Skip to main content
Secure web and mobile application developmentView service

Contain, investigate,

recover, and harden.

Structured incident response for organisations under active attack or preparing before one happens. We contain the intrusion, investigate with forensic discipline, restore operations, and leave you with a hardening plan, on a pre-arranged retainer or as an emergency engagement.

Retainer clients24/7 on-call access under defined response terms
01
Five
Response Phases
Detect, contain, investigate, recover, harden
02
24/7
Retainer On-Call
Access under agreed response terms
03
Two
Engagement Models
Retainer or emergency engagement
04
Full
Chain of Custody
Court-admissible forensic handling

Five phases.
One disciplined arc.

Every incident is different; the process is not. Detect, contain, investigate, recover, harden: the same sequence applied consistently, because a repeatable process is what holds up under pressure.

01 · Detect
Immediate

Triage the Signal

A structured intake call establishes what is known, the likely blast radius, and whether this is a confirmed incident. Severity is classified so the right resources are committed at once.

  • Structured triage call
  • Blast-radius assessment
  • Severity classification
02 · Contain
First priority

Contain the Intrusion

Network isolation, credential and key rotation, and removal of attacker persistence. Containment comes first; investigation runs in parallel rather than delaying it.

  • Network segmentation
  • Credential & key rotation
  • Persistence eradication
03 · Investigate
In parallel

Reconstruct the Attack

Disk and memory forensics, log correlation, and lateral-movement tracing establish the timeline and root cause. Every artefact is handled under chain-of-custody procedures for legal, insurance, or regulatory use.

  • Disk & memory forensics
  • Timeline reconstruction
  • Root-cause identification
04 · Recover
Once contained

Return to Operations

Clean rebuilds, validated restores, and staged reintroduction of systems. Recovery is declared complete only with evidence that attacker access has been removed.

  • Validated clean rebuilds
  • Tested restore paths
  • Staged reintroduction
05 · Harden
After recovery

Harden Against Recurrence

A post-incident review documents control gaps, tunes detections, and produces a prioritised hardening roadmap so the same attack path does not work twice.

  • Post-incident review
  • Detection tuning
  • Hardening roadmap

Incident types
we respond to.

Procedures and tooling are prepared for the incident types organisations most commonly face, from opportunistic ransomware to long-dwell intrusions by well-resourced adversaries.

01 — Extortion

Ransomware

Containment, decryption-feasibility analysis, clean-rebuild planning, and coordination with insurers and, where appropriate, specialist negotiators.

02 — Exfiltration

Data Breach

Exfiltration scoping, data-subject notification workflows, regulator liaison, and disclosure support against statutory deadlines.

03 — Upstream

Supply-Chain Compromise

Compromised vendor package, poisoned update channel, or third-party SaaS breach. We trace the blast radius across your environment and its downstream dependencies.

04 — Internal

Insider Threat

Malicious or negligent insiders. Discreet evidence collection, HR and legal coordination, and containment that preserves options while protecting the business.

05 — Cloud

Cloud Compromise

AWS, Azure, Google Cloud, or SaaS account takeover: token revocation, IAM forensics, resource audit, and containment of billing abuse.

06 — APT

Advanced Persistent Threat

Long-dwell intrusions, living-off-the-land techniques, and custom tooling from well-resourced adversaries, where forensic depth determines whether eviction is complete.

Retainer or
emergency engagement.

We accept both. A retainer removes the delays that cost the most during an incident: contracts are already signed, your environment is already documented, and the responders already know your team.

Recommended

IR Retainer

Pre-engaged, pre-scoped, and on-call. The same team each time, already briefed on your environment, ready to begin containment under agreed response terms.

  • Contractually defined response time to a lead responder
  • Legal and scoping agreements signed in advance
  • Environment baseline documented before an incident
  • Priority allocation of responders and tooling
  • Tabletop exercises included
  • Annual incident response plan review
Cold Start

Emergency Engagement

Available without a prior relationship, subject to responder availability. Expect a cold-start rate and the practical delay of agreeing terms while systems are compromised.

