Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
Build your evaluation
no account needed
Match on your requirements
no account needed
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
1. Weight what matters
53 criteria
baselineWhat incident response services are included — retainer-based proactive IR (guaranteed response SLA), reactive breach response, or both — and what is the contractual time-to-first-response for a declared incident?
baselineDescribe the platform/tooling analysts bring to an engagement — forensic collection, malware analysis, and evidence handling — and whether findings integrate with our existing SIEM/EDR or require standing up separate parallel tooling during the incident.
baselineWhat is the analyst team's actual experience and certification profile (GCFA, GREM, OSCP, etc.), and can the customer request specific specializations (ransomware, nation-state, cloud-native incidents) for a given engagement?
baselineDetail post-incident deliverables — root-cause analysis, timeline reconstruction, remediation roadmap — and the typical turnaround from incident closure to final report delivery, with a customer reference.
baselineHow does the retainer model work financially — pre-purchased hours, use-it-or-lose-it versus rollover, and what happens if an incident exceeds the retained hours mid-engagement?
baselineExplain breach-coach/legal-privilege coordination — does the provider have established relationships with breach-coach law firms to help preserve attorney-client privilege over IR findings, and how is this workflow typically initiated?
baselineWhat proactive readiness services are offered outside of active incidents — tabletop exercises, IR plan development/review, compromise assessments — and are these included in a retainer or separately priced?
baselineDetail surge capacity — for a large-scale incident requiring many simultaneous analysts, what is the provider's actual bench depth, and can they demonstrate having surged for a comparably-sized real incident before?
baselinePerform periodic incident response exercises with a deliverable report and debriefing upon completion.
baselineDo you have expertise in security monitoring, threat hunting, incident containment, and response? If so, describe.
baselineBeyond the pre-purchased retainer-hours structure, what is the rate and terms for emergency, non-retainer engagement (a customer with no existing retainer calling during an active breach), and how does response priority differ for retainer versus non-retainer customers?
baselineDoes the IR team provide direct support drafting the actual regulatory breach-notification filings (not just internal technical findings), and has the firm actually filed notifications with real regulators (state AGs, GDPR supervisory authorities) on a customer's behalf before?
baselineCan the provider share a real, detailed case study or reference for a comparable incident (similar industry, similar attack type, similar scale) — not just an aggregate claim of '500+ incidents handled' — that a prospective customer can actually evaluate?
baselineDoes the team provide ransomware-negotiation support specifically as a distinct service, and what is their actual experience and track record with real ransom negotiations (outcome statistics, typical reduction from initial demand)?
baselineIs data recovery/restoration support included as part of the engagement (working with backup systems to actually restore operations), or is the engagement limited to investigation and remediation guidance with recovery left entirely to the customer's own team?
baselineWhat proportion of a typical engagement is remote versus requiring analysts on-site, and what is the actual response-time difference between the two for a geographically distant customer?
baselineIs the firm on the approved incident-response panel for major cyber-insurance carriers, and does the vendor coordinate directly with the customer's insurer to ensure the engagement satisfies policy requirements for coverage?
baselineWhat is the actual bench depth and simultaneous-engagement capacity during a widescale event (e.g., a mass-exploited CVE affecting many customers at once) — can the provider demonstrate they didn't have to deprioritize existing customers during a real past mass-incident event?
baselineMSSP must deliver at least one annual tabletop exercise (scenario themes prioritizing phishing compromise, ransomware, privileged account misuse), with technical teams and leadership participation and a mutually agreed after-action reporting format.
baselineContractor shall perform a technical/procedural review of every incident and high-priority event, including gap identification, Root Cause Analysis (RCA), and posture recommendations to improve detection, prevention and response capabilities.
baselineContractor shall lead enterprise IR readiness via an annual Incident Response Tabletop Exercise (TTX) plan developed with the Privacy team, designing at least 3 distinct high-fidelity scenarios per exercise (incorporating both cybersecurity e.g. ransomware and privacy e.g. PII breach components), and delivering a formal After-Action Report within 10 business days of TTX conclusion.
baselineProvide user behaviour analysis to identify potential internal and external threats; assist the Bank's active participation in cyber drills conducted under CERT-In/IDRBT; coordinate with internal/external contact groups to monitor, analyze and escalate security incidents, developing protect/detect/respond/recover capability for cyber-attacks.
