TEBI-CSIRT · INCIDENT RESPONSE
When crisis strikes, you are not alone.
SENTRA REACT — CSIRT Support, Incident Response
A security incident without a response plan can paralyze your organization for days. SENTRA REACT is your formal incident response device: qualified CSIRT (Computer Security Incident Response Team) engineers, guaranteed SLAs, proven procedures, built with you before the crisis, activated when you need it.
A formal and proven device.
SENTRA REACT rests on three complementary pillars to ensure a structured response to any incident affecting your information systems.
Warranty Repair
Triggering based on previously defined conditions in case of an incident affecting your information systems. Formalized SLA.
Strategic Anticipation
Preparatory actions taken before any incident to support the client in managing cyber threats. Crisis preparedness happens when everything is going well.
Procedural Rigor
Application of adapted and strictly formalized procedures during the occurrence of a critical event. Proven, documented, and regularly tested playbooks.
Setting up the response mechanism.
CSIRT onboarding is a structured phase of approximately 4 to 6 weeks that builds your complete framework before any crisis.
Creation of a single centralized repository containing all critical information: emergency contacts, system inventory, crisis procedures, escalation criteria, and decision trees. This folder is the compass for any intervention.
DELIVERABLE: Complete IR file
Identification and formal integration of all stakeholders: senior management, IT team, business owner, legal team. Each role is documented with its specific responsibilities during an incident.
MAX 3 TECHNICAL INTERLOCUTORS
Integration of the complete technical organization chart, mapping of network scope and systems, and prioritization of critical assets according to their business impact. Essential basis for prioritizing response.
DELIVERABLE: IT Architecture Diagram
Strict alignment with your Information Systems Security Policy (PSSI), IT charters, and existing internal procedures. Any CSIRT intervention respects your governance framework.
Complete integration of the Business Continuity Plan and the Disaster Recovery Plan. Verification of the robustness and consistency of existing resilience solutions.
Identification of critical vulnerabilities detected during onboarding and planning of simulation exercises to test the device before any real-life situation.
INCLUDED: First exercise
Continuous access to the TEBI-CSIRT team.
After onboarding, managed services ensure the operational readiness of your response system.
SUPPORT & SLA
Incident Management 8x5
Incident management service with guaranteed phone support 8 hours a day, 5 days a week. Support from a senior CSIRT engineer from the first alert.
SLA GUARANTEE 8 hours/day · 5 days/week
Intervention provision
8h CSIRT Information / Action
Annual provision of 8 hours of direct intervention by the specialized CSIRT team, usable for any declared incident. Beyond that, billing according to contractual terms.
8 HOURS DIRECT INTERVENTION / YEAR
CONTINUOUS EVALUATION
Nessus Expert Annual Scan
A comprehensive annual scan with Nessus Expert to identify new vulnerabilities and misconfigurations that have appeared in the year. Detailed report with remediation plan.
1 SCAN NESSUS / AN INCLUSION
Dynamic Documentation
Quarterly Update
Strict quarterly update of the intervention file to reflect the evolution of your infrastructure, threats, and internal procedures.
QUARTERLY GUARANTEE REVIEW
Weekly continuous improvement.
4 hours dedicated each week to maintaining and improving your incident response posture.
Documentary Review
Update phishing and ransomware playbooks. Continuous alignment with ISO 27001 and NIS2.
IT / Helpdesk Training
Continuous awareness training for your IT teams and simulation of real escalation scenarios.
Exercises
Realistic crisis management simulation to identify areas for improvement in the system.
Maintenance Lab CSIRT
Testing new tools (EDR, SIEM) and enriching analysis environments (sandbox).
Technology Watch
Analysis of critical vulnerabilities (CVE, CISA, CERT-FR) and inter-client information sharing.
Post-Incident Follow-up
Integration of lessons learned after each incident and verification of recommendation implementation.
PERIODICITY: WEEKLY · DURATION: 4 HOURS DEDICATED PER SESSION
Resilience & Security Posture.
Tangible and measurable benefits for your organization in 12 months.
Enhanced Compliance
Organization better prepared for audit and regulatory framework requirements (ISO, NIS2, DORA)
Advanced Analysis Capability
Operational cyber lab ensuring high-quality forensic and technical analyses
Skill Development
First-line support teams capable of effectively detecting and escalating alerts
Actionable Documentation
Up-to-date procedures, easily actionable in high-intensity crisis situations
Guaranteed crisis intervention
Formalized SLA, identified team, procedures ready. No improvisation when emergencies strike.
Reduced recovery time
Every hour lost in a crisis costs. A prepared device drastically reduces MTTR (Mean Time To Recovery).
Due diligence evidence
Documentation of protective measures for insurers, regulators, and demanding partners.
Aligned with international standards.
SENTRA REACT prepares you for the requirements of major cybersecurity regulatory frameworks.
ISO 27001
Information security management system. Incident management requirements.
NIS2
European Directive on the security of network and information systems. Notification and response obligations.
DORA
Digital Operational Resilience Act. Digital operational resilience for the financial sector.
Tick
Swiss Minimal ICT Standards. Cybersecurity framework for Swiss critical infrastructures.