RESOLV

Secure · Cyber & Networks

Incident response

Investigation, containment and recovery when a breach is suspected or confirmed, run to NIST SP 800-61 and documented for regulators and insurers.

The challenge

A security incident is a test of decisions made under pressure: what to shut down, what to preserve, whom to notify and when. Poor early decisions destroy evidence, extend the outage or create regulatory exposure.

Few organisations handle serious incidents often enough to be practised at them. Plans written for an audit rarely survive the first hour of a live ransomware event.

We bring a structured response, forensic discipline and calm coordination, and we help you prepare beforehand so the plan you rely on has been exercised.

Our method

How the work is done.

  1. 01

    Preparation

    We review or write your incident response plan, define roles and decision rights, and run tabletop exercises with technical and executive teams.

  2. 02

    Detection and analysis

    On activation we establish scope and severity, collect and preserve evidence with chain of custody, and build a timeline of attacker activity.

  3. 03

    Containment

    We isolate affected systems and accounts, cut off attacker access and prevent further spread, balancing evidence preservation against operational impact.

  4. 04

    Eradication and recovery

    Persistence mechanisms are removed, credentials rotated, systems rebuilt or restored from verified backups, and monitoring increased during return to service.

  5. 05

    Post-incident activity

    We deliver a root-cause report, lessons learned and a prioritised plan to close the weaknesses that allowed the incident.

Deliverables

What you receive.

  • Incident response plan and playbooks for priority scenarios
  • Tabletop exercise reports with findings and actions
  • Evidence handling and chain-of-custody records
  • Attacker timeline and scope of compromise
  • Executive briefings during the incident
  • Root-cause and post-incident report suitable for regulators and insurers
  • Remediation roadmap

Engagement options

Ways to buy it.

  1. 01

    Retainer

    Pre-agreed terms, onboarding and an annual exercise, so response begins without contract negotiation during an incident.

    12 months
  2. 02

    Emergency response

    Immediate engagement for an active incident without an existing retainer.

    Days to weeks, as the incident requires
  3. 03

    Readiness programme

    Plan review, playbook development and tabletop exercises.

    3 to 6 weeks

Standards

Frameworks we work to.

  • NIST SP 800-61
  • ISO 27035
  • MITRE ATT&CK
  • NIST CSF
  • ISO 27001

Questions

What buyers ask us.

Should we switch off affected systems?

Not before speaking to a responder if you can avoid it. Powering down can destroy volatile evidence. Isolating from the network is usually the safer first step.

Do you negotiate with ransomware operators?

We advise leadership on the options and their legal and practical implications. The decision remains yours, taken with your legal counsel and insurer.

Will you help with regulator and customer notifications?

We provide the factual findings and timeline your legal and communications teams need to make accurate notifications.

What does a retainer give us that an emergency call does not?

Pre-agreed terms, a team that already knows your environment, and an exercised plan. That removes hours of delay at the point when time matters most.

Discuss incident response.

A senior engineer reviews every enquiry and replies within one business day.