Talk with an Expert

Incident Response & Forensics

Containment, investigation, recovery and executive decision support when an incident threatens operations.

When an incident is live the hard part is rarely the technology. It is deciding what to shut down, what to say, who to notify and in what order, while the picture is still incomplete. We run the containment and the forensics, and we sit with the people making those calls. Readiness work uses the same material in advance, so the first time your executives rehearse a crisis is not during one.

Capabilities

What the work actually is. Scoped to the parts of it you need, at the depth the estate calls for.

Live response

  • Rapid containment, investigation coordination, eradication support and restoration planning.
  • Evidence preservation, log review, timeline reconstruction and malware analysis coordination.
  • Legally aware reporting, written so it survives later scrutiny.
  • Decision support for containment, communication, regulatory coordination and stakeholder management.

Readiness

  • Scenario-based exercises for incident response, decision-making and communications.
  • Legal, security operations and business continuity coordination rehearsed together, not separately.
  • Executive drills covering accountability, disclosure and the calls only leadership can make.
  • Post-exercise improvement actions with owners and dates.
Business outcome

Faster containment, clearer responsibility during the event, less operational disruption, and a defensible account afterwards, for the board, the regulator, the insurer and the customers who will ask.

Deliverables

What you actually get. Scoped up front, priced fixed, and delivered by the people who scoped it.

  • 01

    Incident response summary

  • 02

    Forensic findings and evidence timeline

  • 03

    Containment and recovery recommendations

  • 04

    Root cause and contributing factors analysis

  • 05

    Post-incident improvement roadmap

  • 06

    Crisis management or tabletop exercise report

How it runs

Four phases, agreed up front. The arc this practice follows, from the scoping call to the check that it held.

01
First hour
Incident scope, urgency, affected systems, business impact and the decisions that cannot wait are established on the first call.
02
Contain and preserve
Containment and evidence preservation run together, and the second one is what keeps the insurer, the regulator and any later litigation answerable.
03
Investigate
Logs, artifacts, timelines, attacker activity and recovery dependencies are analyzed into an account of what happened, how far it got and what it touched.
04
Recover and improve
Recovery planning is supported through to service restoration, and the post-incident actions become work with owners and dates attached.

Talk with an Expert.

Tell us about your organization and the challenge you are facing. Our consultants will shape the right cybersecurity approach.