Contain, investigate,
Structured incident response for organisations under active attack or preparing before one happens. We contain the intrusion, investigate with forensic discipline, restore operations, and leave you with a hardening plan, on a pre-arranged retainer or as an emergency engagement.
Five phases.
One disciplined arc.
Every incident is different; the process is not. Detect, contain, investigate, recover, harden: the same sequence applied consistently, because a repeatable process is what holds up under pressure.
Triage the Signal
A structured intake call establishes what is known, the likely blast radius, and whether this is a confirmed incident. Severity is classified so the right resources are committed at once.
- Structured triage call
- Blast-radius assessment
- Severity classification
Contain the Intrusion
Network isolation, credential and key rotation, and removal of attacker persistence. Containment comes first; investigation runs in parallel rather than delaying it.
- Network segmentation
- Credential & key rotation
- Persistence eradication
Reconstruct the Attack
Disk and memory forensics, log correlation, and lateral-movement tracing establish the timeline and root cause. Every artefact is handled under chain-of-custody procedures for legal, insurance, or regulatory use.
- Disk & memory forensics
- Timeline reconstruction
- Root-cause identification
Return to Operations
Clean rebuilds, validated restores, and staged reintroduction of systems. Recovery is declared complete only with evidence that attacker access has been removed.
- Validated clean rebuilds
- Tested restore paths
- Staged reintroduction
Harden Against Recurrence
A post-incident review documents control gaps, tunes detections, and produces a prioritised hardening roadmap so the same attack path does not work twice.
- Post-incident review
- Detection tuning
- Hardening roadmap
Incident types
we respond to.
Procedures and tooling are prepared for the incident types organisations most commonly face, from opportunistic ransomware to long-dwell intrusions by well-resourced adversaries.
Ransomware
Containment, decryption-feasibility analysis, clean-rebuild planning, and coordination with insurers and, where appropriate, specialist negotiators.
Data Breach
Exfiltration scoping, data-subject notification workflows, regulator liaison, and disclosure support against statutory deadlines.
Supply-Chain Compromise
Compromised vendor package, poisoned update channel, or third-party SaaS breach. We trace the blast radius across your environment and its downstream dependencies.
Insider Threat
Malicious or negligent insiders. Discreet evidence collection, HR and legal coordination, and containment that preserves options while protecting the business.
Cloud Compromise
AWS, Azure, Google Cloud, or SaaS account takeover: token revocation, IAM forensics, resource audit, and containment of billing abuse.
Advanced Persistent Threat
Long-dwell intrusions, living-off-the-land techniques, and custom tooling from well-resourced adversaries, where forensic depth determines whether eviction is complete.
Retainer or
emergency engagement.
We accept both. A retainer removes the delays that cost the most during an incident: contracts are already signed, your environment is already documented, and the responders already know your team.
IR Retainer
Pre-engaged, pre-scoped, and on-call. The same team each time, already briefed on your environment, ready to begin containment under agreed response terms.
- Contractually defined response time to a lead responder
- Legal and scoping agreements signed in advance
- Environment baseline documented before an incident
- Priority allocation of responders and tooling
- Tabletop exercises included
- Annual incident response plan review
Emergency Engagement
Available without a prior relationship, subject to responder availability. Expect a cold-start rate and the practical delay of agreeing terms while systems are compromised.
- Cold-start billing rate
- Contracts and scoping agreed mid-incident
- Environment discovery from scratch
- Responder allocation subject to availability
- No prior relationship with your team
- Onboarding time delays containment
Evidence that
survives scrutiny.
When an incident leads to litigation, a regulatory enquiry, or an insurance claim, the handling of evidence determines what can be relied on. We work to a standard intended to produce court-admissible evidence.
Chain of Custody
Every artefact is hashed, timestamped, and logged from acquisition through analysis: a documented handling trail from the affected system to the final report.
Court-Admissible Evidence
The forensic workflow is built to withstand cross-examination. Methodology is documented, tooling is verified, and our analysts are available to provide expert testimony if litigation follows.
Post-Incident Report
A single authoritative document: timeline, root cause, scope of compromise, data impact, remediation actions, and a ranked hardening plan. One reference for executives, regulators, and insurers.
Disclosure planning,
built into response.
Cross-border incidents create legal, insurance, customer-notification, and board reporting pressure at the same time. Our engagements organise evidence, timelines, decisions, and remediation records so counsel and leadership can act quickly.
Chain of Custody
Forensic handling, hashing, timestamps, and analyst notes preserved from acquisition onward.
Legal Readiness
Clear timelines, scope notes, and evidence packages for external counsel and disclosure decisions.
Insurance Support
Incident facts, containment actions, and recovery records organised for cyber-insurance review.
Notification Support
Business-facing summaries that help teams explain what happened and what was done.
Executive Reporting
Decision-ready updates for leadership during containment, investigation, and recovery.
Remediation Tracking
A hardening roadmap that connects incident lessons to accountable security improvements.
Containment actions begin as soon as the scope is understood: network isolation, credential and key rotation, and removal of persistence. Investigation runs in parallel so evidence is preserved without delaying eviction.
Questions to ask
before an incident.
How quickly can you be on a call?
Retainer clients have a contractually defined response time to a lead responder. Emergency engagements without a retainer are handled on a best-effort basis depending on current commitments. We will tell you what we can commit to when you contact us rather than promise a time we cannot keep.
What is the difference between a retainer and an emergency engagement?
A retainer is pre-paid response capacity with a defined response time. Contracts are signed in advance, a baseline of your environment is on file, and response starts with containment rather than paperwork. An emergency engagement starts cold: terms are agreed while the intrusion is ongoing, and time spent on onboarding is time not spent on containment.
Do you negotiate with ransomware actors?
Only when it is lawful and operationally justified, and only after clean-rebuild feasibility has been assessed. Where negotiation is appropriate it is coordinated with specialist counsel and negotiators, with sanctions screening as a precondition. The objective is always recovery without payment where that is achievable.
Will your evidence hold up with counsel, insurers, or regulators?
Yes. Our forensic workflow follows chain-of-custody practice from acquisition onward: tooling is documented, every handling step is recorded, our analysts are prepared to provide expert testimony, and reports are structured for legal, insurance, and regulator-facing review where required.
What tools do you use?
Established DFIR tooling such as Velociraptor, Volatility, KAPE, X-Ways, and Cellebrite, together with in-house tooling for cloud and ephemeral workloads. We bring our own toolkit, so no procurement is needed during a live incident.
We are in the middle of an incident right now. Can you help?
Contact us immediately and mark the request as an active incident; those requests are prioritised. Triage can begin under a short letter of engagement, with full documentation completed once the immediate situation is contained.
Establish the relationship
before you need it.
The best time to set up incident response is before an incident. Start with a scoping conversation, or contact us now if you are dealing with an active incident.