Response
Incident Response
Help when something has already happened, and arrangements made before it does
There are two ways people arrive here. Something has happened and you need help now. Or nothing has happened yet and you want to know who to call before it does. The second position is significantly better, and considerably cheaper.
What incident response involves
Response work generally moves through containment, investigation, eradication, and recovery. Containment stops the situation getting worse — isolating affected systems, revoking credentials, cutting attacker access. Investigation establishes what happened, when it started, what was accessed, and whether data left the environment. Eradication removes attacker persistence. Recovery restores operations with confidence that the problem has not been restored alongside them. Running through all of it is evidence handling. Decisions made in the first hours determine whether you can later answer the questions that matter — to a regulator, an insurer, a customer, or a court. Wiping and rebuilding a compromised machine feels decisive and destroys the evidence you will need. Regulatory timelines apply in parallel. UK GDPR requires notification to the ICO within 72 hours of becoming aware of a qualifying personal data breach. That clock runs whether or not you have finished investigating.
Who needs it
- Organisations dealing with an active incident — ransomware, business email compromise, suspected intrusion
- Businesses that want a responder identified and contracted in advance rather than sourced under pressure
- Companies whose cyber insurance requires a named response provider
- Teams that have had an incident and want an independent review of what happened and what to change
What you get
Fast matching during an active incident
Connection to responders with current capacity and relevant experience. During an incident, availability matters as much as capability.
Retainer arrangements before you need them
A pre-agreed retainer means contracting, scoping, and access arrangements are already settled — so response starts immediately rather than after procurement.
Awareness of parallel obligations
Technical response runs alongside regulatory notification, insurer notification, and legal advice. We flag where those need to run in parallel.
Frequently asked questions
What should we do first if we think we have been breached?
Preserve evidence and avoid destroying it. Isolate affected systems from the network rather than powering them off — memory contents are often critical to the investigation. Do not wipe or rebuild anything yet. Do not communicate with an attacker without advice. Start an accurate timeline of what you observed and when. Then get specialist help involved quickly.
Should we tell the ICO?
Under UK GDPR, a personal data breach that poses a risk to individuals must be reported to the ICO within 72 hours of your becoming aware of it. The 72 hours runs from awareness, not from having full facts, and partial reporting followed by an update is expected. Whether a specific incident meets the threshold is a decision to take with legal advice — this is general information, not a legal determination.
What is an incident response retainer and is it worth it?
A retainer is a pre-agreed arrangement with a response firm: contract signed, access arrangements understood, response commitment defined, before anything happens. The value is time. Sourcing, contracting, and briefing a responder from scratch during an active incident routinely costs a day or more, which is exactly when time is most expensive. Many retainers also include unused hours toward proactive work.
Will our cyber insurance cover this?
Frequently yes, but policies commonly require you to notify the insurer before engaging a responder, and some mandate providers from a panel. Engaging your own firm first can jeopardise the claim. Check your policy wording now rather than during an incident — and if you already have a preferred responder, confirm the insurer will accept them.