Cyber Security Act 2021 Compliance

Incident Response & Cyber Crisis Management

Barakat helps organisations prepare for cyber incidents, coordinate urgent response actions, preserve evidence, restore affected systems, and strengthen controls afterwards in a way that supports the Section 53 reporting obligation and the National Cybersecurity Policy 2021 technical measures focus on incident handling, CERT capability, and crisis management.

Crisis response, clearly defined

For organisations that cannot afford confusion during ransomware, phishing compromise, lost devices, website defacement, suspicious admin activity, or data leak events, this engagement turns incident response into a practical operating model with clearer decisions, faster escalation, and stronger recovery discipline.

Legal anchor

Section 53 of Sierra Leone's Cyber Security and Crime Act, 2021 requires a person or institution operating a computer system or network to immediately inform the National Computer Security Incidence Response Team of an attack, intrusion, or other disruption liable to hinder the functioning of another computer system or network.

Section 53 also creates offence exposure where an incident of that kind is not reported within 7 days without reasonable excuse. The National Cybersecurity Policy 2021 technical measures pillar reinforces the need for practical incident-handling capability, a CERT ecosystem, and a national crisis-management approach. This engagement focuses on preparation, live response support, evidence preservation, recovery discipline, and post-incident improvement.

Best for

Banks Hospitals NGOs Schools Law Firms Ministries Service Providers

Best suited to organisations where downtime is costly, reporting pressure is real, and internal teams need clearer incident leadership, technical response steps, and recovery coordination before the next crisis arrives.

Deliverables

  • Incident response plan
  • On-call support retainer
  • Incident ticket templates
  • Evidence checklist
  • Post-incident review report
  • Quarterly tabletop exercise

Field work

  • Remote login during active crises
  • On-site support for affected servers and devices where required
  • Backup restoration support
  • Network containment and urgent coordination with internal teams
Preparation

Define the plan before the first hour of an incident becomes chaos

Incident response fails fastest when no one knows who decides, who escalates, or what the first actions should be. We prepare teams before the crisis so the organisation can move with more speed and less confusion when a real incident starts.

Write the incident response plan and define severity levels, call trees, and escalation contacts across technical and management teams
Define first-hour actions for ransomware, phishing compromise, lost laptop, website defacement, insider abuse, suspicious admin login, and data leak scenarios
Prepare ticket templates, evidence checklists, and tabletop exercises so response discipline exists before it is urgently needed
Placeholder illustration for incident response planning and crisis preparation
During Incidents

Contain the event, preserve the evidence, and keep decisions moving

During an active incident, delay increases damage. We help teams identify what happened, isolate the affected systems, preserve the evidence, and move quickly through the technical actions needed to contain the event and support reporting, restoration, and executive decisions.

Help identify what happened, isolate affected devices or servers, and preserve logs and other critical evidence before it is lost
Block malicious domains and IPs, disable compromised accounts, and support backup restoration and network containment where needed
Document the event timeline and key response steps so management, auditors, and regulators can see what was known, when, and how the organisation responded
Placeholder illustration for live cyber incident containment and response
After Incidents

Turn the event into stronger controls instead of repeating the same weakness

The real value of incident response is not only getting through the event. It is also learning fast enough to stop the same weakness from returning. We help teams review the root cause, tighten the relevant controls, and update the operating model so the next incident is less likely and better contained.

Perform root-cause review and identify where technical, procedural, or human weaknesses allowed the event to happen or spread
Recommend hardening improvements and update firewall, DNS, and EDR controls to reflect what the incident exposed
Improve policies, training, and playbooks so lessons learned become operational improvements rather than another report filed away
Placeholder illustration for post-incident review and control improvement
Retainer Support

Keep support on call so the next crisis does not start from zero

A crisis retainer gives the organisation a defined path to technical support, escalation, and quarterly testing instead of scrambling for help after the event has already started. It is designed for environments where reporting pressure, service continuity, and recovery timing matter.

Provide on-call support retainer coverage for urgent incidents and crisis coordination when teams need immediate help
Run quarterly tabletop exercises so leadership and technical teams keep the response plan current and usable
Maintain evidence checklists, incident templates, and response readiness so each new event starts from a stronger baseline

Deliverables: Incident response plan, on-call support retainer, incident ticket templates, evidence checklist, post-incident review report, and quarterly tabletop exercise.

Urgency: If an organisation would struggle to identify, contain, document, and report a serious cyber incident within the required time pressure, the response gap should be closed before the next disruption tests it in public.

Book Incident Response Retainer
Placeholder illustration for cyber crisis retainer and ongoing readiness support

If the first hour of an incident is unclear, the damage will outrun the response

We can prepare the plan, support the live response, preserve the evidence, and help your team recover with enough clarity to meet reporting pressure and reduce repeat exposure.

Request a Compliance Review