AsteronAsteron

    Incident response for European healthtech

    Prepare before a security incident and coordinate the response when one occurs. Asteron helps healthtech teams establish activation routes, assess impact, coordinate containment and recovery, preserve an evidence trail and organise the technical facts required for management, customers and advisers.

    • Pre-agreed activation and decision routes
    • Coordinated technical and management response
    • Evidence, timeline and actions kept under control
    • Retainer from €2,400 per month

    Retainers from €2,400/month · Active incidents scoped individually

    An incident is a decision problem under time pressure

    A security incident rarely arrives with a complete diagnosis. The first signal may be an unusual administrator login, a customer report, a supplier notification, unexplained data access or disruption in a production service. Teams must decide quickly what is happening, what should be contained and who needs to be involved — often before the full impact is known.

    Asteron Incident Response creates a controlled way to make those decisions. We help establish the facts, coordinate the appropriate internal and external specialists, maintain the incident record and keep technical, business and notification work aligned. The objective is not simply to close a technical ticket, but to reduce impact and leave the company with a defensible account of what happened and how it responded.

    Faster, safer activation

    Roles, contacts and escalation routes are agreed before or at the start of the engagement. The team spends less time deciding who is responsible while the incident continues to develop.

    Coordinated decisions

    Technical containment, service continuity, health-data risk, customer communication and regulatory assessment are managed as connected workstreams rather than separate reactions.

    A reliable incident record

    Facts, decisions, evidence, actions and unresolved questions are logged as the response develops. This supports management review, customer discussions, legal assessment and lessons learned.

    When to activate incident response

    The response process should begin when there is credible evidence of compromise or material impact — or when the available facts are serious enough that waiting for certainty would increase risk.

    Account or access compromise

    Privileged credentials, administrator accounts, authentication systems or access tokens may have been compromised. The immediate questions are what the account could reach, whether access is continuing and which containment action can be taken safely.

    Health-data or tenant-boundary exposure

    Personal or health data may have been accessed, disclosed or altered without authorisation, or isolation between customers may have failed. Technical investigation and data-protection assessment need to proceed together without assuming the legal conclusion in advance.

    Malware, ransomware or service disruption

    Malicious software, destructive activity or unexplained outages may affect production systems or supporting infrastructure. Containment must consider evidence preservation, business continuity and the risk that rushed changes could make recovery or investigation harder.

    Supplier or external notification

    A cloud provider, technology supplier, researcher, hospital customer or other third party may report a potential issue affecting the company. The team must determine whether its own systems, data or customers are actually affected and what further information is required.

    Not every alert becomes a confirmed incident. Initial triage determines the appropriate response level. A company should not wait for complete certainty when the potential consequence is material.

    Retainer or active-response project?

    Asteron supports incident response through two different engagement models. Both are commercially separate; scope, availability and responsibilities are confirmed in the proposal.

    Incident Response Retainer

    from €2,400 / month

    Purpose. Establish a prepared relationship and an agreed route for activating response support before an incident occurs.

    May include

    • Initial readiness and contact review
    • Agreed activation and escalation procedure
    • Severity and decision criteria
    • Alignment with existing response plans
    • Access to response coordination under the contracted terms
    • Templates for incident facts, decisions and actions
    • Periodic review of material changes

    Exact availability windows, response targets, included activities, specialist access and engagement term are confirmed in the proposal. The retainer does not automatically provide 24/7 response.

    Active incident-response project

    Scoped individually

    Purpose. Provide response support for a current or recently identified incident when there is no applicable retainer or the required work falls outside it.

    Scope may depend on

    • Incident type, severity and current status
    • Systems, products and data affected
    • Number of environments and external parties involved
    • Required technical or forensic specialists
    • Business-hours or out-of-hours work
    • Duration and recovery complexity
    • Reporting and stakeholder requirements

    Support for a non-retainer incident depends on availability and the facts known at the time. Asteron confirms the immediate scope, commercial basis and responsibilities before substantive work begins.

    How the response lifecycle works

    1. Activate, establish facts and assess impact

      The response starts by confirming the activation authority, immediate contacts and known facts. Asteron helps establish what triggered the concern, which systems and data may be affected, whether activity is continuing and what decisions cannot wait.

      Unconfirmed assumptions are kept separate from verified facts. The incident record begins immediately so that later decisions can be traced to the information available at the time.

    2. Contain safely and preserve evidence

      Containment aims to limit further impact without unnecessarily destroying evidence or creating avoidable service disruption. Actions may include access restriction, credential changes, isolation, configuration changes or temporary compensating controls, depending on the incident.

      The client’s authorised technical teams or engaged specialists normally implement changes. Relevant logs, system records and other evidence are preserved using an agreed approach before destructive remediation where practical.

    3. Remove the cause and recover operations

      Once the affected scope and likely cause are understood, the response moves towards remediation and controlled recovery. This may involve removing malicious access, correcting vulnerabilities or configurations, restoring systems, validating integrity and increasing monitoring around the affected area.

      Recovery is not complete simply because the service is available again. Remaining exposure, temporary controls, customer impact and follow-up work must remain visible.

    4. Close, report and improve

      The closing phase documents what happened, the likely root cause, affected systems and data, decisions made, remediation completed and actions that remain open. Technical facts are organised for management, customers, insurers and legal or regulatory advisers where required.

      A post-incident review identifies changes to controls, architecture, monitoring, suppliers, procedures and training. Actions move into Vulnerability Management, Compliance Operations or the security roadmap rather than disappearing when the immediate pressure ends.

    Healthtech response requires more than technical containment

    Healthtech incidents can affect several priorities at once: confidentiality of health data, integrity of records, availability of a customer-facing service, hospital integrations and contractual commitments. The technically fastest containment action may not always be the safest operational decision.

    Product, engineering, privacy, compliance, customer and management stakeholders may each hold part of the relevant context. Asteron coordinates the response so that technical work is not separated from service impact, affected data and external obligations.

    Where regulated medical software or clinical workflows may be affected, the company may also need specialist quality, safety or regulatory input. Incident Response does not replace those roles; it creates a controlled structure in which their decisions can be made and documented.

    Notification decisions and deadlines

    Technical response and notification assessment should run in parallel. Waiting until the investigation is complete may leave insufficient time to meet an applicable reporting deadline, while premature or inaccurate notification can create unnecessary confusion.

    For organisations within the relevant scope, NIS2 requires an early warning for a significant incident without undue delay and within 24 hours of awareness, followed by an incident notification within 72 hours and a final report normally within one month. Applicability and significance must be assessed for the specific entity and incident.

    Under GDPR, a controller must notify the competent supervisory authority of a personal-data breach without undue delay and, where feasible, within 72 hours of awareness unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. Processors must notify the controller without undue delay.

    Asteron can organise the technical facts, incident timeline, affected-scope analysis and remediation information required for that assessment. The client’s DPO, legal counsel and responsible management decide whether notification is required, approve its content and submit it to the relevant authority or affected party.

    Responsibilities and boundaries

    Asteron leads

    • Response coordination within the agreed scope
    • Initial fact and impact assessment
    • Incident timeline and decision log
    • Coordination of technical and specialist workstreams
    • Tracking of containment, recovery and follow-up actions
    • Technical input for management and notification assessment
    • Post-incident review and improvement actions

    Your company owns

    • Authority to activate the response
    • Access to systems, logs, personnel and suppliers
    • Internal technical and business owners
    • Approval and implementation of production changes
    • Business-continuity and service decisions
    • Legal, regulatory and customer-notification decisions
    • Risk acceptance and executive approvals
    • Engagement of insurers, law enforcement or external counsel

    Asteron coordinates the response but does not automatically provide 24/7 monitoring, malware forensics, legal advice, public relations, ransom negotiation, law-enforcement liaison or unrestricted production access. Specialist providers may be required depending on the incident and are included only when explicitly scoped.

    Vulnerability Management handles routine findings and remediation from €1,900/month. Incident Response begins when exploitation, unauthorised access or material impact is suspected. vCISO supports ongoing management governance but does not replace contracted response capacity.

    Pricing summary

    Retainer
    Incident Response Retainer — from €2,400/month
    Active incident
    Active incident-response project — scoped individually

    Final scope depends on readiness level, required availability, systems and data covered, incident complexity, specialist involvement and response expectations. Prices exclude VAT where applicable.

    View Security Operations pricing

    Frequently asked questions

    What is an incident response retainer?

    A retainer establishes an agreed relationship, activation route and response scope before an incident occurs. Exact availability, response targets and included work are defined in the contract.

    When should we activate incident response?

    Activate when there is credible evidence of compromise or material impact, or when the potential consequence is serious enough that waiting for certainty would increase risk.

    Does the retainer provide 24/7 response?

    Not automatically. Availability windows, response targets and escalation arrangements depend on the contracted scope and must be confirmed in the proposal.

    Can Asteron help without a retainer?

    Potentially. Active incidents are scoped individually and support depends on availability, incident type, affected systems and required specialists.

    Which incidents can Asteron support?

    Examples include suspected account compromise, unauthorised data access, malware, service disruption, supplier incidents and customer-reported security issues. Exact technical scope is confirmed during activation.

    Who performs containment and recovery?

    The client’s authorised technical teams or separately engaged specialists normally implement production changes. Asteron coordinates decisions, actions, evidence and follow-up within the agreed scope.

    Can Asteron perform forensic investigation?

    Forensic work is included only when explicitly scoped and the required capability is available. Some incidents require a specialist forensic provider, whose role and commercial terms are agreed separately.

    Can Asteron decide whether an incident must be reported?

    Asteron can prepare the technical facts and timeline. The client’s DPO, legal counsel and responsible management determine applicability, approve notifications and submit them to authorities or affected parties.

    What are the NIS2 incident-reporting deadlines?

    For in-scope entities and significant incidents, NIS2 provides for an early warning within 24 hours, an incident notification within 72 hours and normally a final report within one month. Applicability must be assessed for the specific organisation and event.

    How much does Incident Response cost?

    The Incident Response Retainer starts from €2,400 per month. An active incident-response project is scoped individually based on severity, affected systems and data, required specialists, duration and response conditions.

    Official references

    • - NIST SP 800-61 Rev. 3
    • - Directive (EU) 2022/2555, Article 23
    • - GDPR, Articles 33 and 34
    • - ENISA health-sector incident-response resources

    Last reviewed: July 2026

    Prepare the response before the incident defines it

    Review your current plans, contacts, systems and likely incident scenarios with Asteron. We will define whether a retainer is appropriate and document a clear activation and response scope.