With the surplus of ransomware attacks consistently increasing, I have unfortunately witnessed another increase – in shoddy and predatory cybersecurity incident response firms with good SEO taking advantage of victims. In some cases this may be opportunistic, and in others simply a side effect of the shortage of senior and principal level incident responders in relation to the number of incidents occurring.
The quality of Incident Response a security company provides is certainly not tied to its size, age, or publicity. I have seen big companies which stretch themselves too thin with new hires and fail to provide quality service. I have also seen small firms which excel and go above and beyond. What I can tell you, is some basic indicators of the quality of service you are getting from an IR company or retainer. Here is a list of things any company worth their salt should be able to provide:
