Is this for you?
- You are an operator, an MRO or a small manufacturer with a handful of systems the business cannot run without: scheduling, maintenance records, flight data, design files.
- Your cyber insurance application or renewal asks for an incident response plan and evidence of an exercise.
- You have backups but nobody has restored from them, or a plan but nobody has read it.
- You want your crews and technicians to know what to do when the systems are down, not just the IT contractor.
What you get
- One-page incident response plan. Who decides, who calls whom, what is switched off first, how operations continue without the systems, and when to declare an incident over. One page, printed and pinned.
- Playbooks. Ransomware, business email compromise and payment fraud, lost or stolen device, supplier compromise, and loss of a critical system, each with the first hour, the first day and the recovery.
- Reporting obligations map. Who has to be told, by when, and by whom: your aviation authority where airworthiness records or operations are affected, privacy regulators, your insurer, customers under contract, and law enforcement.
- Tabletop exercise. A two-to-three-hour rehearsal with your leadership and operations staff around a realistic scenario, followed by a report of what worked and what to fix.
- Backup and restore check. A short review of whether your backups would actually bring the business back, and how long that would take.
How it runs
- Week 1Interviews and inventoryWhich systems the business runs on, who owns them, how they are backed up, what contracts and insurance say.
- Week 2Plan and playbooksDrafted, reviewed with you, and cut down until they are short enough to be used under stress.
- Week 3Tabletop exerciseRun in person or over video with the people who would actually be in the room; two to three hours.
- Week 3ReportExercise findings, the finished plan and playbooks, and a short list of preparations to complete in the next month.
What I need from you
Two or three hours of interviews, your insurance policy and key supplier contracts, an honest description of your backups, and half a day of your leadership team for the exercise.
Questions I get asked
We have cyber insurance. Do we still need this?
Yes, and increasingly the insurer will insist on it: a written plan and evidence of an exercise are now common conditions of cover. The plan also tells you how to engage the insurer's own response team quickly, which is where the policy earns its premium.
Can you respond to an incident for us?
I am not a 24-hour incident response firm and do not pretend to be. The plan names one, through your insurer or a retainer, and I can advise your leadership during an incident. The engagement is about being ready, which is what most small companies are missing.
Does this cover aircraft operations, or only IT?
Both. The plan deals with continuing to operate safely when the systems are down: dispatch on paper, maintenance release without the records system, and when to stop flying. That is the part generic IT plans leave out.
How often should we repeat the exercise?
Once a year, or after any significant change in systems or people. The second run takes half the time and is where you see the improvement.
Start with a 45-minute readiness call
Tell me what you build or operate. You leave the call with your three most important next steps, whether or not we work together; if this engagement fits, a fixed-scope proposal and quote follow within a few days.
Ask about incident readiness