IR-1

by Blackpanda

Asia’s Leading Cyber Emergency Response Solution

Top-tier incident response, proactive readiness intelligence, and seamless access to cyber insurance—all in one platform. Delivered at less than 10% of the cost of traditional IR.

Essential Cyber Emergency Response Services. 
Accessible to Every Business.

Proud IR-1 partner to:

Not just another IR firm.

Most Incident Response companies bill by the hour, regardless of outcome, leaving you with all the risk. We're different.
As a Lloyd's of London insurance underwriting firm with our own tech-enabled elite IR team, we don't just respond to incidents—we share the risk. We're so confident in our capabilities that we stake capital on the results.

CYBER

INSURANCE

Lloyd’s of London
overholder

  • A+ rated financial institution
  • 335 years of Lloyd's institutional credibility
  • Asia's first and only pure cyber insurance provider

ELITE

IR TEAM

Asia’s Premier Cyber Emergency
First Responders

  • Full-time Level 3 specialists across Asia
  • Over 100 incidents managed in Asia
  • Hyper-specialized exclusively in IR

TECH

-ENABLED

Designed by Responders
for Responders

  • Attack Surface Readiness (ASR) tech for fast response
  • Dark web intelligence for holistic investigations
  • Proprietary attack data from real-world cases

When you're under attack, your loss is our loss—and that’s why

we fight harder.

Customer Reviews

When our customers and clients are happy, we are.

Billy Naveed

Founder & Chairman, Young Founders School

When our team started receiving phishing emails asking for Amazon vouchers, I was confused. Why would anyone target a non-profit? We don’t have much money. Then I realised it wasn’t about money. It was about trust. The trust between our team and our advisors. That’s what they were trying to exploit.

My next thought was panic. What if the hackers were already inside? We hold sensitive data on our students. We run cybersecurity training and we stay alert, but any organisation can be vulnerable. We checked the basics.

Then we called Blackpanda. They responded immediately. Calm, clear, and thorough. They started with the essentials, like checking the doors and windows were locked, then moved into a full investigation. It took time, but it was comprehensive. By the end, we had clarity. We knew we were safe. And we could give that assurance to our advisors, our team, and our donors.

For a non-profit like ours, that kind of support felt out of reach. But Blackpanda didn’t hesitate. They were there when we needed them. It wasn’t just a service. It was a lifeline.

We’re forever grateful."

Deepak Sarda

CTO, Endowus

At Endowus, security is our top priority, and incident response is a key element of our cybersecurity strategy. In today's rapidly evolving threat landscape, it is critical to have the right partners in place. Blackpanda's Incident Response team has demonstrated outstanding expertise, quickly understanding the technical scope and delivering actionable insights. When we needed assistance, their timely response was invaluable—fast, reliable, and precisely what we needed during high-pressure situations. It's reassuring to have a partner we can count on in critical moments. More recently, we've also onboarded to IR-1 as part of our Cyber Insurance coverage. This has given us an added layer of assurance and peace of mind at great value. Together, these services form a powerful combination that makes Blackpanda a trusted partner in our cybersecurity strategy.

-

CISO, OSL

As the Chief Information Security Officer at OSL, maintaining a proactive cybersecurity posture is critical to protecting our clients’ digital assets. Blackpanda’s threat hunting service has been a game-changer for us, providing deep, real-time visibility into potential vulnerabilities and emerging threats. Their expert team operates with precision and efficiency, identifying risks before they can escalate and offering actionable recommendations to enhance our defenses. The partnership has greatly strengthened our overall cybersecurity framework, and we highly recommend Blackpanda to any organization committed to staying ahead in the ever-evolving threat landscape.

Keith Kwok

Senior IT Manager, Ka Shui

The Blackpanda cybersecurity team delivered an exceptional health check compromise assessment, demonstrating deep expertise and professionalism. Their thorough analysis provided us with clear insights and actionable recommendations, significantly enhancing our security posture. We highly value their commitment to excellence and would confidently recommend their services to any organization seeking robust cyber protection.

We’re a regional manufacturing company with facilities across Asia and North America, providing critical components to industrial clients.

The Complete
Post-Attack
Recovery Ecosystem

As a Lloyd’s coverholder with an embedded IR team, we’re able to deliver the full post-breach lifecycle that covers you at every stage of post-attack recovery.

