Service
Incident Response & Digital Forensics
Emergency containment, forensic investigation and recovery — with a one-hour response SLA for retainer clients and a hotline that a human answers.
The first six hours decide how much of an incident becomes a crisis. Our responders have handled ransomware in manufacturing plants, business email compromise in law firms, and insider data theft in fintech.
Contain, investigate, recover
We stabilise first — isolating affected systems and cutting attacker access — then run a full forensic investigation to establish root cause, dwell time and data impact. Recovery runs in parallel, with rebuild guidance that does not reintroduce the original weakness.
Evidence that stands up
Investigations are conducted to an evidentiary standard with documented chain of custody, suitable for regulators, insurers and legal proceedings.
What the engagement covers
What you receive
- 01 Incident timeline and root-cause analysis
- 02 Forensic report to evidentiary standard
- 03 Data impact and notification assessment
- 04 Recovery and hardening plan
- 05 Lessons-learned workshop
Often combined with
Next step
Find out what an attacker sees before they show you.
Book a scoping call with a senior consultant. No sales engineer, no slide deck — a technical conversation about your actual exposure.