Emergency incident response — live intake, 24/7
Under attack right now?
Message the on-call line first, then read the checklist below while you wait. Do not start rebuilding — that destroys the evidence we need to establish scope.
Assured response
4 hours
From first contact, any hour, any day. Remote acquisition starts immediately.
While you wait
Do
- Preserve the affected systems in place — leave them powered on if you can.
- Write down what you have already observed, and when.
- Note any changes your team has already made to the environment.
- Identify who has domain and cloud tenant admin, and keep them reachable.
- Move incident coordination to an out-of-band channel.
Do not
- Do not rebuild or reimage — it destroys the evidence needed to establish scope.
- Do not delete suspicious files, accounts or mailbox rules.
- Do not pay or negotiate before we have established scope.
- Do not rotate every credential at once before containment is planned.
- Do not announce externally before the facts are confirmed.
How the engagement runs
Detect, contain, eradicate, recover — reconstructing the attack path as we go rather than reporting on it afterwards.
Hour 0–4
Intake and acquisition
First contact starts the clock. We begin remote volatile-memory capture and forensic acquisition immediately, because the evidence that answers the hardest questions is the evidence that disappears first.
Day 1
Containment
Containment executed alongside your team, planned against what we already know about the actor rather than against the symptom that tripped the alert.
Days 1–5
Attack-chain reconstruction
We reconstruct the full path — entry, credentials taken, lateral movement, what was touched — as we go, rather than reporting on it afterwards.
Recovery
Eradication and hand-back
We stay through eradication and restoration, verify the access path is genuinely closed, and hand you a report your board, insurer and regulator can all read.
What we will ask you for
- A single point of contact with authority to approve containment actions.
- Read access to your EDR, SIEM and identity provider, or someone who has it on the call.
- Network diagrams and asset inventory, however imperfect.
- The timeline of what has happened so far, in your own words.
Who to loop in
We are used to working under counsel direction and to producing reporting that meets insurer and regulatory evidentiary expectations.
- External counsel — we are used to working under their direction.
- Your cyber insurer, before remediation spend starts.
- Regulators or the national cyber directorate, where notification applies.