GhostTrace LLC — Security Awareness Training for Small Businesses

GhostTrace LLC is a Georgia-based security awareness training and cybersecurity practice (Control No. 26142915), run by founder Daniel Upperman. We run live security awareness training that keeps small businesses insured and compliant.

Who is GhostTrace LLC?

GhostTrace LLC is owned and founded by Daniel Upperman. The company is registered in Georgia, USA with Georgia Control Number 26142915. Founded in 2026, GhostTrace's primary service is live security awareness training for small businesses, producing the documented completion records cyber insurers and regulators require. GhostTrace also provides incident documentation support, exposure monitoring, business and domain due diligence, impersonation takedown packaging, and digital safety reviews. Ethics complaints are reviewed directly by the founder under our published Ethics Complaint process. This is not a law enforcement agency. We do not conduct unauthorized hacking, surveillance, or data theft. We use only legal, public-source research methods, and we do not research individuals.

Founder Details

Founder & Owner: Daniel Upperman | Email: Founder@ghosttrace.net | Company: GhostTrace LLC | Location: Georgia, USA | Registration: Control No. 26142915

GhostTrace isn't a private investigator, a law firm, or law enforcement, and doesn't locate, profile, or run background checks on people.

Who runs this

Founder and Owner: Daniel Upperman

Email: Founder@ghosttrace.net

Daniel Upperman founded GhostTrace LLC in 2026 to help people affected by online fraud, impersonation, and digital abuse document what happened and figure out what to do next. GhostTrace is one person; every request is handled directly by Daniel.

Ethics & Compliance

Ethics complaints come straight to the founder: complaint reviews, policy compliance, and research standards. File a concern via our Ethics Complaint form.

Business registration

GhostTrace LLC is a registered Georgia limited liability company (Control No. 26142915, status Active), formed June 25, 2026. Full registration and registered-agent details are on the Legal page.

Contact Information

Services

Popular questions we answer

Contact

Email support@ghosttrace.net — replies within one business day. Anonymous intelligence submissions accepted (no account required).

Enable JavaScript to access the full interactive site, client portal, and staff portal. Content below is rendered by React once JavaScript is available.

PROMO

CodeGabe partner code20.0% off, referred by CodeGabe

CODEGABE5CF6View pricing
← Back to articles
Article

Building an Incident Response Plan That Actually Works

Jul 12, 2026 · GhostTrace Team

A written incident response plan and a useful incident response plan are not the same document. The gap between them shows up exactly when it matters most — in the first confused hour after something goes wrong.

What a plan needs to actually answer

A plan that only says "notify IT" isn't a plan — it's a placeholder. A working plan answers, specifically:

  • Who has authority to make decisions — take a system offline, notify customers, engage outside help — and who's the backup if that person is unreachable.
  • What "an incident" actually means for your business, concretely enough that a non-technical employee can recognize one.
  • Who gets contacted, in what order, including outside counsel, insurance, and any specialist help — with actual current phone numbers, not a name that's since left the company.
  • What gets preserved before anything gets "fixed." The instinct to immediately wipe and reinstall a compromised system destroys the evidence needed to understand what happened and whether it's still happening elsewhere.
  • What you're legally required to disclose, to whom, and within what timeframe — this varies by industry and jurisdiction, and figuring it out mid-incident costs time you don't have.

The testing gap

Most plans that fail weren't wrong on paper — they were simply never rehearsed. A short tabletop exercise, walking through a plausible scenario (a phishing-compromised email account, a ransomware note, a lost laptop with customer data) surfaces the gaps a document review never will: the contact who no longer works there, the backup that turns out not to actually restore, the decision-maker no one thought to loop in.

Keep it usable under stress

A 40-page plan does not get read during an actual incident. The operational core should fit on one or two pages: who to call, what to preserve, what not to do yet. Put the longer procedural detail in an appendix for after the immediate response is underway.

After the incident

The plan's job isn't finished when systems are back online. A short post-incident review — what worked, what didn't, what the plan missed — is what turns one bad day into a better plan for the next one. Skipping this step is the most common reason the same gap gets exploited twice.

If you're building this from scratch or reviewing an existing plan, GhostTrace's Incident Documentation and Cybersecurity Consulting services can help pressure-test it against realistic scenarios.