Barakat helps organisations prepare for cyber incidents, coordinate urgent response actions, preserve evidence, restore affected systems, and strengthen controls afterwards in a way that supports the Section 53 reporting obligation and the National Cybersecurity Policy 2021 technical measures focus on incident handling, CERT capability, and crisis management.
For organisations that cannot afford confusion during ransomware, phishing compromise, lost devices, website defacement, suspicious admin activity, or data leak events, this engagement turns incident response into a practical operating model with clearer decisions, faster escalation, and stronger recovery discipline.
Section 53 of Sierra Leone's Cyber Security and Crime Act, 2021 requires a person or institution operating a computer system or network to immediately inform the National Computer Security Incidence Response Team of an attack, intrusion, or other disruption liable to hinder the functioning of another computer system or network.
Section 53 also creates offence exposure where an incident of that kind is not reported within 7 days without reasonable excuse. The National Cybersecurity Policy 2021 technical measures pillar reinforces the need for practical incident-handling capability, a CERT ecosystem, and a national crisis-management approach. This engagement focuses on preparation, live response support, evidence preservation, recovery discipline, and post-incident improvement.
Best suited to organisations where downtime is costly, reporting pressure is real, and internal teams need clearer incident leadership, technical response steps, and recovery coordination before the next crisis arrives.
Incident response fails fastest when no one knows who decides, who escalates, or what the first actions should be. We prepare teams before the crisis so the organisation can move with more speed and less confusion when a real incident starts.
During an active incident, delay increases damage. We help teams identify what happened, isolate the affected systems, preserve the evidence, and move quickly through the technical actions needed to contain the event and support reporting, restoration, and executive decisions.
The real value of incident response is not only getting through the event. It is also learning fast enough to stop the same weakness from returning. We help teams review the root cause, tighten the relevant controls, and update the operating model so the next incident is less likely and better contained.
A crisis retainer gives the organisation a defined path to technical support, escalation, and quarterly testing instead of scrambling for help after the event has already started. It is designed for environments where reporting pressure, service continuity, and recovery timing matter.
Deliverables: Incident response plan, on-call support retainer, incident ticket templates, evidence checklist, post-incident review report, and quarterly tabletop exercise.
Urgency: If an organisation would struggle to identify, contain, document, and report a serious cyber incident within the required time pressure, the response gap should be closed before the next disruption tests it in public.
Book Incident Response Retainer