IT and cyber security incident response

Senior-led help with a cyber attack, an outage or data loss: assess the situation, prioritise containment and recovery, and record what happened. A named engineer coordinates the response and any supplier escalation within the agreed service scope.

General enquiries: Monday to Friday, 9am to 5.30pm. Existing clients should use their agreed incident contact route; availability and response targets follow the service agreement. New clients: call to check availability. The enquiry form is not an emergency response channel.

Verified
ISO 27001 & 9001Certified by a UKAS-accredited certification body Cyber Essentials & PlusCertification body NCSC AssuredCyber Advisor scheme CISSPHeld by Daniel McClure Fisher MCIISChartered Institute of Information Security, Full Member, held by Daniel McClure Fisher

What incident response is

Incident response is what happens on the worst day: the structured handling of a security breach, an outage or a data loss, to limit the damage, get you working again and learn from it. For managed clients, the engineers who run your systems are the ones who respond.

What we respond to

Not every emergency is a cyber attack. We respond across the situations that bring a business to a halt.

01Contain

Security incidents and cyber attacks

Ransomware, phishing and data breaches. We investigate the extent of the threat, take agreed containment steps and work through recovery and remediation.

RansomwarePhishingBreach containment
02Recover

Server failures and downtime

When a critical system goes down we diagnose the cause and recover the service, in an agreed priority order.

DiagnosisService recoveryContinuity
03Restore

Disaster and infrastructure failure

Power outages, hardware failures and network disruption. We work to failover plans, and help you build them so the next event hurts less.

FailoverRecovery plansInfrastructure
04Rebuild

Data loss and corruption

Accidental deletion, software failure or database corruption. We recover what can be recovered, rebuild safely, then check the backups will hold next time.

Data recoveryBackup restoreIntegrity checks

What happens when you call

Every minute and every decision counts, so the sequence is practised.

01

Take the call

We establish what is happening, confirm availability and scope, and assign an engineer to coordinate the response.

02

Contain

We prioritise limiting the spread, with affected systems isolated or compromised accounts locked down where appropriate.

03

Recover

We work to restore critical systems in priority order, using verified clean backups where available.

04

Report and harden

You get a clear account of what happened, what we did, and the changes that reduce the chance of it recurring. It sets out what to change, not who to blame.

Already in an incident? Call us now on 0118 359 2220. Existing clients should use their agreed incident contact route. New clients can call during our published enquiry hours to check availability. Do not rely on a website enquiry for an immediate response.

Who responds, and how

The hard part of an incident is rarely the technology. It is staying calm under pressure and owning the outcome rather than passing it around.

SeniorA senior engineer takes ownershipA named, experienced responder coordinates the agreed work.
One teamContext retainedFor supported systems, the response draws on the team and records already in place.
ClearA written accountWhat happened, what we did, and recommended changes to reduce recurrence.

Common questions

What is incident response?

Incident response is the structured handling of an IT or security event: a cyber attack, a breach, a major outage or data loss. The aim is to contain the damage, restore the business and learn from what happened. Once the engagement is accepted, a named engineer coordinates the agreed response, including supplier escalation where needed.

We think we are under attack right now. What should we do?

Call us on 0118 359 2220. If you can, disconnect affected machines from the network to limit the spread, but do not turn them off or delete anything: that destroys evidence and makes recovery harder. Do not pay a ransom before taking advice. Existing clients should follow their agreed incident contact route. New clients can call Monday to Friday, 9am to 5.30pm, to check availability; we will confirm what we can take on.

Do I need to be an existing client to get help in an incident?

Incident response is part of what we provide to our managed clients, and because we already know their systems we can move faster. If you are not a client, call us and we will tell you what we can do. Availability, hours and response targets are set out in your service agreement rather than promised on a web page.

What kinds of incident do you handle?

The full range that stops a business in its tracks: security incidents such as ransomware, phishing and data breaches; server failures and downtime; infrastructure events like power, hardware or network failure; and data loss or corruption. The common thread is an organised response that prioritises containment, recovery and a clear record of decisions.

What do we get after the incident is over?

A clear account of what happened, what we did to contain and recover, and the changes that reduce the chance of it recurring. Where you need it for an insurer, a regulator or your board, we produce the documented evidence they expect. The point is not blame; it is making sure the same gap does not catch you twice.

Talk to us about incident response

If you are in an incident now, call us. If you want to be ready before one happens, book a consultation and we will agree the plan, the scope and who to call while there is still time.

Reading, Berkshire  /  incident response for managed clients