Incident response & digital forensics

Contain the threat. Restore operations.

Incident leadership, digital forensics, containment, and recovery—on demand or through a retainer with defined response commitments. Establish response access before you need it.

Incident support

Start with what you know.

You do not need a complete picture to start a conversation. Tell us what is affected, the operational impact, and what your team has done so far.

Contact our response team

For the first conversation

  • Environment: affected systems, accounts, and services.
  • Impact: what is disrupted and what needs to keep operating.
  • Actions: response work already underway and a point of contact.

Keep credentials, logs, and sensitive evidence out of the initial web inquiry. If you have a response agreement with us, follow its activation process.

What we help you handle

Investigate the intrusion. Protect the mission.

Forensic evidence, cross-source telemetry, and incident leadership connect the initial signal to containment decisions and staged recovery.

Response 01

Ransomware & extortion

Contain the intrusion, reconstruct attacker activity, and plan staged restoration. Preserve evidence while identifying affected systems and the operational priorities for recovery.

  • Containment
  • Forensic reconstruction
  • Staged restoration

Response 02

Identity & cloud compromise

Investigate token abuse, compromised identities, and persistence in cloud environments. Trace the control failures that allowed access and coordinate containment with your operators.

  • Token abuse
  • Persistence
  • Control-failure investigation

Response 03

SIEM, EDR & telemetry

Correlate endpoint, identity, cloud, and network evidence to map attacker actions and impact. Build the incident timeline and investigate activity beyond the initial alert.

  • Cross-source correlation
  • Incident timeline
  • Impact analysis

Response 04

Recovery & hardening

Plan the restoration of affected services, verify recovery checkpoints, and address the weaknesses that enabled the incident. Turn findings into engineering work your team can sustain.

  • Recovery validation
  • Identity & segmentation
  • Detection improvements

How we respond

From activation to recovery.

The work is not a rigid sequence. Evidence collection, containment, and recovery often overlap. Your team retains authority over changes to its systems.

  1. 01

    Activate & triage

    Agree on authority, affected systems, operational priorities, and evidence handling. Set the response roles and decision cadence.

    Outcome: Scope, priorities, and response owners.

  2. 02

    Analyze & contain

    Reconstruct attacker activity while limiting access. Investigation and containment run together as the evidence develops.

    Outcome: Incident timeline and containment actions.

  3. 03

    Eradicate & recover

    Remove persistence, address compromised access, and restore services in stages. Validate the changes and hand off remaining remediation priorities.

    Outcome: Validated recovery and remediation priorities.

Response access & retainers

Expert response. In place before you need it.

Every option includes 24×7 incident intake. Choose on-demand access or a retainer with defined response commitments and readiness support.

IR On-Demand

Best-effort response, subject to availability. The 8-hour target is not an SLA.

Request support
Incident intake
24×7
Best-effort response target
8 hours
No response-time commitment
No SLA

Includes

  • Direct path to request incident response support

IR Access

Defined response commitments and essential readiness support.

Discuss IR Access
Human acknowledgment
1 hour
Remote response begins
4 hours
Included response / readiness
15 hours

Includes

  • Contact onboarding
  • Annual activation test

IR Standard

Recommended

Faster acknowledgment, more included hours, and response plan review.

Discuss IR Standard
Human acknowledgment
30 min
Remote response begins
4 hours
Included response / readiness
30 hours

Includes

  • Onboarding and escalation matrix
  • IR plan / playbook review

IR Priority

Reserved senior capacity and ongoing readiness support.

Discuss IR Priority
Human acknowledgment
15 min
Remote response begins
2 hours
Included response / readiness
40 hours

Includes

  • Senior incident lead
  • Annual tabletop
  • Quarterly readiness check-ins

Activation matters. Retainer commitments begin after confirmed activation by an authorized customer contact. Dependencies, exclusions, and remedies are governed by the executed service schedule.

Use included hours for response or readiness. Establish contacts, test activation, and prepare your team before an incident. The selected option determines the included readiness support.

The handoff

A record your team can act on.

Technical findings and clear decisions for the people responsible for recovery, risk, and ongoing operations.

Explore engineering
Incident timeline
A reconstruction of observed activity, affected systems, supporting evidence, and gaps that remain unresolved.
Response record
Containment and recovery actions, key decisions, validation results, and residual risks for the operating team.
Remediation plan
Prioritized control improvements, engineering work, and retest criteria informed by the incident findings.

Working with us

Before we begin.

Explore security readiness
How does On-Demand differ from a retainer?

Every option includes 24×7 incident intake. IR On-Demand has an 8-hour best-effort response target, subject to availability, with no response-time SLA. IR Access, IR Standard, and IR Priority add defined acknowledgment and remote-response commitments, included hours, and readiness support.

When do retainer response commitments begin?

Commitments begin after confirmed activation by an authorized customer contact. Human acknowledgment and the start of remote response are separate commitments. Dependencies, exclusions, and remedies are governed by the executed service schedule.

Can included hours be used before an incident?

Yes. Included retainer hours may be used for incident response or readiness support. Depending on the option, readiness work includes activation testing, escalation planning, IR plan and playbook review, tabletop exercises, or quarterly readiness check-ins.

Can you join a response already underway?

Yes. We can work alongside your security team, IT operators, and existing providers. We agree on responsibilities, authorization, and evidence-sharing arrangements before taking response actions.

What should we share in an initial inquiry?

Start with your contact details, a high-level description of the affected environment, operational impact, and actions already taken. Do not send credentials, logs, customer data, or sensitive evidence through the initial web inquiry. We can agree on an appropriate exchange method after contact.