Code under inspection on a developer's display
Service

Incident Response & Forensics

The worst time to work out who to call is during a breach. We provide a retained response capability — an agreed plan, named contacts and a team that already understands your environment — and the engagement itself when an incident lands. We contain the spread, preserve evidence before it is destroyed by well-meaning cleanup, establish what actually happened and what was reached, support your regulatory and insurer notifications, and run the recovery. Afterwards you get an honest post-incident review covering what let it in and what stopped it being worse.

What You Get

01

Hours, Not Days

A retainer means response begins immediately instead of after a week of procurement while the attacker keeps working.

02

Evidence Preserved

Well-intentioned cleanup destroys the evidence you later need for insurers and regulators. We secure it first.

03

Defensible Answers

Regulators and customers will ask what was accessed. A proper investigation means you can answer accurately rather than guess.

04

Insurer Alignment

Many cyber policies require defined response arrangements, and some dictate who may be engaged.

How We Work

  1. 1

    Readiness & Retainer

    Before anything happens: a response plan, agreed escalation contacts, authority to act defined in advance, and our familiarity with your environment established while nobody is panicking.

  2. 2

    Triage & Containment

    On activation we establish what is affected and cut off the spread — isolating hosts, disabling accounts and closing the path in, while keeping the business running wherever possible.

  3. 3

    Forensic Investigation

    Evidence is preserved properly, then we reconstruct the timeline: how entry was gained, what was accessed, what was taken and whether the attacker still has a foothold.

  4. 4

    Eradication & Recovery

    Persistence is removed, credentials rotated, systems restored from known-good copies, and services brought back in a controlled order.

  5. 5

    Post-Incident Review

    A written account for your board, insurer and regulator, plus a frank assessment of the control failures that allowed it and the changes that would prevent a repeat.

When something has already happened: contain it, understand it, and get you back to normal with evidence intact.

Every engagement ends with something you can act on — a report, a tested configuration, a decision with a cost attached. Not a dashboard nobody opens.

Talk to an Engineer

Tools & Technologies

Forensic Imaging

Sound capture of disk and memory so evidence stands up to scrutiny.

Timeline Analysis

Correlating logs across endpoint, network, identity and cloud into one sequence of events.

Threat Intelligence

Attributing tooling and behaviour to known actors to anticipate the next move.

Secure Collaboration

An out-of-band channel, on the assumption your normal systems may be compromised.

Frequently Asked Questions

Do we need this if you already run our SOC?+
They solve different problems. The SOC detects and contains day to day. This is for the incident that becomes a business event — forensics, legal and regulatory notification, board reporting and recovery at scale.
What happens if we call you without a retainer?+
We will help where capacity allows, but response starts slower: no agreed authority, no prior knowledge of your environment, and contracting has to happen while the incident is live.
Will you work with our insurer and lawyers?+
Yes, and in a serious incident that coordination matters as much as the technical work. Some policies require specific notification steps and approved responders.
How quickly do you respond?+
Retained clients get a defined activation time agreed in the retainer. That target is set with you rather than advertised as a blanket number.