Emergency response
Incident Response: Containment, Investigation, and Recovery
If something is happening right now, start with the contact options directly below; you do not need to be an existing client. If nothing is happening yet, this is the page to read before it does.
Dealing with an incident right now
Ransomware, a compromised email account, a fraudulent payment, or something you cannot explain: reach us through whichever of these is fastest for you. Tell us what you are seeing and what you have already done. We accept engagements from organizations who are not existing clients.
Before you do anything else: disconnect affected systems from the network but leave them powered on, stop deleting or rebuilding anything, preserve your logs, move coordination off the potentially compromised environment, and notify your cyber insurer. The first three answers in the questions below explain why each of those matters.
What the first hours decide
Most of the damage is done by decisions made in a hurry
By the time an incident is visible, the attacker has usually been present for a while. What is still open to you is how much worse it gets: whether the intrusion spreads to systems that are still clean, whether you end up able to explain what happened, and whether the recovery leaves the original entry point closed.
The instinctive reactions are mostly wrong. Powering machines off destroys evidence held in memory. Rebuilding immediately erases the trail that would have shown how the attacker got in, and often restores the same weakness. Changing a password on a compromised mailbox without checking for forwarding rules and active session tokens can leave the attacker exactly where they were. Discussing the incident over the compromised email system tells them what you know.
Response is mostly a sequence: contain the spread, preserve evidence, establish scope, notify the parties you are obliged to notify, then recover into an environment where the original weakness is fixed. That order does not change under pressure, which is why having it written down in advance is worth more than almost anything else you can prepare.
The problem
The incidents organizations call us about
Different starting points, and largely the same first hour of work.
Ransomware
Files encrypted, a note left behind, and often exfiltration alongside the encryption so that paying resolves only half the problem.
Business email compromise
A mailbox is taken over, forwarding rules are created quietly, and the account is used to redirect a payment or reach your customers.
Fraudulent payment or wire
An invoice or bank detail was altered convincingly, money has moved, and speed determines whether any of it can be recalled.
Data exfiltration
Evidence that files left the environment, which converts a technical event into a contractual and regulatory notification question.
A confirmed intrusion of unknown scope
Something was clearly present on the network and nobody can yet say how far it reached or how long it has been there.
Insider or departing-employee incident
Data was accessed or removed by someone who had legitimate credentials, which needs care with both evidence and employment process.
Scope
What an incident response engagement covers
Scope depends entirely on what happened. These are the components; not every incident needs all of them.
Immediate triage
Establish what is actually happening, what is affected, and what the highest-value containment action is right now.
Containment
Isolate affected systems, disable compromised accounts, revoke active sessions and tokens, and cut off the attacker's access paths.
Evidence preservation
Capture and protect logs, endpoint telemetry, and system images before recovery work begins and before retention windows expire.
Scope and root-cause investigation
Determine how entry was gained, what was reached, whether data left the environment, and whether persistence remains.
Coordination with insurer and counsel
Work alongside your cyber insurer, appointed counsel, and any vendors your policy requires, supplying the technical facts they need.
Regulatory and contractual reporting support
Produce the timeline and technical detail your notification obligations depend on, including DFARS-driven reporting for defense suppliers.
Recovery and hardening
Restore into a secured environment with the entry point closed, rather than restoring the conditions that allowed the incident.
Post-incident review
A written account of what happened, what was done, what remains open, and the specific changes that reduce a repeat.
Our approach
How a response runs
The sequence rarely changes. What changes is how much of it a retainer has already settled in advance.
- 01
Engage
Establish contact, agree authorization and scope quickly, and identify who on your side can make decisions and grant access.
- 02
Contain and preserve
Stop the spread while capturing evidence, in that order and simultaneously where possible; recovery does not start here.
- 03
Investigate
Determine entry point, scope, dwell time, and whether data was taken, and give you facts your counsel and insurer can rely on.
- 04
Recover and review
Restore into a hardened environment, verify the attacker is gone, and document the incident and the changes that follow from it.
Business outcomes
What good response changes
Incidents cannot be undone. Their cost, duration, and consequences are substantially within your control.
The spread stops sooner
Early containment limits how many systems and accounts are affected, which is the single largest driver of total cost.
You can explain what happened
Preserved evidence supports a defensible account for your insurer, your regulator, your customers, and your board.
Notification obligations are met on time
A documented technical timeline is what short reporting deadlines, including 72-hour requirements, actually depend on.
Recovery does not restore the hole
Understanding the entry point before rebuilding prevents the second incident that follows a rushed restore.
Insurance coverage is protected
Prompt notice and cooperation with policy requirements keep a claim on solid ground rather than in dispute.
The next one is less likely
A post-incident review turns an expensive event into specific, prioritized changes rather than a general resolve to do better.