RESPONSE

Assured Incident Response

When attacked, you get 24×7 emergency dispatch from our elite local responders. One response included per year means no dipping into consulting hours — and no more hourly billing in a crisis.

READINESS

Readiness Consulting

We codify playbooks, drill with TTX and purple teaming, and hunt threats to act quickly. Our Attack Surface Readiness (ASR) gathers the context we need to contain threats faster.

RECOVERY
Up to $10M USD in Insurance Coverage

We’re so confident in our ability to contain and limit damage quickly that we also offer up to 20% off your premium for all IR-1 customers. With response and evidence handled in-house, you pay zero IR deductible and claims move much faster than traditional insurance companies.

IR-1 Assured Incident Response

The foundation of our model is IR-1.

Before anything else, you need experts who show up fast. IR-1 is fixed-cost incident response assurance that guarantees 24×7 dispatch with a 4-hour SLA to rapidly contain the threat.

First limit the damage, then premiums drop and claims move faster.

24/7 Emergency 
Dispatch Centre

Your ‘Big Red Button’ for cyber attacks. Activate Blackpanda’s emergency response team instantly through the IR-1 Portal for rapid response within 4 hours – when you need it most.

Elite Local Responders

Your own special forces unit for cyber emergencies. Blackpanda cyber security specialists are the best in their field, stationed full-time across key Asian cities, ensuring you receive the highest quality support possible.

Innovative Pricing Model

A smarter replacement for overpriced IR retainers. Our unique mix of readiness intelligence and insurtech data keeps risk low, so you get elite IR for a fraction of the usual cost.

+ Included: 


IR Readiness Tech

Attack Surface Readiness (ASR) for upfront environmental intelligence, Dark Web monitoring for early threat discovery, and a 60-day SentinelOne enterprise EDR trial that enables rapid detection, real-time blocking, and faster mobilisation by our response team.

+ Unlocks:

Up to 20% off Insurance Premium

Attack Surface Readiness (ASR) for upfront environmental intelligence, Dark Web monitoring for early threat discovery, and a 60-day SentinelOne enterprise EDR trial that enables rapid detection, real-time blocking, and faster mobilisation by our response team.

Why We Created IR-1

We didn’t invent incident response. We just made it more accessible.

Every city has a fire department. Every business needs IR-1.

We’ve built public systems for fires and other emergencies. But when a cyber attack hits your business, there’s no 911 to call — just panic, asking Google, and a more than five-figure bill.

That’s why we created IR-1: our fixed-cost cyber emergency response subscription, activated at the click of a button. No billable hours, no delay. All for less than 10% of a traditional IR retainer.

Every city has a fire department. Every business needs IR-1.

We’ve built public systems for fires and other emergencies. But when a cyber attack hits your business, there’s no 911 to call — just panic, asking Google, and a more than five-figure bill.

That’s why we created IR-1: our fixed-cost cyber emergency response subscription, activated at the click of a button. No billable hours, no delay. All for less than 10% of a traditional IR retainer.

We didn’t just change the price—we changed the model.

IR-1 is what we call assurance: a new category of risk-backed response.By combining deep incident response expertise with our own Lloyd’s of London insurance entity, we underwrite the cost of a breach up front—so any business can access top-tier emergency response for the price of a monthly SaaS subscription.

Think of IR-1 like your local cyber fire department. Your digital AAA. It works because it’s backed by collective coverage, modeled risk, and intelligent allocation of resources. That’s how we make expert emergency response universally available—without relying on crisis pricing.

Because you’re already covered, we only win when you stay resilient.

Traditional IR firms make money when you’re breached. We don’t. That’s why IR-1 includes ongoing ASR readiness insights to uncover exposures early and keep you ahead of risk.

That’s good for your business — and ours.

IR-X
Readiness
Consulting

All the Benefits of IR-1 + Flexible Consulting Hours

We organize work into Plan & Prepare, Test & Improve, and Detect & Uncover so our responders can move immediately (and more effectively) when needed.

Plan & Prepare

Board-ready response plans and playbooks; roles, comms, and decision paths so the right people act in the first minutes.

  • IR Plans/Playbooks Development & Review

Test & Improve

Pressure-test your team and workflows; close gaps following an incident.

