Skip to content

Services / RespondEmergency

Incident Response

Containment, eradication and attribution when the breach has already happened. Retainer clients get a named lead responder and an agreed playbook; the hotline is open to anyone.

47 min

median time to first responder, trailing 12 months

What you receive

  • Named lead responder and incident commander
  • Containment, eradication and recovery to written plan
  • Regulator-ready incident report (GDPR Art. 33, NIS2 Art. 23)
  • Post-incident hardening roadmap

When you need this

Three situations that call for it. If none of them is yours, it probably is not the right spend.

  • 01

    An account is doing things nobody authorised

    A domain administrator was created at three in the morning and no change ticket explains it. What gets isolated in the first hour decides whether the intruder notices you and whether the memory evidence still exists when someone finally looks.

  • 02

    Your MSP says it is contained

    The party telling you the incident is closed may also be the party the intruder came through, and they are unlikely to be the ones to say so. An independent responder answers to you, and will tell you if the containment claim does not hold.

  • 03

    The 24-hour clock started this morning

    NIS2 makes you file an early warning before you know what happened, and a first filing that later contradicts your 72-hour report is its own problem. The technical record has to be written with the second filing already in mind.

How it runs

  1. 01

    Scoping call

    Thirty minutes with an engineer, not a sales development rep. We establish what you actually need and tell you plainly if it is not us.

  2. 02

    Written proposal

    Fixed scope, fixed price, named delivery team, and the rules of engagement in writing before anyone touches a system.

  3. 03

    Delivery

    Weekly written status and a direct channel to the delivery lead. Critical findings are escalated the moment they are confirmed, never held back for the report.

  4. 04

    Readout and retest

    A working session with your team, an executive summary for your board, and a remediation retest included in the original scope rather than quoted separately.

No lock-in

Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.

Who turns up

The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.

Scope

What this does not cover

  • Rebuilding what we tell you to rebuild is not in scope — the report names the work; Cloud Security and DevSecOps are where it gets done.

  • Legal advice is not ours to give. We write the technical record your counsel and DPO rely on; the notification decision stays with them.

  • Evidence collected at containment speed is not evidence built for court — Digital Forensics is the engagement for that.

Measured against

NIS2 Directive (EU) 2022/2555, Art. 23
Early warning within 24 hours of awareness, incident notification within 72 hours, and a final report within one month.
GDPR Art. 33
Notification to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware.
DORA Regulation (EU) 2022/2554, Art. 19
Financial entities must report major ICT-related incidents to their competent authority in initial, intermediate and final reports.

If the scope is wrong

Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.

Questions

The ones we are actually asked.

We are not a retainer client. Will you take the call?

Whether we can start today is a commercial question, and it is answered faster on the phone than on a website. The technical part does not change: where there is no prior engagement there is no agreed playbook and no pre-authorised containment, so the first hour goes on access and authority rather than on the intruder.

Can you guarantee containment within a set time?

No. Containment depends on the access you can grant us and how deep the intruder already is. No. Response time is ours to control; containment is not — it depends on the access you can grant us and how deep the intruder already is. A containment figure quoted before anyone has seen your estate is a guess with a number attached.

Should we shut everything down while we wait?

Usually not. Pulling power destroys memory-resident evidence and tells the intruder they have been seen — isolate at the network layer and leave machines running unless safety or continuing damage forces the choice.

Next step

See what an attacker sees

We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.

30 min

A scoping call, with an engineer rather than a sales rep.

What it costs

Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.

Under attack now?

Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.