  • Cold-start billing rate
  • Contracts and scoping agreed mid-incident
  • Environment discovery from scratch
  • Responder allocation subject to availability
  • No prior relationship with your team
  • Onboarding time delays containment

Evidence that
survives scrutiny.

When an incident leads to litigation, a regulatory enquiry, or an insurance claim, the handling of evidence determines what can be relied on. We work to a standard intended to produce court-admissible evidence.

Chain of Custody

Every artefact is hashed, timestamped, and logged from acquisition through analysis: a documented handling trail from the affected system to the final report.

Court-Admissible Evidence

The forensic workflow is built to withstand cross-examination. Methodology is documented, tooling is verified, and our analysts are available to provide expert testimony if litigation follows.

Post-Incident Report

A single authoritative document: timeline, root cause, scope of compromise, data impact, remediation actions, and a ranked hardening plan. One reference for executives, regulators, and insurers.

Global Regulatory Landscape

Disclosure planning,
built into response.

Cross-border incidents create legal, insurance, customer-notification, and board reporting pressure at the same time. Our engagements organise evidence, timelines, decisions, and remediation records so counsel and leadership can act quickly.

Evidence01

Chain of Custody

Forensic handling, hashing, timestamps, and analyst notes preserved from acquisition onward.

Counsel02

Legal Readiness

Clear timelines, scope notes, and evidence packages for external counsel and disclosure decisions.

Insurers03

Insurance Support

Incident facts, containment actions, and recovery records organised for cyber-insurance review.

Customers04

Notification Support

Business-facing summaries that help teams explain what happened and what was done.

Board05

Executive Reporting

Decision-ready updates for leadership during containment, investigation, and recovery.

Follow-up06

Remediation Tracking

A hardening roadmap that connects incident lessons to accountable security improvements.

Operating principle
Containfirst
Isolation before investigation

Containment actions begin as soon as the scope is understood: network isolation, credential and key rotation, and removal of persistence. Investigation runs in parallel so evidence is preserved without delaying eviction.

Retainer on-call
Documented methodology
DFIR tooling ready

Questions to ask
before an incident.

How quickly can you be on a call?

Retainer clients have a contractually defined response time to a lead responder. Emergency engagements without a retainer are handled on a best-effort basis depending on current commitments. We will tell you what we can commit to when you contact us rather than promise a time we cannot keep.

What is the difference between a retainer and an emergency engagement?

A retainer is pre-paid response capacity with a defined response time. Contracts are signed in advance, a baseline of your environment is on file, and response starts with containment rather than paperwork. An emergency engagement starts cold: terms are agreed while the intrusion is ongoing, and time spent on onboarding is time not spent on containment.

Do you negotiate with ransomware actors?

Only when it is lawful and operationally justified, and only after clean-rebuild feasibility has been assessed. Where negotiation is appropriate it is coordinated with specialist counsel and negotiators, with sanctions screening as a precondition. The objective is always recovery without payment where that is achievable.

Will your evidence hold up with counsel, insurers, or regulators?

Yes. Our forensic workflow follows chain-of-custody practice from acquisition onward: tooling is documented, every handling step is recorded, our analysts are prepared to provide expert testimony, and reports are structured for legal, insurance, and regulator-facing review where required.

What tools do you use?

Established DFIR tooling such as Velociraptor, Volatility, KAPE, X-Ways, and Cellebrite, together with in-house tooling for cloud and ephemeral workloads. We bring our own toolkit, so no procurement is needed during a live incident.

We are in the middle of an incident right now. Can you help?

Contact us immediately and mark the request as an active incident; those requests are prioritised. Triage can begin under a short letter of engagement, with full documentation completed once the immediate situation is contained.

Establish the relationship
before you need it.

The best time to set up incident response is before an incident. Start with a scoping conversation, or contact us now if you are dealing with an active incident.

Retainer on-call · Defined response terms · Emergency engagements accepted