IT and cyber security incident response

When something goes wrong, a ransomware attack, a breach, a server down, a senior responder takes control, contains the situation, restores the business, and gives you a clear account of what happened and how to stop it recurring. One engineer owns the incident from the first call to the write-up.

Verified
ISO 27001 & 9001Certified by a UKAS-accredited certification body Cyber EssentialsCertification body NCSC AssuredCyber Advisor CISSPHeld by Daniel McClure Fisher MCIISChartered Institute of Information Security, Full Member, held by Daniel McClure Fisher
Incident response / 01 · What it is

What incident response is

Incident response is what happens on the worst day: the structured handling of a security breach, an outage or a data loss, to limit the damage, get you working again and learn from it. For managed clients, the engineers who run your systems are the ones who respond.

Incident response / 02 · What we handle

What we respond to

Not every emergency is a cyber attack. We respond across the situations that bring a business to a halt.

01Contain

Security incidents and cyber attacks

Ransomware, phishing and data breaches. We contain the threat, work out how far it reached, restore what was hit and close the gap.

RansomwarePhishingBreach containment
02Recover

Server failures and downtime

When a critical system goes down we diagnose the cause and recover the service, in an agreed priority order.

DiagnosisService recoveryContinuity
03Restore

Disaster and infrastructure failure

Power outages, hardware failures and network disruption. We work to failover plans, and help you build them so the next event hurts less.

FailoverRecovery plansInfrastructure
04Rebuild

Data loss and corruption

Accidental deletion, software failure or database corruption. We recover what can be recovered, rebuild safely, then check the backups will hold next time.

Data recoveryBackup restoreIntegrity checks
Incident response / 03 · What happens

What happens when you call

Every minute and every decision counts, so the sequence is practised.

01

Take the call

You reach a senior engineer who takes ownership straight away, and we establish what is happening and what is at stake.

02

Contain

We stop the spread first: affected systems isolated, compromised accounts locked down.

03

Recover

Critical systems come back in priority order, restored from clean backups where needed.

04

Report and harden

You get a clear account of what happened, what we did, and the changes that stop it recurring. It sets out what to change, not who to blame.

Already in an incident? Call us now on 0118 359 2220. Incident response is available to our managed clients; if you are not a client, call anyway. Do not wait to read the rest of this page.
Incident response / 04 · The difference

Who responds, and how

The hard part of an incident is rarely the technology. It is staying calm under pressure and owning the outcome rather than passing it around.

SeniorA senior engineer takes ownershipA calm, experienced responder owns the incident from the first call.
One teamNo handover, no gapThe people who run your systems are the people who respond.
ClearA written accountWhat happened, what we did, and what stops it happening again.
FAQ

Common questions

What is incident response?

Incident response is the structured handling of an IT or security event: a cyber attack, a breach, a major outage or data loss. The aim is to contain the damage, restore the business and learn from what happened. With us, a senior engineer takes ownership from the first call and owns it through to resolution.

We think we are under attack right now. What should we do?

Call us on 0118 359 2220. If you can, disconnect affected machines from the network to limit the spread, but do not turn them off or delete anything: that destroys evidence and makes recovery harder. Do not pay a ransom before taking advice. For managed clients we take ownership from that call. If you are not a client, call anyway and we will tell you what we can do.

Do I need to be an existing client to get help in an incident?

Incident response is part of what we provide to our managed clients, and because we already know their systems we can move faster. If you are not a client, call us and we will tell you what we can do. Availability, hours and response targets are set out in your service agreement rather than promised on a web page.

What kinds of incident do you handle?

The full range that stops a business in its tracks: security incidents such as ransomware, phishing and data breaches; server failures and downtime; infrastructure events like power, hardware or network failure; and data loss or corruption. The common thread is a senior response that contains the problem and gets you working again.

What do we get after the incident is over?

A clear account of what happened, what we did to contain and recover, and the changes that reduce the chance of it recurring. Where you need it for an insurer, a regulator or your board, we produce the documented evidence they expect. The point is not blame; it is making sure the same gap does not catch you twice.

Talk to us about incident response

If you are in an incident now, call us. If you want to be ready before one happens, book a consultation and we will agree the plan, the scope and who to call while there is still time.

Reading, Berkshire  /  incident response for managed clients