Cyber Response Systems Services

Incident recovery

Containment, forensics, and a clean rebuild. We document what happened in language your insurer and your board can both read.

In the middle of one right now?

Call +1 555 0100 and press 9. Do not switch machines off, do not start restoring backups, and do not pay anything yet. Unplug the network cable and leave the rest until we have spoken.

The first seventy-two hours

Every incident is different in its details and the same in its shape. This is the order we work in, and roughly how long each part takes for an office of twenty to fifty people.

  1. Hour 0 to 2

    Contain

    Isolate affected machines, disable compromised accounts, block the attacker's route out. Nothing is wiped. Evidence is worth more than tidiness at this point.

  2. Hour 2 to 24

    Understand

    How they got in, how long they were there, what they touched. This decides whether you have a notification duty, and it is the first thing your insurer will ask.

  3. Day 1 to 3

    Rebuild

    Clean machines from known-good images, data restored from backups we have verified predate the intrusion, every credential rotated. Staff back at work in priority order.

  4. Week 2

    Report

    A written account: timeline, root cause, what was and was not accessed, and the specific changes that would have prevented it.

What you get at the end

DocumentWho it is forLength
Incident summaryDirectors, staff, clients if neededOne page
Technical timelineInsurer, legal counsel, regulatorsTen to twenty pages
Remediation planWhoever holds the budgetA prioritized list with costs

The report was the first time anyone had explained our own network to us. We used it as the IT plan for the following year.

Operations director, regional logistics firm
Cyber Response Systems

Managed detection and response for organizations too small to staff a security desk and too important to go without one.

Get in touch

hello@example.com
+1 555 0100
Mon–Fri, 8am–6pm