Tenth Floor Labs

Secure — Incident Response & Security Training

Be ready for a security incident, and train your team to prevent one

We write your incident response plan, run a tabletop exercise with your leaders and stay on call through an incident response retainer. We also train your staff with security awareness sessions and phishing simulations, and teach developers secure coding. It suits any business that handles customer data.

Mon–Sat · 9am–8pm IST
Starting from
₹37.5k
one-time · retainer and training yearly
Timeline
2–3 weeks
typical
After launch
IR retainer ₹3L/yr · training ₹800/user/yr
Maulik Gupta, Founder & Lead Engineer
Maulik Gupta
Founder & Lead Engineer · you'll talk to me

Sound familiar?

"If we got hacked tomorrow, honestly, we wouldn't know who to call first."

  • We've heard about CERT-In's 6-hour reporting rule but have no plan to meet it.
  • Our staff click on anything that looks like an invoice or a courier update.
  • Nobody knows who decides whether to tell customers, the regulator or the press.
  • A customer asked for our incident response plan and we didn't have one.
  • Our developers never had security training, and it shows in code reviews.

Built for

Businesses that handle customer, payment or health dataCompanies subject to CERT-In, DPDP, RBI or SEBI incident reportingTeams preparing for ISO 27001 or SOC 2, which expect an IR plan and trainingOffices where staff handle invoices, payments or customer records dailyEngineering teams wanting practical secure coding trainingCompanies that recently had a phishing or fraud scare

What we do

What's included in Incident Response & Security Training.

01

Incident Response Plan

A short, practical plan: who does what, who to call, how to contain an incident and how to recover, with checklists for common cases.

02

Tabletop Exercise

A 2–3 hour guided drill with your leadership on a realistic scenario like ransomware or a data leak, with a report on what to improve.

03

Incident Response Retainer

Senior responders on call when something goes wrong, with agreed response times, investigation help and recovery guidance.

04

Breach Notification Support

Help deciding what to report and drafting notices for CERT-In (within 6 hours), the Data Protection Board, GDPR authorities and customers.

05

Security Awareness Training & Phishing Simulation

Short, engaging lessons in plain language and regular simulated phishing emails, with simple reports on who needs more help.

06

Secure Coding Training

Hands-on workshops for developers on the OWASP Top 10, using examples in your own stack, run by engineers who ship code.

Who delivers this

Senior security people, not juniors.

Every engagement is led and advised by our security team — a serving CISO with 31+ years in technology, and a partner with security experience across India, Europe and the USA.

Principal Security Advisor

Leads this service
Serving CISO · 31+ years in technology

A serving CISO at a global European telecom and IT services group, with 31+ years of making security a business advantage.

Serving CISO31+ years in technologyMulti-country security governanceBoard-level risk reporting

ISO 27001 · NIST CSF · GDPR · NIS2 · Risk & governance

Security & Compliance Partner

Advises
India · Europe · USA

A hands-on security specialist across India, Europe and the USA, covering cloud, privacy and penetration testing.

3 continentsCloud & privacy securityPublished IoT security researcherAzure security certified

GDPR · DPDP Act · Europrivacy · OWASP · Azure security · GRC

Pricing

Transparent packages. Fixed quotes.

Your final quote is fixed after a 20-minute call — no surprise bills.

IR Plan + Tabletop

₹37.5k
one-time · 2–3 weeks
  • Incident response plan and contact tree
  • Playbooks for ransomware, data leak and account takeover
  • CERT-In, DPDP and GDPR reporting checklists
  • One tabletop exercise with leadership
  • Improvement report after the drill
Get this quote

Awareness & Phishing

₹800
per user per year · min 25 users
  • Security awareness training modules
  • Monthly phishing simulations
  • Simple reports by team and person
  • Extra training for people who click
  • Yearly live session with our security partners
Get this quote
Recommended

IR Retainer

₹3L/yr
per year · on-call response
  • IR plan and yearly tabletop exercise
  • On-call senior responders with agreed response times
  • Incident investigation and containment support
  • Breach notification drafting and support
  • Post-incident review and fixes
  • Unused hours convert to training or reviews
Get this quote

Ongoing costs after launch

No surprises: here's everything you may pay every month, stated upfront.

With us

IR retainer ₹3L/yr · training ₹800/user/yr

See all ongoing plans
Paid to third parties, at cost, no markup

Training platform licences, if resold

  • —Training or phishing platform licences beyond those included, if you choose a specific vendor, are paid directly by you.
  • —Digital forensics needing specialist labs or legal chain of custody is handled with a partner firm and quoted separately.
  • —Legal advice during a breach is provided by your lawyers. We work alongside them.
  • —Cyber insurance is bought separately from your insurer, though we help with their security questions.

Want a quick estimate for your exact project? Try the cost estimator.

Process

From first message to launch.

Clear stages, a live preview link every week, and payments tied to milestones you approve.

  1. Step 01Day 1

    20-min call

    We learn your team, systems and reporting duties. You get a fixed price.

  2. Step 02Weeks 1–2

    Plan & playbooks

    Short interviews, then a draft IR plan and playbooks fitted to your business and regulators.

  3. Step 03Weeks 2–3

    Tabletop & training

    We run the tabletop drill, launch awareness training and send the first phishing simulation.

  4. Step 04Ongoing

    Stay ready

    Regular phishing tests, yearly drills and, with the retainer, responders on call when you need them.

Technology

Tools we trust.

NIST SP 800-61NIST CSF 2.0ISO 27001:2022ISO/IEC 27035CERT-In DirectionsDPDP Act 2023GDPROWASP Top 10MITRE ATT&CKGoPhishKnowBe4

Our promises

Working with us is low-risk.

Fixed quote

A clear, fixed price after a 20-minute call. No surprise bills.

Pay in milestones

Projects: 40% to start, 30% on design approval, 30% at launch.

You own everything

Code, domain, ad accounts, WhatsApp number and data — in your name.

Weekly previews

See real progress on a live link every week, not just status updates.

30 days of free fixes

Anything not working as agreed after launch, we fix at no cost.

Talk to the builder

No account managers. You speak with the engineers doing the work.

FAQ

Questions, answered.

What decides the cost?+

For plans, the number of systems, locations and regulators involved. For training, the number of users. For the retainer, the response times and hours you need each year.

How quickly can we have a plan in place?+

An IR plan and tabletop exercise take 2–3 weeks. Awareness training and the first phishing test can start within a week of signing.

What do the CERT-In rules require?+

CERT-In's Directions of 28 April 2022 require specified cyber incidents to be reported within 6 hours of noticing them, and ICT logs to be kept for 180 days within India. Your plan should make both of these routine.

Will phishing simulations embarrass our staff?+

No. We keep it supportive. Results are used to offer extra training, not to shame anyone, and we agree with you in advance how results are shared.

Will you sign an NDA? Incidents are sensitive.+

Yes. We sign an NDA before any work, and during incidents we share details only with the people you name.

What happens if we have an incident without a retainer?+

Call us and we'll help if we can, but retainer clients come first and get agreed response times. A retainer also means we already know your systems, which saves hours when it matters.

Does training actually work?+

Regular, short training with phishing practice usually lowers click rates over a few months. You'll see your own numbers each month, so you can judge the results yourself.

Let's scope your project.

One message is enough. You'll speak directly with the engineer who builds your system — and get a fixed quote, not a sales pitch.

Call WhatsApp us