baselineContractor shall serve as system liaison to the Security Controls Assessor (SCA), penetration tester, and for overall system security purposes for both internal and external parties, and compile documentation and supporting materials required for each system assessment, including SSP, Risk Assessment Report, Contingency Plans and Test Results, SORN, FIPS 199, Configuration Management Plan, Cybersecurity and Privacy Incident Response Plan, and Disaster Recovery Plan.
baselineSelected bidder is responsible for product updates/upgrades (including version upgrades) throughout the contract at no additional cost; in the event of a Data Leakage incident, the onsite engineer must prepare and submit a Root Cause Analysis to the financial institution.
baselineDescribe your expected response time to notify us if a cyber-attack or security breach should occur and the actions you would take to mitigate damages.
baselineUpon request, promptly provide copies of information security policies covering data classification, security training/awareness, systems administration/patching/configuration, application development/code review, incident response, disaster recovery/business continuity, data/system backup, and compliance with information security/privacy laws, regulations, or standards.
baselineDefine potential Incident Response / Disaster Response tabletop exercise (TTX) scenarios with the ISO.
baselinePlan and prepare for the TTX to include scripts and presentation materials and review with the ISO; all exercises will use simulated data and scenarios with no live systems impacted.
baselineFacilitate, in person, a 3-4 hour TTX with 20-30 department leaders and IT professionals from the organization.
baselineDocument TTX results within 30 days, to include documented scenarios, evaluation of the port authority's response to scenarios, and documented well-done items and opportunities for improvement of critical and high findings.
baselineEstablish a formal process for incident reporting, escalation, and resolution (Incident Management).
baselineProvide deep-dive incident investigations, including root cause analysis and forensic support, on an as-needed time-and-materials basis under pre-negotiated rates (Incident Response Support and Root Cause Analysis).
baselinePerform real-time investigation and response to alerts, including device isolation, user suspension, and other containment actions within pre-approved parameters (Alert Investigation and Containment).
baselineNotify the organization of any Cybersecurity Incident or Privacy Incident within 1 hour of becoming aware, including description, affected data/systems, individuals impacted, mitigation steps taken/recommended, and a designated incident response contact.
baselineCooperate fully with the organization in investigation of cybersecurity/privacy incidents, including participating in forensic and law enforcement investigations and notification of affected individuals/media/FCC as directed.
baselineProvide a Cyber Incident Response Team (CIRT) that can support the incident response lifecycle with the housing finance agency.
baselineDo you have critical incident response services? If so, describe the different types/tiers of critical incident response services available.
baselineHow is your incident response team integrated into the service delivery teams, particularly the log monitoring team?
baselineWhat degree do you support the Incident Response lifecycle?
baselineProvide Data Breach Risk Assessment and Response Plan Development, and Information Security Risk Assessment.
baselineProvide Incident Response Program Development or Review.
baselineMust provide API support for seamless integration with other security tools (e.g., EDR, firewall management, IAM solutions), and should support integration with existing ticketing and incident management systems.
baselineBidder is required to provide RCA for all Critical and key issues for in-scope applications within 48 hours of the issue being identified/notified, and for significant issues, submit the RCA report within timelines defined by the financial institution.
baselineBidder shall share detailed information security incident report(s) with details of the incident.
baselineSolution should support quick response to ongoing incidents with remote configuration of parameters in servers/desktops, firewalls, AD, IPS, WAF, and network switches/routers, and support automated remediation for commodity threats (e.g. recall malicious mails, block bad IPs, disable bad users in AD).
baselineSecurity Incident and Crisis Management (one-time onboarding service): align the Security Incident management plan with the financial institution's Cyber Crisis Management Plan (CCMP) and Cyber Security Policy, develop a response plan/strategy prioritizing incidents by organizational impact, perform root cause analysis and recommend controls to prevent reoccurrence, and provide on-demand forensic analysis of logs.
baselineContinuous 24x7x365 monitoring is required for all alert severities, not just critical/high after business hours; the MSSP is expected to provide incident coordination, triage, investigation, root cause analysis, and remediation support (within defined authority boundaries) as part of SOC operations, with full forensic investigation/malware analysis available via the professional services block if requested.
baselineProposal must clearly describe authority boundaries for three tiers of response action: (1) non-disruptive playbook actions authorized without prior agency approval, (2) actions requiring standing agency approval (e.g. account disable/reset, endpoint isolation, blocking IOCs at firewall/proxy/email), and (3) actions requiring explicit agency authorization (changes outside Sentinel, destructive actions, external communications) — including an emergency exception process for confirmed active incidents threatening public safety or critical agency services.
baselineReport any breach of vendor system to the university's Chief Information Security Officer in accordance with the applicable state data breach notification law and the European Union General Data Protection Regulation.
baselineWhat is your procedure for handling a data breach and how will the university be notified?
baselineVendor will maintain, update and document an Incident Response Plan (IRP) and notify the university's designated security contact of a Security Incident as soon as reasonably practicable and without undue delay, including a description of the incident, type, location, data involved, and containment/eradication plan.
baselineWhat is the vendor process for communicating a security breach or incident to its customers?
baselineVendor shall provide notice to the agency within eighteen (18) hours of becoming aware of any security breach that has or may negatively impact the agency's data and/or information systems, via both encrypted email to the CISO (using a standardized breach-notification subject line) and a voice call to the IT Service Desk, with defined minimum content for initial, follow-up, and closure reports.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Platform baseline
neutral · staff-reviewed
RFIWhat incident response services are included — retainer-based proactive IR (guaranteed response SLA), reactive breach response, or both — and what is the contractual time-to-first-response for a declared incident?Answer key — what a strong answer shows
Look for a specific, contractually-committed response-time SLA, not a vague 'rapid response' claim — during an active incident, hours matter.
RFPDescribe the platform/tooling analysts bring to an engagement — forensic collection, malware analysis, and evidence handling — and whether findings integrate with our existing SIEM/EDR or require standing up separate parallel tooling during the incident.Answer key — what a strong answer shows
Standing up unfamiliar parallel tooling mid-incident adds friction at the worst time — look for integration with the customer's existing stack, not a bring-your-own-black-box approach.
RFIWhat is the analyst team's actual experience and certification profile (GCFA, GREM, OSCP, etc.), and can the customer request specific specializations (ransomware, nation-state, cloud-native incidents) for a given engagement?Answer key — what a strong answer shows
Look for named certifications and specialization-matching, not a generic 'experienced team' claim — incident types vary enormously in required expertise.
RFPDetail post-incident deliverables — root-cause analysis, timeline reconstruction, remediation roadmap — and the typical turnaround from incident closure to final report delivery, with a customer reference.Answer key — what a strong answer shows
Look for a stated report turnaround time and a real customer reference; a report delivered months later has limited value for driving remediation urgency.
RFIHow does the retainer model work financially — pre-purchased hours, use-it-or-lose-it versus rollover, and what happens if an incident exceeds the retained hours mid-engagement?Answer key — what a strong answer shows
From other buyers
crowdsourced · anonymized
💬
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Retainer financial terms vary widely and matter operationally — look for explicit answers on hour rollover and overage handling, not just the headline retainer price.
RFPExplain breach-coach/legal-privilege coordination — does the provider have established relationships with breach-coach law firms to help preserve attorney-client privilege over IR findings, and how is this workflow typically initiated?Answer key — what a strong answer shows
Privilege preservation is a real legal consideration in breach response; look for described experience working under breach-coach direction, not a purely technical engagement model that ignores this.
RFIWhat proactive readiness services are offered outside of active incidents — tabletop exercises, IR plan development/review, compromise assessments — and are these included in a retainer or separately priced?Answer key — what a strong answer shows
Look for clear pricing separation between proactive readiness work and reactive incident hours, since bundling can obscure what's actually included in a retainer.
RFPDetail surge capacity — for a large-scale incident requiring many simultaneous analysts, what is the provider's actual bench depth, and can they demonstrate having surged for a comparably-sized real incident before?Answer key — what a strong answer shows
Look for a demonstrated real example of surge capacity at scale — bench depth claims are easy to make and hard to verify without a concrete precedent.
RFPPerform periodic incident response exercises with a deliverable report and debriefing upon completion.
RFPDo you have expertise in security monitoring, threat hunting, incident containment, and response? If so, describe.
RFIBeyond the pre-purchased retainer-hours structure, what is the rate and terms for emergency, non-retainer engagement (a customer with no existing retainer calling during an active breach), and how does response priority differ for retainer versus non-retainer customers?Answer key — what a strong answer shows
Ask for specific emergency-engagement rates and priority terms — a customer without a pre-existing retainer needs to know exactly what happens (cost and response speed) if they call for the first time during an active breach.
RFPDoes the IR team provide direct support drafting the actual regulatory breach-notification filings (not just internal technical findings), and has the firm actually filed notifications with real regulators (state AGs, GDPR supervisory authorities) on a customer's behalf before?Answer key — what a strong answer shows
Regulatory notification drafting is a distinct, high-stakes deliverable from technical root-cause analysis — ask for real evidence of this specific capability having been used, not just general breach-response experience.
RFICan the provider share a real, detailed case study or reference for a comparable incident (similar industry, similar attack type, similar scale) — not just an aggregate claim of '500+ incidents handled' — that a prospective customer can actually evaluate?Answer key — what a strong answer shows
A specific, detailed case study (even anonymized) is far more evaluable than an aggregate incident-count claim — press for real comparable-incident detail.
RFPDoes the team provide ransomware-negotiation support specifically as a distinct service, and what is their actual experience and track record with real ransom negotiations (outcome statistics, typical reduction from initial demand)?Answer key — what a strong answer shows
Ransomware negotiation is a distinct, specialized skill from general incident response — ask for concrete outcome statistics from real negotiations, not just confirmation the service exists.
RFIIs data recovery/restoration support included as part of the engagement (working with backup systems to actually restore operations), or is the engagement limited to investigation and remediation guidance with recovery left entirely to the customer's own team?Answer key — what a strong answer shows
Investigation-only engagements leave the customer to handle actual recovery alone — ask explicitly whether hands-on recovery support is included or a separate, additional service.
RFIWhat proportion of a typical engagement is remote versus requiring analysts on-site, and what is the actual response-time difference between the two for a geographically distant customer?Answer key — what a strong answer shows
On-site response for a geographically distant customer can add real hours or days to initial response — ask for a specific breakdown of remote-versus-on-site capability and realistic timing.
RFPIs the firm on the approved incident-response panel for major cyber-insurance carriers, and does the vendor coordinate directly with the customer's insurer to ensure the engagement satisfies policy requirements for coverage?Answer key — what a strong answer shows
Many cyber-insurance policies mandate using a carrier-approved IR panel firm — ask for specific named insurer relationships rather than a generic 'we work with insurance' claim, since using a non-approved firm can jeopardize coverage.
RFIWhat is the actual bench depth and simultaneous-engagement capacity during a widescale event (e.g., a mass-exploited CVE affecting many customers at once) — can the provider demonstrate they didn't have to deprioritize existing customers during a real past mass-incident event?Answer key — what a strong answer shows
A widescale event (like a major CVE actively exploited across many organizations) can genuinely strain a provider's capacity — ask for a real example of how they handled simultaneous demand during a past mass-incident event, not just a steady-state bench-depth claim.
RFPMSSP must deliver at least one annual tabletop exercise (scenario themes prioritizing phishing compromise, ransomware, privileged account misuse), with technical teams and leadership participation and a mutually agreed after-action reporting format.
RFPContractor shall perform a technical/procedural review of every incident and high-priority event, including gap identification, Root Cause Analysis (RCA), and posture recommendations to improve detection, prevention and response capabilities.
RFPContractor shall lead enterprise IR readiness via an annual Incident Response Tabletop Exercise (TTX) plan developed with the Privacy team, designing at least 3 distinct high-fidelity scenarios per exercise (incorporating both cybersecurity e.g. ransomware and privacy e.g. PII breach components), and delivering a formal After-Action Report within 10 business days of TTX conclusion.
RFPProvide user behaviour analysis to identify potential internal and external threats; assist the Bank's active participation in cyber drills conducted under CERT-In/IDRBT; coordinate with internal/external contact groups to monitor, analyze and escalate security incidents, developing protect/detect/respond/recover capability for cyber-attacks.
RFPContractor shall serve as system liaison to the Security Controls Assessor (SCA), penetration tester, and for overall system security purposes for both internal and external parties, and compile documentation and supporting materials required for each system assessment, including SSP, Risk Assessment Report, Contingency Plans and Test Results, SORN, FIPS 199, Configuration Management Plan, Cybersecurity and Privacy Incident Response Plan, and Disaster Recovery Plan.
RFPSelected bidder is responsible for product updates/upgrades (including version upgrades) throughout the contract at no additional cost; in the event of a Data Leakage incident, the onsite engineer must prepare and submit a Root Cause Analysis to the financial institution.
RFPDescribe your expected response time to notify us if a cyber-attack or security breach should occur and the actions you would take to mitigate damages.
RFPUpon request, promptly provide copies of information security policies covering data classification, security training/awareness, systems administration/patching/configuration, application development/code review, incident response, disaster recovery/business continuity, data/system backup, and compliance with information security/privacy laws, regulations, or standards.
