The assumption that breaks during a breach
Most organisations plan for cyber incidents on paper. Runbooks exist. Roles are defined. The IR plan is on the shared drive, reviewed annually, and ticked off for compliance.
Then ransomware encrypts the shared drive.
Or Active Directory is compromised, and nobody can authenticate to the ticketing system. Or the SIEM is offline because the servers it monitored are now encrypted. Or the IR plan itself was on a file share that no longer exists.
The uncomfortable truth of modern cyber incidents — particularly ransomware — is that the systems you normally use to manage incidents may be the systems that are compromised. Coordinating response from the same environment the attacker controls is not a plan. It is a liability.
What CyberDesk is
CyberDesk is Echo-9's cyber breach response platform — built on the proven GLPI framework, but designed to operate independently of your main infrastructure.
When a serious incident occurs, CyberDesk provides a secure, trusted environment for coordinating recovery: incident tracking, task management, asset discovery, resource coordination and access to disaster recovery and business continuity plans — all from a platform that was not on the network the attacker traversed.
This is not a replacement for your everyday service desk. It is the break-glass platform you activate when normal operations are not available or cannot be trusted.
Why independence matters
During a ransomware attack, the NCSC and CISA guidance is consistent: isolate affected systems, preserve evidence, coordinate recovery from a clean environment. That last point is critical.
If your incident coordination happens over Teams — and Active Directory is compromised — who can you trust? If your asset inventory is in the CMDB on an encrypted server — how do you scope the impact? If your DR plans are on the file share that no longer mounts — what do you execute?
CyberDesk's design principle is simple: the response platform must survive the incident it is responding to.
Key capabilities
Rapid deployment
CyberDesk can be operational in 8–36 hours depending on tier. This is not a six-month implementation project — it is a platform designed to be stood up when you need it, with pre-built workflows based on industry best practice.
Secure vault for DR and BCP plans
Disaster Recovery and Business Continuity Plans are stored securely within CyberDesk — accessible to authorised response team members even when primary infrastructure is unavailable.
Full incident lifecycle tracking
From initial detection through containment, eradication, recovery and post-incident review — every action, decision and communication is tracked within CyberDesk. This creates the audit trail regulators, insurers and boards will demand after the event.
Asset discovery and impact scoping
Understanding the full scope of a breach requires knowing what was affected. CyberDesk includes asset discovery and management capabilities — particularly valuable when your primary CMDB is offline or untrusted.
Task management and resource coordination
Cyber response is a team sport. CyberDesk coordinates tasks across technical teams, communications, legal, HR and leadership — with clear ownership, status tracking and escalation paths.
Pre-built recovery workflows
CyberDesk includes workflows based on industry standards and best practice — not a blank canvas you have to configure while under attack.
How CyberDesk relates to the Echo-9 stack
CyberDesk is built on GLPI, which means organisations already running Echo-9's GLPI environment have familiar architecture, user management and reporting. But CyberDesk is deployed separately — its own instance, its own infrastructure, its own access controls.
- Day-to-day: GLPI manages service desk, assets and changes. Zabbix monitors. Wazuh detects threats.
- During a breach: CyberDesk takes over incident coordination. Wazuh detections can feed into CyberDesk. Asset data from GLPI informs impact scoping — if available and trusted.
- After recovery: Post-incident review data in CyberDesk informs improvements to everyday processes in GLPI.
Who needs this
CyberDesk is relevant for organisations that handle sensitive data, have regulatory breach notification obligations, rely on cyber insurance, run critical operations, or have experienced or fear ransomware — the most common scenario where primary infrastructure becomes unavailable.
It is particularly valuable for organisations whose current IR plan assumes the ticketing system, email and file shares will be available during an incident. That assumption is the gap CyberDesk fills.
Preparing before you need it
The worst time to set up a breach response platform is during a breach.
CyberDesk can be procured and configured in advance — DR plans uploaded, response team roles defined, workflows tested, access credentials distributed through out-of-band channels. When an incident occurs, activation is a decision, not a project.
Echo-9 recommends CyberDesk as part of a broader resilience posture alongside tested backups, segmented networks, monitoring and detection (Zabbix + Wazuh), and regular incident response exercises.
The bottom line
Every organisation has an incident response plan. Fewer have an incident response platform that will actually be available when they need it.
CyberDesk is insurance you hope never to use — but when ransomware encrypts your service desk, your file shares and your email, you will be glad it runs somewhere else.
Discuss CyberDesk
Explore how a break-glass breach response platform fits your resilience posture.