Our response
What happens when we join.
The sequence follows the NIST SP 800-61 incident handling lifecycle.
It is deliberately unglamorous: scope before you act, contain before
you clean, and never eradicate before you understand the whole
footprint — because a partial eviction just tells the intruder you
are watching.
Throughout, you get a single point of contact, a running timeline
document, and a daily written situation report that your leadership
and your insurer can both use.
Hour 0
Triage and stabilisation
A live call to establish what is known, what is assumed, and what
is actually at risk. We give you immediate containment direction
you can execute with the staff you have on hand while evidence
collection is set up.
Evidence
Preservation and collection
Memory and disk images from affected hosts, log exports before
retention windows expire, and cloud audit trails pulled with
documented chain of custody — so the findings hold up if this ends
in litigation or a claim.
Scope
Forensic analysis
Initial access vector, dwell time, lateral movement, persistence
mechanisms, and — the question your regulator will ask first —
whether data was staged or exfiltrated, and which data.
Eviction
Coordinated eradication
Every foothold closed in one coordinated action rather than
piecemeal: credentials rotated, persistence removed, access paths
severed, and the initial vector shut. Partial eradication is worse
than none.
Return
Recovery and monitoring
Staged restoration to clean builds with heightened monitoring on
the paths the intruder used, so a missed foothold surfaces
immediately rather than next quarter.
After
Report and lessons learned
A written incident report suitable for your board, your insurer,
and your regulator — followed by the remediation programme that
stops the repeat. That work is described under
post-incident resolution.