
Incident Response & Forensics
The worst time to work out who to call is during a breach. We provide a retained response capability — an agreed plan, named contacts and a team that already understands your environment — and the engagement itself when an incident lands. We contain the spread, preserve evidence before it is destroyed by well-meaning cleanup, establish what actually happened and what was reached, support your regulatory and insurer notifications, and run the recovery. Afterwards you get an honest post-incident review covering what let it in and what stopped it being worse.
What You Get
Hours, Not Days
A retainer means response begins immediately instead of after a week of procurement while the attacker keeps working.
Evidence Preserved
Well-intentioned cleanup destroys the evidence you later need for insurers and regulators. We secure it first.
Defensible Answers
Regulators and customers will ask what was accessed. A proper investigation means you can answer accurately rather than guess.
Insurer Alignment
Many cyber policies require defined response arrangements, and some dictate who may be engaged.
How We Work
- 1
Readiness & Retainer
Before anything happens: a response plan, agreed escalation contacts, authority to act defined in advance, and our familiarity with your environment established while nobody is panicking.
- 2
Triage & Containment
On activation we establish what is affected and cut off the spread — isolating hosts, disabling accounts and closing the path in, while keeping the business running wherever possible.
- 3
Forensic Investigation
Evidence is preserved properly, then we reconstruct the timeline: how entry was gained, what was accessed, what was taken and whether the attacker still has a foothold.
- 4
Eradication & Recovery
Persistence is removed, credentials rotated, systems restored from known-good copies, and services brought back in a controlled order.
- 5
Post-Incident Review
A written account for your board, insurer and regulator, plus a frank assessment of the control failures that allowed it and the changes that would prevent a repeat.
When something has already happened: contain it, understand it, and get you back to normal with evidence intact.
Every engagement ends with something you can act on — a report, a tested configuration, a decision with a cost attached. Not a dashboard nobody opens.
Talk to an EngineerTools & Technologies
Forensic Imaging
Sound capture of disk and memory so evidence stands up to scrutiny.
Timeline Analysis
Correlating logs across endpoint, network, identity and cloud into one sequence of events.
Threat Intelligence
Attributing tooling and behaviour to known actors to anticipate the next move.
Secure Collaboration
An out-of-band channel, on the assumption your normal systems may be compromised.
Frequently Asked Questions
Do we need this if you already run our SOC?+
What happens if we call you without a retainer?+
Will you work with our insurer and lawyers?+
How quickly do you respond?+
Related Services
Ready to Get Started?
Contact us today for a free consultation about our incident response & forensics services.
Schedule Consultation