Skip to content
Process

Our five-phase incident response process

Every engagement follows the same disciplined, containment-first workflow. It protects evidence, restores operations, and closes the gaps that let the incident happen.

Response Process

A disciplined path from chaos to control

A containment-first workflow that protects evidence, restores operations, and reduces the chance of recurrence.

  1. 01

    Triage

    Rapidly establish scope, severity, and business impact to direct the response.

  2. 02

    Contain

    Stop active spread and cut off attacker access while preserving evidence.

  3. 03

    Investigate

    Reconstruct the timeline and determine root cause through digital forensics.

  4. 04

    Eradicate

    Remove footholds, persistence, and compromised credentials across the estate.

  5. 05

    Recover & Harden

    Restore operations safely and close the gaps that enabled the incident.

Phase by Phase

What happens inside each phase

The same five phases govern a ransomware outbreak and a quiet mailbox compromise — only the tempo changes.

01 · Triage
We establish what is known, what is assumed, and what is at stake: affected systems, data exposure, business impact, and regulatory clock. Severity is set with an explainable rationale, and the response is sized to match — no over-mobilization, no dangerous delay.
02 · Contain
Active spread is stopped and attacker access is cut — isolating systems, revoking sessions and credentials, and blocking command-and-control — always in an order that preserves evidence. Containment that destroys the timeline is a second incident.
03 · Investigate
Forensic analysis reconstructs the attack end to end: initial access, lateral movement, privilege escalation, and data touched. AI-assisted correlation compresses days of log work into hours; responders validate every finding before it drives a decision.
04 · Eradicate
Footholds, persistence mechanisms, malicious accounts, and compromised credentials are removed across the estate in a coordinated pass. Partial eviction teaches the attacker; complete eviction removes them.
05 · Recover & Harden
Systems return to service against verified-clean baselines, monitoring is tuned to catch any return, and the root-cause gaps are closed with a prioritized hardening plan. The engagement ends with an executive report your board, insurer, and regulator can use.

Facing an incident right now?

Engage a responder in minutes with a fixed fee, or start a conversation about readiness before you need us.