If you are in the middle of an incident right now, call us. We will have a named analyst on with you inside 30 minutes, even out of hours. If you are here to plan retainer capability before you need it — so the response is rehearsed, not improvised — read on.
We’ll get a named analyst on with you inside 30 minutes, even out of hours. Existing clients: your SOC escalation line takes priority and routes straight through.
A true breach is never a one-hit wonder — it is usually nine attempts, packages morphing, various routes being tried at once. Containing the single threat is a priority one. So is strengthening defence, so is keeping the business running, so is communicating. That is why we assemble a structured team of around twelve people for a P1, with a central incident manager and four specialist leads who each own their own front.
Stop and contain the threat: isolate devices, stop lateral movement, prevent the threat propagating. Pulls in a security architect as needed.
Strengthens defences while containment runs — closing the holes and gaps that would let an attacker re-establish a connection.
Restore and workarounds: databases, rebuilt machines, shipped laptops, new cloud services, DR invocation — so recovery isn’t an afterthought three hours in.
Customers, internal stakeholders, what’s down, what decisions have been made and by whom. The role that’s most often forgotten — and shouldn’t be.
Each lead can extend their own team. Across our three companies we employ getting on for 100 people, around 75 in the security space — and we have never exhausted that resource to get a client out of a muddle. Need ten cloud architects to invoke a DR strategy, or fifteen people on site to rebuild a hundred laptops in eight hours? Each sub-incident lead calls on the right people. The key is that it is all mapped in the RACI matrix and rehearsed in advance — no one is guessing who to pull into which call.
Organisations that face meaningful cyber risk should retain an IR capability. It dramatically reduces response time and, increasingly, satisfies insurer requirements. If you can catch something in the first six or seven minutes and respond well, a whole world of pain is avoided.
An annual tabletop exercise, pre-agreed response terms, pre-engaged legal and forensic contacts, and a guaranteed response SLA. Built around your business impact analysis, so every critical application already has a playbook.
Engagement is available for an active incident without a prior retainer — but at commercial rates and without the SLA. The first call still gets a named analyst inside 30 minutes; the difference is everything that wasn’t rehearsed in advance.
Set up an Incident Response retainer and we’ll build the playbooks against your critical applications, then tabletop-test them with your team. Or, if you’re in an incident now, call.