  • Tabletop Exercises (TTX) 
  • Purple Teaming Exercises

Detect & Uncover

Proactively find hidden compromise and insider risk before they become incidents.

  • Compromise Assessments
  • Threat Hunting Services

Response

Board-ready response plans and playbooks; roles, comms, and decision paths so the right people act in the first minutes.

  • IR Plans/Playbooks Development & Review

IR-1 Insured

From Response to Recovery

Lloyd’s-backed cyber insurance built for IR-1 customers—with coverage up to USD 10M.We’re so confident in our ability to contain and limit damage quickly that we offer up to 20% off your premium for IR-1 customers. With response and evidence handled in-house, you pay zero IR deductible, and claims move much faster than traditional insurance companies.

Financial Loss & Operational Recovery

Covers lost profits and the costs of getting back up and running. From business interruption losses to data recovery costs—quickly restoring you to your pre-incident state.

Legal &
Compliance Support

Covers third-party liability claims and relevant legal costs to minimize the risk of regulatory fines. Includes top-shelf legal counsel and compliance guidance following a breach.

Crisis &
Reputation Management

Covers expert crisis management and communications following an attack. Quickly and effectively manage the narrative, restore public trust, and maintain customer confidence.

“At Endowus, security is our top priority, and incident response is a key element of our cybersecurity strategy. In today's rapidly evolving threat landscape, it is critical to have the right partners in place. Blackpanda's Incident Response team has demonstrated outstanding expertise, quickly understanding the technical scope and delivering actionable insights. When we needed assistance, their timely response was invaluable—fast, reliable, and precisely what we needed during high-pressure situations. It's reassuring to have a partner we can count on in critical moments. More recently, we've also onboarded to IR-1 as part of our Cyber Insurance coverage. This has given us an added layer of assurance and peace of mind at great value. Together, these services form a powerful combination that makes Blackpanda a trusted partner in our cybersecurity strategy.”
- Deepak Sarda, CTO, Endowus

Blackpanda is a Lloyd’s of London–accredited insurance coverholder and Asia’s leading local cyber incident response firm, delivering end-to-end digital emergency support across the region.

We are pioneering the A2I (Assurance to Insurance) model — uniting detection, response, and insurance into a seamless pathway that accelerates recovery and strengthens resilience.

Through expert consulting, response assurance subscriptions, and discounted cyber insurance, we help organisations prepare, respond, and recover from cyber attacks — all delivered by local specialists working in concert.

Our mission is clear: to bring complete cyber peace of mind to every organisation in Asia, from the first moment of breach through full recovery and beyond.

Our Mission:

To provide digital emergency response to everyone.

Our Vision:

Accessing cyber incident response is as universally accessible as dialing 9-1-1.

IR-1 FAQs

If you cannot find the answer to your question, contact our Sales team and they’ll be happy to talk to you.

Who is IR-1 for?

IR-1 is a one-stop-shop for everything a business needs to minimize financial impact after a cyber attack. It is for any business that is seeking an affordable, integrated, and comprehensive cyber emergency response, preparation, and financial recovery IR-1 addresses the three core aspects of post-attack cybersecurity solutions—Response, Recon, and Recovery—ensuring businesses are prepared with exactly what they need during and after a cyber incident.

For those requiring more tailored incident response preparation services, our flexible IR-X offering includes all the features of IR-1 plus customizable add-ons, such as multiple response credits and hours-based consulting service packages, like table-top exercises, purple-teaming, and threat-hunting, to name a few.

What is included in IR-1?

IR-1 is an annual subscription that includes:

  • Expert Incident Response: One incident response credit can be activated in case of a suspected attack, providing comprehensive incident response services, including investigation, containment, and neutralization of the threat.
    Learn More: What is Incident Response?
  • Continuous Vulnerability Scans: Weekly Attack Surface Readiness (ASR) scans and Dark Web monitoring to identify and alert you and your customers to critical security gaps.
  • Automated Access to Cyber Insurance: Integrated access through the Blackpanda Platform to support your financial recovery, with comprehensive coverage and instant, one-click insurance estimates. The comprehensive cyber insurance product can cover up to $10M USD in claims and is backed by Lloyd’s of London and directly underwritten by Blackpanda Underwriting with optimized pricing provided based on the ASR results and incident response preparation services.
    Learn More: What is Cyber Insurance?
What is Blackpanda ASR?

