rabbhit
Part of Security

Incident Response

A runbook and a real point of contact when something breaks — not a support ticket queue.

What's included

What you get

An incident runbook tailored to your systems and common failure modes

A defined on-call point of contact within your agreed SLA

Escalation paths and communication templates ready to use

Post-incident review after any handled incident

Regular review and update of the runbook as your systems change

Not included (available as add-ons)

Active incident-handling hours (billed separately, hourly)Infrastructure monitoring itself (see Infrastructure Monitoring)Guaranteed prevention of incidents — this is response, not immunity

Investment

From €300/mo

A realistic starting point for the smallest sensible version of this project — not a fixed quote.

What moves it up the range

  • Response SLA (hours vs. same-day)
  • On-call coverage window
  • Number of systems in scope
  • Whether active incident-handling hours are included or billed separately

These are starting prices, not fixed quotes. We scope every project to match your actual budget — the final number depends on what you need built.

How it works

Our process

01

Build the runbook

Written against your actual systems and past incidents, not a generic template.

02

Define escalation

Who gets contacted, in what order, and how — agreed before an incident, not during one.

03

Be reachable

A real point of contact within your agreed SLA when something goes wrong.

04

Review after

Every handled incident gets a post-mortem so the same thing doesn't happen twice.

Questions

Incident Response — frequently asked

Is active incident handling included in the monthly price?

No — the retainer covers readiness (runbook, on-call point of contact, escalation paths). Hands-on-keyboard incident handling is billed hourly on top, typically €175-400/hr depending on urgency.

What's the response SLA?

It depends on the tier — same-day response is the entry point, with faster SLAs and 24/7 coverage available at higher tiers.

Do you also monitor our infrastructure?

Monitoring is a separate but complementary service — many clients run both together so incidents are caught and responded to end to end.

What happens after an incident is resolved?

A post-incident review is included, so the root cause is documented and the runbook is updated to reflect what was learned.

Technologies used

PagerDutyRunbooksSlackStatus Pages

Get started

Ready to get this right?

Book a free 30-minute call. We'll review your situation and give you honest advice — no pitch, no commitment.