Digital Forensics Readiness Assessment
Comprehensive evaluation of your organization's ability to collect, preserve, and analyze digital evidence following security incidents. Our assessment examines logging configurations, evidence collection processes, and forensic capabilities to ensure your organization can support investigations, legal proceedings, and regulatory requirements.
In scope
- Log retention configuration
- Evidence collection procedures
- Forensic tool evaluation
- Chain of custody processes
- Digital evidence preservation capabilities
- Memory capture mechanisms
- Network traffic recording
- Legal hold procedures
- Forensic investigation playbooks
- Insider threat investigation capabilities
You receive
- Forensic readiness report
- Logging enhancement recommendations
- Evidence collection framework
- Chain of custody procedures
- Forensic tool recommendations
- Investigation playbook development
- Training recommendations for IT staff
- Legal and regulatory compliance guidance
Tiers
Choose the depth.
Essential Forensic Readiness Review
$32K
Up to 250 employees and 1 site. Reviews log retention on up to 10 critical log sources, evidence collection and chain of custody practice, and current forensic tooling. Readiness report with logging and evidence collection recommendations.
- employees
- 250
- Sites
- 1
- Log retention review for up to 10 critical sources
- Evidence collection and chain of custody process review
- Forensic tool evaluation
- Forensic readiness report
- Logging enhancement recommendations
- — Writing evidence collection procedures
- — Investigation playbooks
- — Memory capture and network recording capability review
- — Legal hold process design
Comprehensive Forensic Readiness Program
$55K
Up to 1,000 employees and up to 3 sites, up to 25 log sources. Adds memory capture and network traffic recording review, and we write the evidence collection framework, chain of custody procedures and 5 investigation playbooks including insider threat.
- employees
- 1000
- Sites
- 3
- Everything in the readiness review
- Memory capture and network recording capability review
- Evidence collection framework and chain of custody procedures
- 5 investigation playbooks (including insider threat)
- Training recommendations for IT staff
- — Custom collection scripts or tooling
- — Logging infrastructure design
- — Legal hold process integration with counsel
- — Performing an actual investigation
Enterprise Forensic Investigation Framework
$85K
Up to 2,500 employees and up to 10 sites, up to 50 log sources. Adds custom evidence collection scripts for your platforms, a target logging architecture for forensic retention, 10 playbooks, and legal hold procedures designed with your counsel.
- employees
- 2500
- Sites
- 10
- Everything in the standard tier
- Custom evidence collection scripts
- Target logging architecture for forensic retention
- 10 investigation playbooks
- Legal hold procedures and regulatory evidence guidance
- — Deploying logging infrastructure or buying tools
- — Incident response or forensic investigation retainer
- — Legal advice (provided by the client's counsel)
- — Organizations above 2,500 employees (scoped separately)
Members: engagement coupons from the CISO Marketplace coupon book apply to services. There is no blanket discount.
What's inside this engagement
Phase by phase.
How a incident response readiness engagement runs, what happens in each phase and what you see. Exact scope, tier and timeline are fixed in your proposal and SOW.
01Current-state review
Plans, playbooks, contacts, logging and insurance requirements reviewed.
You see · Your IR plan and insurance policy.
02Scenario design
Scenarios chosen for your threat profile: ransomware, BEC, insider, cloud compromise.
You see · Participant list and scenario sign-off.
03Exercise / readiness work
Tabletop facilitation or readiness build-out, depending on the service.
You see · Your team's time in the room.
04After-action report
Gaps found, decisions that stalled, and an improvement plan with owners.
You see · A report your board and insurer can read.
Commercials
From first call to final report.
- 01
Scoping call
A practitioner, not a salesperson, walks through targets, constraints and what a good outcome looks like for you.
- 02
Proposal & rules of engagement
A fixed-scope proposal with tier, price and deliverables. Rules of engagement, contacts and out-of-bounds systems are agreed in writing.
- 03
Sign, then start
MSA and SOW are signed electronically and the deposit is paid. Only then does testing begin.
- 04
Execution
Testing runs to the agreed plan. Critical findings are escalated as they are found; you don't wait for the report.
- 05
Report & debrief
An executive summary plus technical findings with evidence, reproduction steps and fixes, walked through with your team.
- 06
Retest
Where the tier includes it, we verify your fixes and reissue the report, so auditors and customers see the issues closed.
Timelines are set per engagement in the SOW.
Related
Incident Response Readiness & Tabletop Exercise
Comprehensive incident response assessment and tabletop exercise designed to validate your organization's IR preparedness through focused policy review, stakeholder coordination validation, and scenario-based team exercises. Our specialized approach combines industry-standard IR maturity assessment with practical tabletop simulations to enhance your incident response capabilities, team coordination, and regulatory compliance readiness.
SOC Maturity & Incident Response Assessment
Comprehensive evaluation of your organization's Security Operations Center (SOC) capabilities and incident response readiness. Our assessment examines detection coverage, response procedures, team capabilities, and technology effectiveness to identify gaps in your security operations and provide a roadmap for enhanced threat detection and response capabilities.
Advanced Threat Hunting Program
Proactive threat hunting service combining machine learning, behavioral analytics, and expert analysis to identify sophisticated threats and establish continuous hunting capabilities.
Research
Latest from the blog

risk-management · Sep 23, 2026
Three Linux Kernel Flaws Hit CISA's KEV List: A CISO Triage Playbook
CISA added three actively exploited Linux kernel CVEs to its KEV catalog with a 72-hour federal remediation window. Here is a step-by-step triage order for CISOs.

operations · Jul 13, 2026
Firmware Is Your Problem Now: Endpoint Trust, Digital Sovereignty, and the Case for an Open-Firmware Fleet
FortiBleed proved the device you trust can be the malware. Regulators are writing firmware into scope, Europe is buying for sovereignty, and the endpoint below the EDR agent remains a black box on most fleets. The CISO case for open-firmware machines — and where NovaCustom's Dasharo-based line fits in a procurement shortlist.

risk-management · Apr 8, 2026
When the Bullets Are Digital: Act-of-War Clauses and the Cyber Insurance Crisis
The geopolitical cyberattack surge is forcing a reckoning between businesses and their insurers — and the fine print may not be on your side. From the Stryker wipeout to Lloyd's rewritten exclusions, here's what every CISO needs to know before the next state-linked attack hits.
Start an engagement