EY helps clients create long-term value for all stakeholders. Enabled by data and technology, our services and solutions provide trust through assurance and help clients transform, grow and operate.
At EY, our purpose is building a better working world. The insights and services we provide help to create long-term value for clients, people and society, and to build trust in the capital markets.
The Cyber Incident Resilience and Response (CIRR) Solution provides cross-functional support to organizations before, during and after a cyber incident. EY teams combine global expertise, embedded support and scalable services to strengthen resilience and accelerate transformation.
Cyber incidents are rarely just technical — they’re fast-moving, high-pressure events that demand coordinated response across business, technology, communications and risk. With attacks rising across sectors, it’s no longer a question of if, but when. While the threat is clear, the response is not so simple — many organizations struggle with fragmented responses, unclear roles and limited access to the right knowledge when it matters most.
Solution features and functionality
The EY approach is different. We bring together a cross-functional team of cyber, forensics, crisis communications, privacy and transformation professionals, backed by global experience and local insight. Whether it’s managing stakeholders, uncovering root cause, coordinating breach notification or remediating vulnerabilities, our teams operate as one, with a single point of contact and a shared mission: to help clients respond decisively and recover stronger. Our alliance partnerships further improve our ability to deploy the right tools and intelligence when it matters most.
EY teams provide a number of services to help you prepare for an incident including a full suite of capability and current state assessment options. This includes a wide variety of exercise and testing options from table to highly experiential and purple teaming options. EY can also wrap these services into a Cyber Incident Response Retainer, which is designed to embed our understanding of your organization before a crisis occurs — building familiarity with your systems, stakeholders and ways of working. This proactive integration enables faster, more effective response when an incident strikes and allows us to work alongside your teams to uplift resilience and strengthen incident response maturity. The retainer operates on a flexible, pre-bought hour model, allowing unused hours to be traded for simulations, testing or capability uplift, enabling continuous improvement. The better we know your business, the better we can protect it.
When a cyber incident strikes, we can mobilize a cross-functional team of responders, forensic analysts and crisis coordinators to act fast. Our retainer model ensures we’re already embedded in your environment, familiar with your systems, stakeholders and ways of working so we can respond decisively. Whether on-site or remote, our teams provide hands-on support across containment, investigation and recovery. We orchestrate response efforts, deliver threat intelligence and manage breach notification and crisis communications. Our alliance partnerships enhance our ability to deploy advanced tooling and threat hunting capabilities. The better we know your business, the faster and more effectively we can help protect it.
Includes:
Incident response management and orchestration
Digital forensics and compromise assessment
Personally identifiable information (PII) discovery and breach notification
Threat intelligence and containment
Crisis communications and stakeholder coordination
Vulnerability remediation
EY teams support clients through the long tail of recovery, helping them stabilize operations, restore trust and build back stronger. Our teams guide technical remediation and resilience uplift, informed by deep knowledge of your environment gained through the retainer and incident response. We help clients navigate the aftermath of an incident with structured debriefs, shadow investigations and transformation planning. Whether it’s vulnerability remediation, insurance support or managed services, we tailor recovery to your business priorities.
Includes:
Remediation and recovery services
Shadow investigations and reporting
Insurance support or loss adjustment
Cyber program transformation
Managed services
Why EY
The EY approach is scalable and adaptable, supporting organizations of all sizes. CIRR leverages global insight and experience to strengthen local response capabilities and is designed to enhance IR maturity and deliver value at every stage of a cyber incident.
EY Alliance and Ecosystem Relationships
The CIRR solution is enhanced by strategic alliances with CrowdStrike, Microsoft, SAP and ServiceNow. Providing clients with access to leading threat intelligence, automation and remediation technologies. These partnerships strengthen our ability to deliver fast, effective and scalable support across the incident lifecycle.
The 2025 EY Global Cybersecurity Leadership Insights Study found that CISOs account for US$36m of each strategic initiative they are involved in. Read more.