Incident Response
Detect, contain, investigate and recover — without destroying the evidence you will need later.
Overview
When an incident is suspected, the priority is to preserve evidence while establishing scope, entry point, attacker activity and exposed data.
The investigation turns a live incident into a defensible sequence of events. Containment and evidence preservation run in parallel, so the decisions taken in the first hours do not destroy the record needed later by counsel, insurers or a regulator.
Engagements are modular. A compromise assessment, a full breach investigation and a post-incident root cause review can be scoped independently or run as one mandate.
Key outputs
- Incident timeline and attack path
- Indicators of compromise (IOCs)
- Affected systems and exposed data
- Root cause and prioritised remediation actions
- Executive-ready findings for board and regulator
Incident response playbook
Four movements, run in order, with evidence preserved at every step.
Identify
Validate the alert and establish scope. Incident triage, confirmation and initial exposure assessment.
Contain
Isolate affected assets while preserving volatile and stored evidence.
Investigate
Correlate evidence across logs, artefacts and communications to reconstruct the attack.
Recover
Remediate, monitor and verify that the entry point is closed.
Investigation workstreams
The four capabilities the deck sets out, run individually or together depending on what the matter requires.
Incident Response & Breach Investigation
- Incident triage and identification
- Containment and evidence preservation
- Attack vector and entry-point analysis
- IOC identification and threat hunting
- Compromise and data-exposure assessment
- Timeline reconstruction
- Root cause analysis
- Remediation recommendations
Dark Web Monitoring & Threat Intelligence
- Corporate credential monitoring
- Domain and brand exposure monitoring
- Leaked data identification
- Threat-actor and alias profiling
- Marketplace and forum monitoring
- Compromised account detection
- Intelligence correlation and validation
- Early-warning alerts and reporting
Server Forensics & Log Investigation
- Server image acquisition and preservation
- Windows / Linux artefact analysis
- Authentication and event-log analysis
- Web, application and database logs
- Unauthorised access investigation
- Malware and persistence detection
- File-system and deleted-data recovery
- Attack timeline reconstruction
Root Cause & Post-Incident Analysis
- Attack-chain reconstruction
- Event and evidence correlation
- Control-gap identification
- Root cause determination
- Impact and exposure assessment
- Lessons learned
- Remediation roadmap
- Forensic reporting
Investigate. Correlate. Attribute. Remediate.
A structured forensic approach connects incident response, underground intelligence, server evidence and root-cause analysis to establish what happened, how it happened and what must change.
Outcome: defensible findings and an actionable remediation roadmap.
Incident
Detect and contain
Dark Web
Monitor and validate
Server
Acquire and examine
Root Cause
Correlate and remediate
From evidence to remediation
Post-incident analysis moves the question from “what happened?” to “why did it happen?” — and then to what changes.
Evidence
Logs, artefacts and communications, preserved and indexed.
Correlation
Timeline, IOCs and attack chain assembled from the record.
Root Cause
Control gaps and entry point identified and evidenced.
Action
Remediation and monitoring, prioritised by exposure.
Related Capabilities
Forensics sits inside a wider integrity and risk practice.
