logo-white
  • Home
  • About Us
  • Services
  • Blog
  • Contact Us
C-Level Support
  • Digital Transformation
  • CIO as a Service
  • Analytics & Insights
  • Project Management
  • Start Up Support
  • DevOps
  • Dev Support
MSP
  • Enterprise Service Desk
  • Infrastructure Management
  • Managed Monitoring
  • Business Continuity
  • Insourced Team
  • Managed Cyber
  • Prime Services
Cloud
  • AWS Strategy
  • AWS Well-Architected Review
  • Azure Strategy
  • Multi-Cloud
  • Containerisation
  • Serverless Specialist
  • Hybrid Architecture
Governance
  • Governance Framework
  • Security Governance
  • ROI & TCO Management
  • Compliance & Auditing
Workforce Optimisation
  • Remote Working
  • Bring Your Own Device
  • Collaboration & Process
Cyber Security
  • Penetration Testing
  • Cyber Audit
  • Cyber Governance
  • Forensics
  • Social Training
  • Security as a Service (SOC)
Artificial Intelligence
  • Sentiment Analysis
  • Pattern Analysis
  • Data Priming & Preparation
  • Cyber AI
  • Robotic Process Automation
  • AI Platform Management
calendar-edit-light
BOOK A
MEETING
Managed Security/Operate/Incident Response

Incident Response — when something serious happens, speed is the only thing that matters.

If you are in the middle of an incident right now, call us. We will have a named analyst on with you inside 30 minutes, even out of hours. If you are here to plan retainer capability before you need it — so the response is rehearsed, not improvised — read on.

24/7P1 responseDigital forensicsRetained or on-call
Call now — 020 3588 2584Set up an IR retainer
In an incident now?
020 3588 2584

We’ll get a named analyst on with you inside 30 minutes, even out of hours. Existing clients: your SOC escalation line takes priority and routes straight through.

The P1 response

A P1 is not one job. It’s five, run at once.

A true breach is never a one-hit wonder — it is usually nine attempts, packages morphing, various routes being tried at once. Containing the single threat is a priority one. So is strengthening defence, so is keeping the business running, so is communicating. That is why we assemble a structured team of around twelve people for a P1, with a central incident manager and four specialist leads who each own their own front.

Central role
Incident Manager
Owns the incident holistically. Coordinates the four leads, holds the timeline, manages decisions and escalation, and keeps everyone working to the same picture. The single point of command for the duration.
Lead 01

Threat containment

Stop and contain the threat: isolate devices, stop lateral movement, prevent the threat propagating. Pulls in a security architect as needed.

Lead 02

Defence implementation

Strengthens defences while containment runs — closing the holes and gaps that would let an attacker re-establish a connection.

Lead 03

Business continuity

Restore and workarounds: databases, rebuilt machines, shipped laptops, new cloud services, DR invocation — so recovery isn’t an afterthought three hours in.

Lead 04

Business comms

Customers, internal stakeholders, what’s down, what decisions have been made and by whom. The role that’s most often forgotten — and shouldn’t be.

Burst capacity

Each lead can extend their own team. Across our three companies we employ getting on for 100 people, around 75 in the security space — and we have never exhausted that resource to get a client out of a muddle. Need ten cloud architects to invoke a DR strategy, or fifteen people on site to rebuild a hundred laptops in eight hours? Each sub-incident lead calls on the right people. The key is that it is all mapped in the RACI matrix and rehearsed in advance — no one is guessing who to pull into which call.

What IR covers

From stop the bleed to lessons learned.

✓
Immediate triage and containment — stop the bleed.
✓
Forensic investigation — what was accessed, what was exfiltrated, what persistence remains.
✓
Remediation support — eviction of attackers, credential rotation, system-rebuild guidance.
✓
Regulatory and insurer liaison — helping you meet ICO reporting deadlines and preserve insurance coverage.
✓
Post-incident review — lessons learned, root cause, prioritised remediation.
Retained vs on-call

Rehearsed beats improvised, every time.

Organisations that face meaningful cyber risk should retain an IR capability. It dramatically reduces response time and, increasingly, satisfies insurer requirements. If you can catch something in the first six or seven minutes and respond well, a whole world of pain is avoided.

Recommended

Retained

Rehearsed, guaranteed, insurer-friendly

An annual tabletop exercise, pre-agreed response terms, pre-engaged legal and forensic contacts, and a guaranteed response SLA. Built around your business impact analysis, so every critical application already has a playbook.

Annual tabletopResponse SLAPre-engaged legalBIA-driven playbooks
Available

On-call

When you need help now

Engagement is available for an active incident without a prior retainer — but at commercial rates and without the SLA. The first call still gets a named analyst inside 30 minutes; the difference is everything that wasn’t rehearsed in advance.

Commercial ratesNo SLA30-min first response
Be ready

Have the plan before you need it.

Set up an Incident Response retainer and we’ll build the playbooks against your critical applications, then tabletop-test them with your team. Or, if you’re in an incident now, call.

Set up an IR retainer →Call now — 020 3588 2584
3gi-adj-logo-white

A Digital Transformation Company.

Site Map
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms
3Gi Technology
  • Whitegates
    Business Centre
    Alexander Ln
    Shenfield
    CM15 8QF
Contact Details
  • 020 3588 2584
  • sales@3gi.co.uk

©2026. All rights reserved