Risk, Resilience & Recovery — Proposal
Risk, Resilience & Recovery · Confidential

Risk Management,
Resilience & Recovery
Services.

Prepared for [Organization Name] — Lexcom's integrated approach to technology risk management, incident response, business continuity, and disaster recovery.

Prepared for
[Contact Name]
[Title, Organization]
Prepared by
[Account Executive]
Lexcom Systems Group
Date
[Date]
Valid until
[30 days]
Introduction

Four disciplines. One integrated program.

Technology risk management, incident response, business continuity, and disaster recovery are often treated as separate projects — purchased from different vendors, delivered at different times, and never tested together. The result is a patchwork of documentation that looks adequate until something actually goes wrong, at which point the gaps become visible in the worst possible way.

Lexcom delivers these four disciplines as an integrated program — because they are not independent. A risk assessment identifies the scenarios that incident response must address. An incident response plan that has never been tested against a real recovery scenario is not a plan — it is a document. Business continuity and disaster recovery are only meaningful if they have been validated against the actual systems and timelines your organization depends on.

This proposal describes each service area and how Lexcom integrates them into a coherent, tested, and continuously maintained resilience program for [Organization Name].

Risk
Know your exposure before an incident reveals it
Respond
Act decisively when an incident occurs — not frantically
Continue
Keep critical operations running through disruption
Recover
Restore full operations on a known, validated timeline
Service 01
Risk Management

Technology Risk Management

Technology risk management is not about eliminating risk — it is about understanding, prioritizing, and making informed decisions about it. Most organizations significantly underestimate their actual exposure because they have never conducted a structured, documented risk assessment. Without this foundation, security investments are made reactively and defensively, without a clear picture of what is actually most likely to cause harm.

Lexcom's risk management program provides that foundation — a formal assessment aligned to NIST CSF that identifies your actual exposure, ranks it by business impact, and produces a prioritized remediation roadmap your organization can execute. The assessment also produces the documented evidence that cyber insurers and auditors increasingly require.

What we deliver

Formal risk assessmentNIST CSF-aligned assessment of your full technology environment — endpoints, servers, network, cloud, and third parties

Business impact analysisRisk findings ranked by business impact — not just technical severity — so remediation priorities align to what actually matters

Vulnerability scanningContinuous scanning across all managed endpoints and network devices with validated remediation tracking

Remediation roadmapA prioritized, costed action plan — not a 200-page findings report that sits unread in a drawer

Insurer documentation packageEvidence documentation for MFA, EDR, backup testing, and training — formatted for insurance underwriters

Annual re-assessmentStructured annual re-assessment to capture changes in the environment and update the risk register

Risk maturity progression

AreaCurrent (typical)After Lexcom engagement
Risk documentationNone / outdatedFormal, annual, auditable
Vulnerability visibilityPoint-in-time at bestContinuous, tracked
Remediation prioritizationAd-hoc / reactiveBusiness-impact ranked
Insurance readinessGaps undocumentedEvidence package maintained
Frameworks:
NIST CSF 2.0
CIS Controls v8
ISO 27001
ISO 27005
HIPAA Security Rule (healthcare)
ISA/IEC 62443 (OT)
Service 02
Incident Response

Incident Response Planning & Readiness

The first hour of a security incident determines whether it becomes a manageable disruption or a material loss event. Organizations without a tested incident response plan spend that critical hour trying to figure out who is in charge, who to call, and what to do — while the attacker continues operating unimpeded. By the time a response is organized, the damage is often done.

Lexcom builds incident response plans that are specific to your environment, tested through tabletop exercises, and integrated with your regulatory notification obligations — so when an incident occurs, your team acts decisively rather than reactively.

What we deliver

Incident response planDocumented IRP covering detection, containment, eradication, recovery, and post-incident review

Escalation & communication proceduresClear escalation trees and communication templates — internal, executive, regulator, and customer

Tabletop exercisesFacilitated annual tabletop exercises that test your team's actual response — not just the document

Regulatory notification proceduresBreach notification procedures under PIPEDA, HIPAA, provincial privacy legislation, and cyber insurance requirements

Evidence preservation proceduresForensic evidence collection and chain-of-custody protocols for incidents that may involve legal proceedings

Post-incident review processStructured post-incident review to capture lessons learned and update controls and documentation

Incident response lifecycle

Detect

Detection & identification

  • Alert triage from monitoring platform
  • Initial severity classification
  • Incident declaration and notification
Contain

Containment

  • Isolate affected systems
  • Preserve evidence
  • Prevent further spread
Eradicate

Eradication & recovery

  • Remove malware or attacker access
  • Remediate vulnerability exploited
  • Restore from clean backup
Review

Post-incident review

  • Root cause analysis
  • Lessons learned documentation
  • Control and plan updates
Frameworks:
NIST SP 800-61
SANS IR Framework
PIPEDA Breach Notification
HIPAA Breach Notification (healthcare)
Service 03
Business Continuity

Business Continuity Planning

Business continuity planning answers a different question than disaster recovery: not "how do we restore our systems?" but "how do we keep delivering value to our customers and stakeholders while our systems are impaired or unavailable?" The distinction matters because organizations that focus only on system recovery often discover that restored systems cannot support operations because the people, processes, and communication structures needed to use them were never part of the plan.

Lexcom develops business continuity plans that address the full operational picture — identifying critical business functions, establishing manual fallback procedures, defining maximum tolerable downtimes, and testing the plan through exercises before an actual disruption forces the test.

