We help organise response to a suspected or confirmed incident. Affected assets and available evidence inform containment actions balanced against business continuity.
Recovery follows checks of selected sources and remediation of known causes. Actions are recorded and recommendations prepared; investigation depth depends on available logs, system condition and when assistance begins.
Incident response and recovery
Who it is for
- Companies facing suspicious activity, compromise or system disruption
Incident response and recovery
Challenges we address
- The incident scope and safe recovery sequence are unclear
Incident response and recovery
What is included
- Initial assessment and containment planning
- Event collection and affected-system analysis
- Recovery and recurrence reduction measures
Incident response and recovery
What you receive
- Incident timeline and action record
- Recovery plan and recommendation report
How we work
- 01
Discovery and scope
We assess the current environment, requirements and constraints. Priorities include: The incident scope and safe recovery sequence are unclear. We agree on scope and acceptance criteria.
- 02
Design and implementation
We design the solution and carry out agreed activities: Initial assessment and containment planning; Event collection and affected-system analysis; Recovery and recurrence reduction measures. Changes are checked before entering the production environment.
- 03
Validation and handover
We validate agreed scenarios, record limitations and hand over documentation. Project timing follows discovery; support hours and response targets are defined in a separate agreement.
How pricing works
Costs depend on scope, urgency, available evidence, system count and agreed working coverage.
Get a consultationCommon questions
Should all servers be reinstalled immediately?
That depends on the situation. Reinstallation may destroy evidence needed for analysis; data preservation, containment and recovery priorities should be agreed first.