← Solutions
CyberPopular

Emergency incident response and breach recovery

A CSIRT on call. When you are breached, one team takes the technical response, the crisis room and the legal exposure until you are clean and trading again.

Typical timing
Mobilised in hours, 4–12 weeks to close out
Engagement
Retainer with incident call-off
Delivery framework
User researchDiscoveryAlphaBetaLive

Stop the breach, prove the environment is clean and get the organisation trading again, while the same team runs the crisis room and the legal exposure. Called incident response, CERT or CSIRT depending on who you ask, it covers ransomware and extortion, data theft, malware, denial of service, business email compromise, account and brand takeover, and insider misconduct. One number to call, one commander, and a report at the end that a board, an insurer and a regulator can each rely on.

  • Ransomware, data theft or a fraudulent payment has just been discovered
  • An extortion demand has landed and nobody knows whether paying is even lawful
  • No retainer, no forensic capability, and a 72-hour notification clock running
How it runs

Activities, step by step

The plan follows our delivery framework. Steps that do not apply to this kind of work are left out rather than padded.

  1. 01 · User researchFirst 24 hours

    Hour one

    • Incident commander named, response bridge opened, crisis roles assigned
    • Evidence preserved before anything is rebooted, wiped or rebuilt
    • First containment call: what gets isolated, what keeps trading
  2. 02 · DiscoveryDays 1–7

    Investigate and contain

    • Forensic timeline: the way in, what was touched, what left the building
    • Threat actor identified and screened against UK and US sanctions lists
    • Attacker access cut — credentials, footholds and persistence removed
  3. 03 · AlphaDays 1–10, in parallel

    The crisis room

    • Executive decisions framed, costed and minuted as they are taken
    • ICO, customer, staff and press communications drafted and sequenced
    • Extortion handled under privilege, with sanctions, OFSI and payment advice
  4. 04 · BetaWeeks 2–4

    Recover and prove it clean

    • Rebuild from known-good, in a restore order the business agrees
    • Monitoring in place across the estate before anything returns to service
    • Return to service on evidence the environment is clean, not on hope
  5. 05 · LiveWeeks 4–12

    Close out and harden

    • Root cause report the board, the insurer and the regulator can each rely on
    • Remediation plan delivered, not merely recommended
    • Response plan rewritten and rehearsed against what actually happened

Retained clients get a named responder and an agreed callout time. We take emergency calls without a retainer, but mobilising takes longer and costs more, and the first hours are the ones that decide the rest.

Deliverables

What you keep at the end.

  • A named incident commander and a 24/7 response bridge
  • Forensic investigation report: timeline, root cause and data-loss assessment
  • Containment, eradication and recovery run through to return to service
  • Regulator notifications, and communications for customers, staff and press
  • Extortion negotiation, sanctions screening and payment handling where it is needed
  • Board and insurer close-out report with a costed remediation plan

Outcomes

What it is built to change.

  • The attacker out, with evidence that they are out
  • Trading again sooner, with less data lost and less money paid
  • Decisions that still stand up months later, to a regulator or an insurer