[{"data":1,"prerenderedAt":235},["ShallowReactive",2],{"service-incident-response-en":3},{"doc":4},{"id":5,"title":6,"body":7,"description":203,"extension":204,"faq":205,"lastReviewed":227,"link":228,"meta":229,"navigation":230,"path":231,"seo":232,"stem":233,"__hash__":234},"servicesEn\u002Fservices\u002Fincident-response.md","Incident Response",{"type":8,"value":9,"toc":193},"minimark",[10,14,26,31,59,63,72,75,114,118,121,125,128,131,135,142,145,153,157,180],[11,12,13],"p",{},"Once an attacker is inside, every decision matters. Shutting down the wrong machine can hide where the attacker is moving. Rebooting a server can wipe the evidence in memory. Paying a ransom before you know the scope still leaves you unsure whether they are gone. We help you make those calls in the right order: stop the spread first, keep the traces that explain what happened, then remove the attacker.",[11,15,16,17,21,22,25],{},"We follow ",[18,19,20],"strong",{},"NIST SP 800-61"," and the ",[18,23,24],{},"SANS Incident Response Framework",", so every engagement goes through the same steps.",[27,28,30],"h2",{"id":29},"services","Services",[32,33,34,41,47,53],"ul",{},[35,36,37,40],"li",{},[18,38,39],{},"Emergency breach response",": Remote or on-site response to an active incident. A lead responder directs containment from the first call.",[35,42,43,46],{},[18,44,45],{},"Investigation & root cause",": We rebuild the timeline from logs and affected systems, analyse malware and persistence, and find the root cause. We only collect what is needed for that.",[35,48,49,52],{},[18,50,51],{},"Ransomware response",": Stop the encryption from spreading, assess what was affected, and harden systems against a repeat attack.",[35,54,55,58],{},[18,56,57],{},"Readiness & tabletop exercises",": Build your response plan and rehearse scenarios with your team.",[27,60,62],{"id":61},"how-we-respond","How we respond",[11,64,65,66,68,69,71],{},"We work through the six steps of the ",[18,67,24],{},". They map to the life cycle in ",[18,70,20],{},": Detect, Respond, and Recover during the incident, Govern, Identify, and Protect as preparation, and Improvement for lessons learned.",[73,74],"ir-lifecycle",{},[76,77,78,84,90,96,102,108],"ol",{},[35,79,80,83],{},[18,81,82],{},"Preparation"," (NIST: Govern, Identify, Protect): Set the response plan, roles, and escalation paths before an incident. Our readiness and tabletop exercises help with this.",[35,85,86,89],{},[18,87,88],{},"Identification"," (NIST: Detect): Confirm whether an alert is a real incident, then set its type and severity. Documentation starts here.",[35,91,92,95],{},[18,93,94],{},"Containment"," (NIST: Respond): Isolate affected systems to stop the spread, without wiping the traces that show how the attacker got in.",[35,97,98,101],{},[18,99,100],{},"Eradication"," (NIST: Respond): Remove malware, persistence, and compromised accounts, so the attacker does not come back with the restored systems.",[35,103,104,107],{},[18,105,106],{},"Recovery"," (NIST: Recover): Your team brings systems back online. We advise on the order and checks, and watch for signs of the attacker returning.",[35,109,110,113],{},[18,111,112],{},"Lessons Learned"," (NIST: Improvement): A written review of what happened, the root cause, and what to fix. The findings go back into preparation.",[27,115,117],{"id":116},"why-the-first-hours-matter","Why the first hours matter",[11,119,120],{},"You need to move fast, but not carelessly. Too slow, and the attacker spreads, takes data, or launches ransomware across more systems. Too hasty, and you lose the memory data, live connections, and logs that show how they got in and whether they are still there. A machine that has only been switched off can still carry the attacker's persistence. In the first hours we contain the spread while keeping enough of that record to decide what to rebuild, what to reset, and whether data left your network.",[27,122,124],{"id":123},"what-you-get","What you get",[11,126,127],{},"Our team works with your IT staff from the moment we are called in until the incident is under control. We keep management updated in plain language throughout, so they can decide on systems, customers, and communications based on facts.",[11,129,130],{},"At the end you receive a written report covering what happened and how far it spread. It includes a forensic timeline of how the attacker got in and what they accessed, the root cause, indicators of compromise (IOCs) your monitoring can use to spot the same activity, and hardening recommendations. After your team applies the fixes, we check them.",[27,132,134],{"id":133},"team-credentials","Team credentials",[11,136,137,138,141],{},"Our in-house team