Fit
Who this is for
- Organizations currently experiencing a security incident, client or not
- Companies that want a retainer in place before an incident rather than during one
- Defense and federal suppliers with contractual incident-reporting obligations
- Organizations whose cyber insurance policy expects a defined response capability
- Businesses that have never written or rehearsed an incident response plan
- Companies recovering from an incident that was never properly investigated
When it may not be the right fit
We would rather tell you up front than sell you something that will not help.
- Ordinary IT outages with no security dimension: that is help desk and disaster recovery work, and it costs far less
- Organizations wanting a plan document written and filed, with no intention of testing or maintaining it
- Situations where litigation strategy is the primary driver, which counsel should direct with us supporting the technical work
- Anyone seeking a guaranteed response time or recovery outcome: we will not commit to numbers we cannot substantiate
Honest expectations during an incident
We do not publish a response-time guarantee. What we commit to is telling you plainly and immediately what we can start on, and when, including if the honest answer is that another responder can reach you sooner. During an incident, a realistic answer is worth considerably more than a reassuring one.
Some outcomes are not recoverable. Data that has been exfiltrated cannot be retrieved, encrypted data may be unrecoverable without a viable backup, and funds transferred fraudulently are often gone. Response limits harm, establishes the facts, and closes the path in. It does not undo what already happened, and any provider suggesting otherwise is not being straight with you.
Incident response frequently intersects with legal, insurance, and regulatory questions. We are not attorneys and nothing here is legal advice. Our role is to produce accurate technical facts and a defensible timeline, and to work alongside your counsel and insurer so their decisions rest on something reliable. For defense suppliers, note that DFARS-based reporting obligations can run to 72 hours from discovery; verify the specific clause in your own contracts.
Incident questions
What to do, and in what order
Will you help us if we are not already a client?
Yes. Organizations in the middle of an incident frequently have no existing relationship with anyone who can help, and turning them away because they did not buy a retainer last year serves nobody. Engaging without a retainer means the first hour is spent on scoping and authorization that a retainer would have settled in advance, so it is slower and it costs more, but it is a normal way for these engagements to start.
What should we do in the first hour, before anyone arrives?
Disconnect affected systems from the network but do not power them off, because shutting down destroys evidence held in memory. Do not delete anything, do not wipe or rebuild, and do not pay anything. Stop using the compromised email account rather than just changing its password, and check for mail-forwarding rules the attacker may have created. Preserve logs immediately, since default retention may be measured in days. Move coordination to a channel that does not depend on the potentially compromised environment, such as personal phones. Then notify your cyber insurer, because most policies require prompt notice and many direct which responders may be engaged.
Should we call our insurer before or after we call you?
Notify your insurer early, ideally in parallel. Most cyber policies require prompt notification and many restrict which vendors may be engaged or require pre-approval for response costs. Engaging responders your policy does not permit can put reimbursement at risk. We work alongside insurer-appointed counsel and vendors routinely, and if your policy directs the work elsewhere we will tell you that rather than compete with it.
What is an incident response retainer, and is it worth it?
A retainer settles in advance everything that otherwise consumes the first several hours: contract terms, authorization to access your systems, escalation contacts, containment authority, and a documented understanding of your environment. It typically also includes preparatory work: an incident response plan, a tabletop exercise, and confirmation that logging retention is long enough to investigate with. The value is not a discount on hours. It is that the clock starts on containment rather than on paperwork, and several insurers now ask whether one is in place.
Do we have to report a breach, and how quickly?
Frequently yes, and the timelines are shorter than people expect. Defense contractors subject to DFARS 252.204-7012 are generally required to report a cyber incident affecting covered systems within 72 hours of discovery. Healthcare, financial services, and most state breach-notification statutes impose their own obligations, and contracts often add customer-notification clauses. Which apply to you depends on your contracts, your sector, and where your affected individuals live, so this is a question for your counsel; we support it by producing the technical facts and timeline the notification depends on.
Should we just restore from backup and move on?
Restoring is part of recovery, but restoring first and investigating later is how organizations get compromised twice. If you rebuild without establishing how the attacker got in, you may restore the same weakness, or restore systems the attacker had already prepared for their return. It also destroys the evidence your insurer, your regulator, and your customers may later require. The right order is contain, preserve, understand the entry point, then recover into an environment where that entry point is closed.
Explore next
Related services
Managed Security Services
Detection and pre-authorized containment that shorten the time before a response even begins.
Learn moreBackup & Disaster Recovery
Isolated, tested recovery is what decides how a ransomware incident ends.
Learn moreSIEM & Security Monitoring
Retained, correlated logs are the raw material every investigation depends on.
Learn morePut the plan in place before you need it
A retainer settles authorization, contacts, and containment authority in advance, so an incident starts with containment rather than with paperwork. If you are dealing with something now, use the contact options at the top of this page.
