Incident Response

Get a clear path through an incident

Evidence, a plain-language explanation of potential business impact, and prioritised next steps within an agreed scope.

Assess a suspected compromise, prioritise containment, and coordinate recovery steps with your team. Availability and scope are confirmed before an engagement.

What's included

Immediate triage - is this real, how bad, and is it still happening?
Containment guidance - isolate what matters without destroying evidence
Damage scoping - what was accessed, taken, or changed
Evidence preservation for legal, insurance, and regulatory needs
Communication guidance - regulators, customers, and staff
Post-incident recommendations to reduce recurrence risk

How it works

01

Contain

First priority: stop the bleeding. We guide immediate containment - sessions, credentials, network isolation - while preserving evidence.

02

Scope

We assess available evidence to determine what may have been reached, how access may have occurred, and what remains uncertain.

03

Recover

Systems are restored safely, the entry point is closed and validated, and you get a full incident report with hardening actions.

What you get

Deliverables, coverage, access, fees, and response or reporting times are agreed in your proposal. Testing requires written authorisation. Findings reflect the agreed scope and available evidence; they are not a guarantee against a breach.

Deliverable 01Incident report with a timeline supported by available evidence
Deliverable 02Preserved evidence package
Deliverable 03Regulatory notification support
Deliverable 04Post-incident hardening plan

Find out what attackers already know about your business.

Tell us what matters to your business. We will agree the right scope and next step.

Discuss your business risks