Uncovered critical IT vulnerabilities in a major tech acquisition, securing deal value.
Incident Response and Preparedness
Preparedness is decided before the incident happens. Berigo helps boards and executive teams with response plans, exercises and procedures that meet NIS2 notification requirements.
The outcome of a serious cyber incident is largely determined before it happens. Organisations that have rehearsed, that know who decides what, and whose plans are actually used, respond faster, at lower cost and with less damage to operations, trust and reputation.
Preparedness and incident response are therefore first and foremost a management responsibility, not a technical one. Boards and executive teams must be able to demonstrate that the organisation is prepared, and under NIS2 this becomes a regulatory requirement with short statutory deadlines for notifying the authorities. Berigo helps organisations build preparedness that works in practice: anchored with leadership, aligned with the organisation's risk profile, and documented to the standards required by NIS2, ISO/IEC 27001 and the GDPR.
What we deliver
- Response and contingency plans: developing or revising plans with clear roles, mandates and escalation paths, so decisions can be made quickly when time is short.
- Tabletop exercises for management: scenario-based exercises in which the board and executive team practise real decisions under pressure, followed by a structured debrief.
- NIS2 notification and reporting procedures: establishing routines that meet the requirements for an early warning within 24 hours, an incident notification within 72 hours and a final report to the authorities.
- Alignment with the GDPR: coordinating incident handling with personal data breach notification duties, in cooperation with the privacy function.
- Learning and continuous improvement: post-incident and post-exercise reviews, with findings fed back into the management system in line with ISO/IEC 27001.
Who this service is for
The service is designed for boards, executive teams and security leaders in organisations classified as essential or important entities under NIS2, and for anyone who wants confidence that their plans will hold when tested. It is equally relevant for organisations with no response plans in place and for those whose plans exist on paper but have never been exercised.
How an engagement typically starts
An engagement normally begins with a review of existing plans, roles and notification procedures, assessed against the organisation's risk profile and regulatory obligations. On that basis we propose a prioritised plan, often a combination of updated response plans, a tabletop exercise for the leadership team and the establishment of reporting procedures. The scope is adapted to the organisation's size and maturity.
Contact us for a confidential conversation about how well prepared your organisation is today, and what it would take to close the gap.
Related services
CISO as a Service
Executive-level security expertise without building an in-house department. Berigo provides senior security leadership on par with group CISOs: flexible, scalable and cost-effective.
Get Certified: ISO/IEC 27001
A complete ISO/IEC 27001 implementation programme, from current state to a fully certified ISMS. Built for organisations that want real security, not a paper tiger.
Proven Executive Outcomes
Guided a Nordic critical infrastructure provider from limited visibility to board-approved NIS2 compliance in 6 months.
Is your Board ready for NIS2?
Download the 2026 Executive Checklist for Cyber Liability.
Your address is used to send you the guide, and handled as described in our privacy statement. privacy statement.