holds incident-response certifications including ",[18,139,140],{},"GCIH, GCIA, GCFA, and eCDFP",": GIAC Certified Incident Handler, Certified Intrusion Analyst, and Certified Forensic Analyst, plus the eLearnSecurity Certified Digital Forensics Professional. The same people run our penetration tests, so they know how attackers move and where they hide.",[143,144],"ir-certs",{},[11,146,147,152],{},[148,149,151],"a",{"href":150},"\u002Fcertifications","See all certifications held by the team",".",[27,154,156],{"id":155},"standards-methodology","Standards & methodology",[11,158,16,159,167,168,172,173,179],{},[148,160,164],{"href":161,"rel":162},"https:\u002F\u002Fcsrc.nist.gov\u002Fprojects\u002Fincident-response",[163],"nofollow",[18,165,166],{},"NIST SP 800-61 Revision 3"," (",[169,170,171],"em",{},"Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile",", April 2025), which replaces Revision 2, and the six-step ",[148,174,177],{"href":175,"rel":176},"https:\u002F\u002Fwww.sans.org\u002Fsecurity-resources\u002Fglossary-of-terms\u002Fincident-response",[163],[18,178,24],{},". We collect only the evidence needed to contain the incident, find the root cause, and prevent a repeat. If you have specific reporting requirements, tell us at the start.",[11,181,182,183,187,188,192],{},"Incident response covers what happens after an attacker gets in. A ",[148,184,186],{"href":185},"\u002Fpenetration-test","penetration test"," finds weaknesses before they are exploited, and ",[148,189,191],{"href":190},"\u002Fred-teaming","red teaming"," tests whether your team would notice an intruder.",{"title":194,"searchDepth":195,"depth":195,"links":196},"",2,[197,198,199,200,201,202],{"id":29,"depth":195,"text":30},{"id":61,"depth":195,"text":62},{"id":116,"depth":195,"text":117},{"id":123,"depth":195,"text":124},{"id":133,"depth":195,"text":134},{"id":155,"depth":195,"text":156},"Incident response in Thailand. Ransomware and data breach containment by a CREST\u002FOSCP-certified team, following NIST SP 800-61. Emergency response, investigation, and tabletop exercises. Book a readiness call.","md",[206,209,212,215,218,221,224],{"q":207,"a":208},"What is incident response?","The process of detecting an attack, stopping it, removing the attacker, getting back to normal operation, and learning from what happened. We follow NIST SP 800-61 and the SANS Incident Response Framework.",{"q":210,"a":211},"How is incident response different from a penetration test?","A penetration test looks for weaknesses before an attacker finds them. Incident response starts after an attacker is already in: stop the damage, remove them, and close the way they came in. Many organisations use both.",{"q":213,"a":214},"How fast should an organisation respond to an incident, and is there a standard?","There is no single response time that fits every incident. NIST SP 800-61 does not set time limits; it asks organisations to rank incidents by severity and handle the most serious first. An attack that is still spreading, such as ransomware, needs action immediately. A malware alert that is already contained can wait for working hours. Notification deadlines set by regulators or insurers are often the real constraint, so plan your internal targets around them. When you contact us, we agree the response timing based on how severe the incident is.",{"q":216,"a":217},"What types of incidents do you handle?","Ransomware, data breaches, insider threats, malware outbreaks, and system intrusions. For ransomware, we stop the spread, check what was affected, and harden the environment so the same attack does not work again.",{"q":219,"a":220},"Can you find out how the attacker got in?","Yes. We trace the attacker's activity in logs and on affected systems to see how they got in, what they accessed, and where they left a foothold, then find the root cause so it can be fixed. We only collect what we need for that, not a full evidence archive.",{"q":222,"a":223},"What do we receive at the end of an engagement?","A written report: an executive summary, a timeline of the incident, the root cause, indicators of compromise (IOCs), and hardening recommendations. After your team applies the fixes, we check them.",{"q":225,"a":226},"Can you help us meet breach reporting timelines?","Yes. We help you establish quickly what happened, which data was affected, and the likely impact, and we prepare the documents you need for regulators, insurers, and affected parties. We work with your legal counsel on this.","2026-10-08","\u002Fincident-response",{},true,"\u002Fservices\u002Fincident-response",{"title":6,"description":203},"services\u002Fincident-response","80E5Pw1UqTKv4uR2_AGOOr6fCUoJX6JQ2bz6k98QZ6g",1791475010299]