Blackpanda's Attack Surface Readiness (ASR) scans are an external-only method for scanning digital infrastructure and identifying security vulnerabilities. It is a core component of the IR-1 subscription, providing visibility into customer security vulnerabilities and actionable insights to address gaps in their defenses before hackers exploit them. This intelligence also serves to enhance the efficiency of Blackpanda’s incident response team as well as provide data for optimized cyber insurance pricing from Blackpanda Underwriting.

Do I need to install any software for my IR-1 subscription?

Nothing needs to be installed on your systems or your customers' systems. Blackpanda ASR works in the cloud and does not require any plugins or agents. This applies to all aspects of IR-1, including Readiness, Response, and Recovery, and ensures instant post-attack coverage upon purchase.

What should I do if my customer believes they are experiencing a cyber incident?

You or your customer can log on to the Blackpanda Platform to report a cyber incident and activate the IR-1 incident response service. An incident responder will be in touch to walk through the best course of immediate action. This initial contact is guaranteed to occur within 4 hours of the incident being reported. In most cases, it will be much faster.

What is included in the IR-1 incident response credit?

The IR-1 credit entitles the holder to comprehensive Level 3 incident responders in case of a cyber emergency (applicable to qualified cyber incidents only).

This includes:

  • Investigation: Determining the extent and scope of the attack.
  • Containment: Stopping the spread of the attack.
  • Neutralisation: Eliminating the threat.* 

The credit does not include the restoration of business activities or implementation of extended remediating actions. 

* Neutralisation requires collaboration with the end-user's IT team to implement remedial actions as recommended by the Blackpanda Incident Manager.

What is considered a “qualified cyber incident”?

A qualified cyber incident includes Basic Web Application Attacks, System Intrusion, Business Email Compromise, Malware, or Ransomware. Additionally, a qualified cyber incident must satisfy the following two criteria: 

  1. The compromise date must be later than the registration/renewal of the IR-1 subscription. 
  2. The scope of the investigation, as determined by the Blackpanda Incident Manager, must not exceed the number of endpoints covered by the subscription size. If the investigation scope includes more endpoints than covered, additional charges apply at the prevailing rate.
What happens if the initial investigation reveals that the IR-1 credit was activated for an incident that is ultimately not considered qualified?

When we receive an Incident Response activation request, our multidisciplinary regional responders start investigating the suspected incident immediately. Regardless of whether the investigation reveals the incident to qualify for our services or not, the IR-1 credit will be redeemed.

Note: Any deliverables outlined in the IR-1 activation Scope of Work will not be provided unless the incident is qualified.

What if an IR-1 credit has been used and a company is hit a second time within the subscription period?

Blackpanda services are available at standard hourly consulting rates, depending on team availability.

What else can be done to strengthen cybersecurity?

At Blackpanda, we offer additional Incident Response Preparation and consulting services to help strengthen defenses and enhance response, including:

  • Incident Response Playbooks: Customized response plans tailored to specific needs, providing clear guidance for fast and effective response.
  • Tabletop Exercises (TTX): Controlled simulations to test and refine incident response playbooks, improving emergency readiness.
  • Compromise Assessments: Thorough evaluations of security postures to identify existing threats or vulnerabilities and strengthen s.
  • Purple Teaming: Realistic exercises combining offense (red team) and defense (blue team) to test and enhance overall security.

Adding bespoke Incident Response Preparations services to IR-1 is called IR-X. For more information on these and other consulting services, please contact our team. We’ll be happy to help advise on the best solutions to meet your needs.

Are these incident response consulting services customisable to suit the customer’s budget and appetite for strengthening their cyber security posture?

We offer flexible consulting packages that can be tailored to address your unique challenges and security goals. Whether you need comprehensive, in-depth cyber defense strategies or targeted support in specific areas, our team will work with you to develop a solution that not only fits your budget but also effectively enhances your organization's cyber resilience.

Blackpanda’s experts can assist with all these services. Contact our team today to find out more.

Ready to defend your business?

Blackpanda is committed to helping regional businesses strengthen their cyber resilience and secure their digital operations. Speak to us to find out how we can help your organization.

Proud IR-1 partner to: