Contained, investigated, documented
A retained team that answers when something has already gone wrong, with the forensic record your insurer and regulator will ask for.
The challenge
The worst time to find an incident response provider is during an incident. Without a retainer you are negotiating scope and rates while an attacker is still inside.
Scope — included and not included
Included
- Declared incident triage
- Containment guidance and actions
- Forensic timeline reconstruction
- Root cause analysis
- Post-incident report
- Regulatory notification support including Law 25
Not included
- Ransom negotiation
- Legal representation
- Rebuilding destroyed systems
- Data recovery from backups you do not have
- Anything outside the retained hours without a change order
How it works
01
Declare
You declare the incident through the agreed channel; the clock and the log start.
02
Triage and contain
Assess scope, stop the spread, record every decision.
03
Investigate
Forensic timeline and root cause, evidence preserved.
04
Report and improve
Post-incident report, lessons learned, notification support where required.
What you receive
- →Containment actions with a decision log
- →Forensic timeline
- →Root cause analysis
- →Post-incident report
- →Lessons learned session
- →Regulatory notification pack where applicable
What we need from you
- ·Pre-agreed contacts and authority to act
- ·Access provisioned in advance, not during the incident
- ·Asset and network documentation
- ·A declared escalation path
Timeline and engagement
Response begins within the tier commitment stated in your contract. Annual retainer.
Standards, methods and tooling
DFIR-IRISMITRE ATT&CKNIST SP 800-61Portal hosted in Canada
Frequently asked questions