CyberGrape – cyber security certification and GRC platform for small business

Platform · Incident Response

Structured command from first alert to lessons learned.

Log and classify incidents, assign a commander, track every action taken and maintain a time-stamped record that satisfies regulators. When it is over, findings flow automatically into Action Hub and the risk register.

Response lifecycle

A structured command process from start to close.

Log and classify

Record the incident, assign severity (critical/high/medium/low), mark reportability under the NDB scheme or Privacy Act, and note whether it has been contained.

Assign a commander

Designate the incident commander who owns the response. All communications, decisions and escalations flow through the commander, with a live record in the platform.

Contain and investigate

Document containment actions, capture forensic evidence, track affected systems and record investigation findings, all time-stamped in an append-only log.

Recover and verify

Log recovery actions and verification steps. The platform tracks each milestone and flags when systems are restored to normal operation.

Close and learn

Complete the post-incident review, link any new risks back to the risk register, and push recovery actions to Action Hub so lessons learned are tracked to completion.

Capabilities

Everything your team needs when it matters most.

AI-drafted response plan

Generate a guided incident response plan with roles, escalation paths, containment procedures, communication requirements and stakeholder contacts. Saved to your policy library.

Tabletop exercises

Schedule structured tabletop exercises via Case Management. Pre-populated 10-step checklists test your team's readiness against specific incident scenarios.

Append-only timeline

Every action, decision and communication is recorded with a timestamp. The immutable log supports NDB scheme reporting, Privacy Act obligations and regulatory review.

Action Hub integration

Incident findings and recovery tasks are pushed directly to Action Hub with the incident linked. Resolve the task, update the incident, from either direction.

Risk register link

When an incident closes, the platform prompts review of related risks. New risks identified during response are added to the register with the incident as evidence.

Severity and reportability

Fields for occurred, detected, acknowledged, contained and resolved timestamps support structured breach notification requirements and insurance reporting.

Regulatory readiness

Notifiable breach reporting built in.

Australian and New Zealand organisations face mandatory breach notification obligations under the Privacy Act and NDB scheme. The platform captures every required timestamp: occurred, detected, acknowledged, contained and resolved, in a format your legal team can use to assess notification obligations without reconstructing the timeline from emails.

  • Structured breach timeline with occurred / detected / acknowledged / contained / resolved timestamps
  • Reportability flag assessed at incident creation and reviewable throughout response
  • Post-incident review documents root cause, lessons learned and remediation steps
  • Incident history preserved as auditable evidence for regulatory enquiry

Action Hub integration

Recovery and post-incident remediation actions go straight to Action Hub. Each task links back to the incident. Closing the task updates the incident record.

See Action Hub

Tabletop exercise scheduling

Schedule structured exercises with pre-populated 10-step checklists via Case Management. Test your team's readiness before you need it in a real event.

Know exactly what to do when something goes wrong.

Build your incident response plan, run a tabletop exercise and be ready before an incident happens.

See Action Hub