Incident response audits
Detection-to-Containment Gap Analysis
Focuses on the critical minutes between first signal and meaningful containment across payment, lending, or wallet flows.
HK$28,500 · 10–14 days
Many programmes invent elaborate recovery plans while the first hour remains fuzzy: who acknowledges the alert, who can revoke access, who freezes a channel. This analysis isolates that window.
We sample alert sources, on-call coverage, tooling permissions, and containment authority. Findings stay concrete—missing dual-control, stale contact trees, tools only reachable from an office VPN.
Useful when audits already exist but recent incidents showed slow or inconsistent first response.
Typically included
- Alert and on-call coverage review
- Containment authority checklist
- First-hour timeline model
- Priority fix list for operations