Secure · Cyber & Networks
Incident response
Investigation, containment and recovery when a breach is suspected or confirmed, run to NIST SP 800-61 and documented for regulators and insurers.
The challenge
A security incident is a test of decisions made under pressure: what to shut down, what to preserve, whom to notify and when. Poor early decisions destroy evidence, extend the outage or create regulatory exposure.
Few organisations handle serious incidents often enough to be practised at them. Plans written for an audit rarely survive the first hour of a live ransomware event.
We bring a structured response, forensic discipline and calm coordination, and we help you prepare beforehand so the plan you rely on has been exercised.
Our method
How the work is done.
- 01
Preparation
We review or write your incident response plan, define roles and decision rights, and run tabletop exercises with technical and executive teams.
- 02
Detection and analysis
On activation we establish scope and severity, collect and preserve evidence with chain of custody, and build a timeline of attacker activity.
- 03
Containment
We isolate affected systems and accounts, cut off attacker access and prevent further spread, balancing evidence preservation against operational impact.
- 04
Eradication and recovery
Persistence mechanisms are removed, credentials rotated, systems rebuilt or restored from verified backups, and monitoring increased during return to service.
- 05
Post-incident activity
We deliver a root-cause report, lessons learned and a prioritised plan to close the weaknesses that allowed the incident.
Deliverables
What you receive.
- Incident response plan and playbooks for priority scenarios
- Tabletop exercise reports with findings and actions
- Evidence handling and chain-of-custody records
- Attacker timeline and scope of compromise
- Executive briefings during the incident
- Root-cause and post-incident report suitable for regulators and insurers
- Remediation roadmap
Engagement options
Ways to buy it.
- 0112 months
Retainer
Pre-agreed terms, onboarding and an annual exercise, so response begins without contract negotiation during an incident.
- 02Days to weeks, as the incident requires
Emergency response
Immediate engagement for an active incident without an existing retainer.
- 033 to 6 weeks
Readiness programme
Plan review, playbook development and tabletop exercises.
Standards
Frameworks we work to.
- NIST SP 800-61
- ISO 27035
- MITRE ATT&CK
- NIST CSF
- ISO 27001
Questions
What buyers ask us.
Should we switch off affected systems?
Not before speaking to a responder if you can avoid it. Powering down can destroy volatile evidence. Isolating from the network is usually the safer first step.
Do you negotiate with ransomware operators?
We advise leadership on the options and their legal and practical implications. The decision remains yours, taken with your legal counsel and insurer.
Will you help with regulator and customer notifications?
We provide the factual findings and timeline your legal and communications teams need to make accurate notifications.
What does a retainer give us that an emergency call does not?
Pre-agreed terms, a team that already knows your environment, and an exercised plan. That removes hours of delay at the point when time matters most.
Related services
Often delivered together.
Secure
Managed detection & response
Continuous monitoring of your endpoints, identities, networks and cloud, with analysts who triage alerts and contain threats under agreed playbooks.
Train
Executive cyber briefings
Focused sessions and tabletop exercises that equip boards and leadership teams to govern cyber risk and lead through an incident.
Secure
Virtual CISO
Senior security leadership on a part-time basis: strategy, risk ownership, board reporting and programme direction without a full-time hire.
Discuss incident response.
A senior engineer reviews every enquiry and replies within one business day.