Incident Response
Help when something has already gone wrong. We contain the incident, work out what actually happened rather than what it looked like, preserve what a regulator or insurer will later ask for, and get you back to operating. Afterwards you get a written account you can give to a board, a customer or a regulator without rewriting it.
Timeline
On a retainer, engaged within the response time we agree — commonly one to four hours. Containment usually inside the first day; full forensic analysis and the written report typically one to three weeks depending on estate size.
You get
- Containment of the active incident
- Forensically sound preservation of evidence
- A timeline: initial access, dwell time, movement and scope of access
If any of these is your week, this is the service.
Something is happening right now
You have ransomware, an intrusion or an account takeover in progress and you need people who have done this before.
What we do
Immediate containment, forensic preservation, and someone experienced running the response while your team keeps the business up.
You have no plan and want one before you need it
Everyone knows roughly what they would do, which is another way of saying nobody knows who decides what at 2am.
What we do
A retainer with an agreed response time, a tested plan, and a team already familiar with your environment before the call.
You need to know what was taken
Breach notification obligations turn on what data was actually accessed, and guessing exposes you either way.
What we do
Forensic analysis and a defensible written finding on scope of access, suitable for a regulator and your insurer.
Every step, and what leaves our hands at the end of it.
- 01
Triage
Establish what is happening, what is affected and what is still at risk. First priority is stopping it getting worse.
→ Initial assessment
- 02
Contain
Isolate affected systems and cut the attacker's access, sequenced so containment does not destroy the evidence we need next.
- 03
Preserve & investigate
Forensic images and log preservation, then the actual investigation: initial access, dwell time, lateral movement and scope of access.
→ Forensic timeline
- 04
Eradicate & recover
Remove persistence, close the path in, and bring systems back in an order that does not simply reinfect them.
- 05
Report
A written account — what happened, what was accessed, what we did — in a form you can hand to a board, an insurer or a regulator.
→ Incident report
- 06
Lessons learned
The specific changes that would have stopped it or caught it sooner, ranked by what is actually achievable for your team.
→ Remediation roadmap
Deliverables.
- Containment of the active incident
- Forensically sound preservation of evidence
- A timeline: initial access, dwell time, movement and scope of access
- A written incident report suitable for a regulator, insurer or board
- A ranked list of changes that would have prevented or caught it
- On a retainer: an agreed response time and a tested response plan
Before we can quote.
- 01What you have observed, and when you first observed it
- 02Access for our responders, and someone empowered to authorise containment
- 03Whatever logs still exist — do not clean up before we arrive
- 04Your insurer and legal contacts, if a notification clock may be running
- 05Any system that cannot be taken offline, and what it would cost if it were
Do not worry about having all of it. Send what you have and we will work out the rest on the scoping call.
Incident Response, answered.
We think we are compromised. What do we do first?
Do not wipe or rebuild anything yet, and do not tip off the attacker. Preserve logs, write down what you have seen and when, and call us. Premature cleanup destroys the evidence that answers what was taken.
Do we need a retainer, or can we call you cold?
You can call cold and we will help. A retainer buys an agreed response time and a team that already knows your environment, which is most of the first day's work done in advance.
Will you talk to our insurer?
Yes. The report is written to be usable by an insurer and a regulator, and we will work to their evidentiary requirements if you tell us who they are early.
Scope a Incident Response.
Incident Response is already selected below. Tell us what you are trying to protect and what is driving the timing — if a different service fits better, we will say so rather than sell you this one.