What we deliver

Business impact analysis (BIA)Identification of critical business functions, dependencies, and maximum tolerable downtime for each

BCP documentationComprehensive business continuity plan covering people, processes, technology, and communications

Manual fallback proceduresDocumented workarounds enabling critical operations to continue without primary IT systems

Stakeholder communication plansTemplates and procedures for communicating with customers, suppliers, regulators, and staff during disruption

BCP testing & exercisesAnnual tabletop exercises and walkthrough testing of continuity procedures

Annual plan maintenanceStructured annual review and update cycle — the plan stays current as your organization evolves

Recovery objectives

Recovery Time Objective (RTO)
Max tolerable downtime

The maximum time a business function can be unavailable before the impact becomes unacceptable. BCP defines RTOs for each critical function and ensures recovery plans meet them.

Recovery Point Objective (RPO)
Max tolerable data loss

The maximum amount of data loss your organization can tolerate, expressed as a time period. BCP and DR plans are designed so backup frequency meets RPO requirements for each system.

Frameworks:
ISO 22301
NIST SP 800-34
ISO 27001
NIST CSF (Recover)
Service 04
Disaster Recovery

Disaster Recovery Planning & Validation

Most organizations believe they have disaster recovery because they have backups. Backups are necessary but not sufficient. A disaster recovery program answers a more demanding set of questions: How long does it actually take to restore your most critical systems from backup? Have you confirmed the backup is restorable? Is your recovery procedure documented so that a technician who has never performed a restore can execute it under pressure? Does the restored system support the business processes that depend on it?

Lexcom designs, implements, and validates disaster recovery programs that answer all of these questions before an actual disaster requires the answers. The difference between a theoretical DR plan and a tested one is the difference between a confident response and a chaotic one.

What we deliver

DR plan documentationSystem-by-system recovery procedures covering all critical infrastructure — written to be executable under pressure

Backup architecture designBackup strategy aligned to RPO requirements — including offsite and air-gapped copies for ransomware scenarios

Annual DR testingFull restore test of critical systems from backup — not a theoretical walkthrough — with documented results

RTO validationVerification that actual recovery times meet the RTOs defined in your business continuity plan

Ransomware recovery playbookSpecific recovery procedures for a ransomware scenario — including decision tree for pay/restore and insurer notification

Cloud & hybrid recovery optionsAssessment and implementation of cloud-based DR options to reduce recovery time and infrastructure cost

DR testing schedule

Quarterly

Backup verification

  • Automated backup completion checks
  • Random file restore sampling
  • Offsite copy confirmation
Semi-annual

Tabletop DR exercise

  • Walkthrough of DR procedures with IT and business teams
  • Identification of gaps or outdated steps
  • Plan updates documented
Annual

Full restore test

  • Complete restore of critical systems from backup in isolated environment
  • RTO measurement and validation
  • Results documented and reported to leadership
Frameworks:
ISO 22301
NIST SP 800-34
NIST CSF (Recover)
ISO 27001
SOC 2 (where applicable)
Integrated Program

How the four services work together.

Each service is valuable independently — but the full value of the program comes from integration. A risk assessment that identifies ransomware as your highest-probability threat should directly inform your incident response plan, your business continuity procedures, and the validation criteria for your disaster recovery testing. Most organizations that purchase these services separately end up with four documents that were never designed to work together.

Lexcom designs and maintains all four as a single program — with a consistent risk model, shared documentation standards, and an annual review cycle that updates all four components together when your environment or risk posture changes.

Annual program calendar
Q1
Annual risk assessment · Insurance documentation package · Plan review and updates
Q2
IR tabletop exercise · BCP walkthrough · Semi-annual DR test · Staff security training
Q3
Vulnerability scan cycle · Remediation progress review · Backup architecture review
Q4
Annual full DR restore test · RTO validation · Program review with leadership · Insurance renewal prep
Why Lexcom

What makes us different in risk and resilience.

Risk management, incident response, business continuity, and disaster recovery are disciplines where the difference between doing them and doing them well is enormous — and where the gap only becomes visible when something goes wrong.

Integrated, not siloed. We design all four disciplines as a single program — consistent risk model, shared documentation, annual review cycle that updates everything together.

Tested, not theoretical. We validate recovery procedures through actual testing — not walkthrough exercises that assume everything works as documented.

Business-impact framing. Risk findings are ranked by business impact — not technical severity. Remediation priorities reflect what matters to your organization, not generic scoring.

Insurer and auditor ready. Every deliverable is produced in a format that satisfies cyber insurance underwriters, auditors, and regulators — because that is increasingly a business requirement.

30 years of regulated-industry experience. We have managed real incidents, conducted hundreds of risk assessments, and tested recovery procedures across regulated industries for three decades.

Integrated with managed IT. For Lexcom managed IT clients, risk and resilience programs are integrated with monitoring, patching, and incident response — not managed as a separate workstream.

Next Steps

How to move forward.

This document describes Lexcom's integrated risk, resilience, and recovery program. A separate scope and investment summary, prepared specifically for [Organization Name], outlines the specific engagement recommended, the proposed timeline, and the investment required.

The most common starting point is the risk assessment — it provides the foundation that makes the other three services more effective and immediately surfaces the most important areas to address. Contact your Lexcom account executive to discuss where to begin.

Your account executive
[Name]
[Title] · Lexcom Systems Group
[Email]
Lexcom Systems Group
877‑539‑2663
lexcom.com  ·  lexcom.ca