RFPDefine potential Incident Response / Disaster Response tabletop exercise (TTX) scenarios with the ISO.
RFPPlan and prepare for the TTX to include scripts and presentation materials and review with the ISO; all exercises will use simulated data and scenarios with no live systems impacted.
RFPFacilitate, in person, a 3-4 hour TTX with 20-30 department leaders and IT professionals from the organization.
RFPDocument TTX results within 30 days, to include documented scenarios, evaluation of the port authority's response to scenarios, and documented well-done items and opportunities for improvement of critical and high findings.
RFPEstablish a formal process for incident reporting, escalation, and resolution (Incident Management).
RFPProvide deep-dive incident investigations, including root cause analysis and forensic support, on an as-needed time-and-materials basis under pre-negotiated rates (Incident Response Support and Root Cause Analysis).
RFPPerform real-time investigation and response to alerts, including device isolation, user suspension, and other containment actions within pre-approved parameters (Alert Investigation and Containment).
RFPNotify the organization of any Cybersecurity Incident or Privacy Incident within 1 hour of becoming aware, including description, affected data/systems, individuals impacted, mitigation steps taken/recommended, and a designated incident response contact.
RFPCooperate fully with the organization in investigation of cybersecurity/privacy incidents, including participating in forensic and law enforcement investigations and notification of affected individuals/media/FCC as directed.
RFPProvide a Cyber Incident Response Team (CIRT) that can support the incident response lifecycle with the housing finance agency.
RFPDo you have critical incident response services? If so, describe the different types/tiers of critical incident response services available.
RFPHow is your incident response team integrated into the service delivery teams, particularly the log monitoring team?
RFPWhat degree do you support the Incident Response lifecycle?
RFPProvide Data Breach Risk Assessment and Response Plan Development, and Information Security Risk Assessment.
RFPProvide Incident Response Program Development or Review.
RFPMust provide API support for seamless integration with other security tools (e.g., EDR, firewall management, IAM solutions), and should support integration with existing ticketing and incident management systems.
RFPBidder is required to provide RCA for all Critical and key issues for in-scope applications within 48 hours of the issue being identified/notified, and for significant issues, submit the RCA report within timelines defined by the financial institution.
RFPBidder shall share detailed information security incident report(s) with details of the incident.
RFPSolution should support quick response to ongoing incidents with remote configuration of parameters in servers/desktops, firewalls, AD, IPS, WAF, and network switches/routers, and support automated remediation for commodity threats (e.g. recall malicious mails, block bad IPs, disable bad users in AD).
RFPSecurity Incident and Crisis Management (one-time onboarding service): align the Security Incident management plan with the financial institution's Cyber Crisis Management Plan (CCMP) and Cyber Security Policy, develop a response plan/strategy prioritizing incidents by organizational impact, perform root cause analysis and recommend controls to prevent reoccurrence, and provide on-demand forensic analysis of logs.
RFPContinuous 24x7x365 monitoring is required for all alert severities, not just critical/high after business hours; the MSSP is expected to provide incident coordination, triage, investigation, root cause analysis, and remediation support (within defined authority boundaries) as part of SOC operations, with full forensic investigation/malware analysis available via the professional services block if requested.
RFPProposal must clearly describe authority boundaries for three tiers of response action: (1) non-disruptive playbook actions authorized without prior agency approval, (2) actions requiring standing agency approval (e.g. account disable/reset, endpoint isolation, blocking IOCs at firewall/proxy/email), and (3) actions requiring explicit agency authorization (changes outside Sentinel, destructive actions, external communications) — including an emergency exception process for confirmed active incidents threatening public safety or critical agency services.
RFPReport any breach of vendor system to the university's Chief Information Security Officer in accordance with the applicable state data breach notification law and the European Union General Data Protection Regulation.
RFPWhat is your procedure for handling a data breach and how will the university be notified?
RFPVendor will maintain, update and document an Incident Response Plan (IRP) and notify the university's designated security contact of a Security Incident as soon as reasonably practicable and without undue delay, including a description of the incident, type, location, data involved, and containment/eradication plan.
RFIWhat is the vendor process for communicating a security breach or incident to its customers?
RFIVendor shall provide notice to the agency within eighteen (18) hours of becoming aware of any security breach that has or may negatively impact the agency's data and/or information systems, via both encrypted email to the CISO (using a standardized breach-notification subject line) and a voice call to the IT Service Desk, with defined minimum content for initial, follow-up, and closure reports.