tested backups. Are backups offline, encrypted, and — most importantly — regularly restored in a test? Untested backups are just hope.
  • Monitoring coverage. Is someone watching 24/7/365 across IT and OT, with the authority and tooling to act?
  • An incident response plan. Is it written down, accessible offline, and known by the people who will use it?
If your response plan only exists in one person's head, you do not have a plan — you have a single point of failure.

During an incident

  • Detect & triage. Confirm the scope quickly. What is affected, what is at risk, and is the threat still active?
  • Contain safely. Isolate affected systems — but in OT, coordinate with operations so containment never creates a safety hazard.
  • Preserve evidence. Capture logs and forensic images before you remediate, so you can understand root cause and meet legal obligations.
  • Communicate. Keep leadership, staff, and (where required) regulators and affected parties informed on a deliberate cadence.

After an incident

  • Recover deliberately. Restore from known-good backups and verify systems are clean before returning them to service.
  • Run a blameless post-mortem. Identify what worked, what did not, and what controls would have changed the outcome.
  • Close the gaps. Turn lessons into concrete improvements — and update the plan you will use next time.

The honest test: if a serious incident started right now, could you say — with confidence — who responds, how fast, and with what authority? If not, that is the first gap to close.

How QSI helps you stay ready

Breach readiness is built into everything we do. Our MXDR provides the 24/7/365 monitoring and rapid response that limits impact, our assessments and tabletop exercises pressure-test your plan, and our digital forensics team is available on-demand and on retainer for when you need expert hands fast. Readiness is not a document — it is a capability, and we help you build it.

Is your organisation breach-ready?

Let us pressure-test your plan with an assessment and tabletop exercise before you need it.