Skip to content

Cybersecurity

Incident Response

Contain, investigate, and recover.

Preparation for, and handling of, live security incidents: triage, containment, recovery, and the review afterwards. The cheapest time to plan an incident response is before the incident.

When this applies

You may need this if

  • No agreed procedure for who does what during an incident
  • You have had a near miss and nothing changed afterwards
  • Nobody is certain who to call outside working hours

Scope

What the engagement covers

  • Incident response planning and playbooks
  • Incident triage and initial investigation
  • Threat containment and endpoint isolation
  • Compromised account response
  • Evidence preservation and malware investigation
  • Recovery coordination
  • Incident documentation and post-incident review

Outcome

What you are left with

  • A defined chain of command before you need it
  • Faster containment and less lateral spread
  • A post-incident review that changes something concrete

Commonly delivered alongside

Cybersecurity

Digital Forensics

Evidence handling and analysis.

Read more

Managed IT

Backup and Recovery

Protected backups with tested restores.

Read more

Managed IT

Endpoint Security

Device management, EDR, and patching.

Read more