- Job title
- Project manager
- Sector
- Cosmetics
- Organization type
- regional distributor
- Joined
- Aug 2024
- Message
- 77
We're a 15-person software and technical consulting company. We're currently renewing a 350,000 TL annual support contract with a corporate client. But this year, due to audit requirements, their corporate procurement department added a clause demanding a "written cyber incident response procedure" and wants a signed document.
We don't have a full-time info-sec specialist, a sysadmin, or an OHS expert on staff. A freelance IT guy comes in once a week to handle the office server and network stuff. The templates I found online are clearly designed for massive enterprise holdings with hundreds of employees; they talk about digital forensics labs, dedicated call centers, and none of it fits us.
What is the minimum required content for this kind of document for a business of our size? Can we draft something that reflects our actual operations and get it approved by the client without paying for expensive external consulting?