Services

Detection and incident response readiness

SOC design, incident response retainers and exercises, so that the first hours of an incident follow a plan.

Regulators now set clocks for incident reporting. Under NIS2 an early warning is due within 24 hours of becoming aware of a significant incident. Swiss critical infrastructure operators have 24 hours to report a cyberattack to BACS, with fines possible since 1 October 2025. Meeting those deadlines depends on detection, escalation and decision rights that are settled before anything goes wrong.

We design security operations, whether in-house, outsourced or mixed, and define use cases, playbooks and service levels. Our incident response retainers give clients agreed access to responders. Tabletop exercises put executives, IT, legal and communications in the same room with a realistic scenario, and the follow-up lists what to change.

Typical deliverables

  • SOC target operating model and detection use case catalogue
  • Incident response plan with reporting workflows for BSI, BACS and FINMA
  • Incident response retainer with agreed response times and contacts
  • Tabletop exercise for executive and technical teams, with written lessons learned
An industrial control cabinet with network modules

Talk to us about your security priorities

Tell us about your organisation, the regulations that apply to you and what you need to achieve, and we will come back to you to arrange a confidential first call. Email contact@alpwacht.com. If you are dealing with an active incident, say so in the subject line.

contact@alpwacht.com