Digital forensics & incident response

The first two hours decide the next six months.

What you do before anyone qualified arrives determines how much you can prove afterwards — to your insurer, your regulator, your clients, and yourself. Below is what to do right now, and what we do when we join.

Report an incident now Jump to the checklist

Do this first

The first-hour checklist.

You do not need us to start. You need to stop the spread without destroying the evidence — and those two goals conflict more often than people expect. This is the order that keeps both intact.

Do

  • Isolate, don't destroy. Pull the network cable or disable the wireless adapter on affected machines — but leave them powered on.
  • Preserve memory. A running machine holds process state, network connections, and keys that vanish on shutdown. Do not reboot.
  • Freeze log retention now. VPN, firewall, EDR, Microsoft 365 and Entra sign-in logs, and cloud audit trails often rotate in days. Extend retention before the window closes.
  • Disable, don't delete, suspect accounts. A deleted account takes its audit trail with it.
  • Reset credentials from a known-clean device, privileged and remote-access accounts first, and revoke active sessions and refresh tokens — a password change alone does not evict an attacker holding a live token.
  • Move coordination out of band. Assume email and chat are being read. Use phones and personal devices until proven otherwise.
  • Start a written timeline. Every observation, action, and decision with a timestamp and timezone. This becomes the backbone of every report that follows.
  • Call your counsel, then your insurer. Most cyber policies require prompt notice and may require approved vendors; involving counsel early can also protect the investigation under privilege.

Don't

  • Don't reimage or restore yet. It feels like progress and it destroys the only copy of how they got in — which means you cannot stop it happening again.
  • Don't reboot or shut down affected systems before memory is captured.
  • Don't delete the phishing email or the malware sample. Quarantine and preserve them.
  • Don't open links in a ransom note or contact the actor before counsel and your insurer have weighed in. That first message has legal and sanctions implications.
  • Don't pay anything on your own initiative. Payment decisions belong with counsel, your insurer, and executive leadership — never with the person who found the note.
  • Don't announce prematurely. Statements made before scope is known are very hard to walk back, and regulators read them.
  • Don't let "it was only one laptop" close the question. One laptop is where scoping starts, not where it ends.

If you are unsure whether this counts as an incident, treat it as one. The cost of a two-hour scoping call that concludes with "you are fine" is trivial next to the cost of finding out in six weeks that you were not.


Our response

What happens when we join.

The sequence follows the NIST SP 800-61 incident handling lifecycle. It is deliberately unglamorous: scope before you act, contain before you clean, and never eradicate before you understand the whole footprint — because a partial eviction just tells the intruder you are watching.

Throughout, you get a single point of contact, a running timeline document, and a daily written situation report that your leadership and your insurer can both use.

Hour 0

Triage and stabilisation

A live call to establish what is known, what is assumed, and what is actually at risk. We give you immediate containment direction you can execute with the staff you have on hand while evidence collection is set up.

Evidence

Preservation and collection

Memory and disk images from affected hosts, log exports before retention windows expire, and cloud audit trails pulled with documented chain of custody — so the findings hold up if this ends in litigation or a claim.

Scope

Forensic analysis

Initial access vector, dwell time, lateral movement, persistence mechanisms, and — the question your regulator will ask first — whether data was staged or exfiltrated, and which data.

Eviction

Coordinated eradication

Every foothold closed in one coordinated action rather than piecemeal: credentials rotated, persistence removed, access paths severed, and the initial vector shut. Partial eradication is worse than none.

Return

Recovery and monitoring

Staged restoration to clean builds with heightened monitoring on the paths the intruder used, so a missed foothold surfaces immediately rather than next quarter.

After

Report and lessons learned

A written incident report suitable for your board, your insurer, and your regulator — followed by the remediation programme that stops the repeat. That work is described under post-incident resolution.

Before it happens

Response retainers.

The worst time to negotiate a contract is while your file servers are encrypting. A retainer puts the paperwork, the scope, and the escalation path in place in advance, so the first call is about your incident rather than about terms.

Terms agreed in advance

Master services agreement, NDA, data-handling requirements, and rates signed before anything happens — and an agreed response window written into the retainer rather than improvised on the day.

We already know your environment

A short onboarding captures your architecture, critical systems, logging coverage, and key contacts. On the day it matters, we are not starting from "what do you run?"

Unused hours aren't wasted

Retained hours you don't spend on an incident convert into proactive work — tabletop exercises, detection engineering, or an assessment — so a quiet year still returns something.

Many cyber insurance policies require you to use an approved incident response vendor, and some reduce coverage if you don't. Check your policy before you commit to any provider, including us — and if the policy names someone else, we will tell you so rather than let you jeopardise a claim.

Active incident intake

Report an incident.

Submissions flagged as an active incident are treated as an out-of-hours page, not an enquiry. Give us enough to call you back usefully — you do not need to have the full picture, that is the job.

Use a number that is not dependent on the affected network.

Sent over TLS to our intake system. Please don't paste passwords, keys, or ransom-note contact details into this form — we will arrange a secure channel on the callback.