Incident Response

Urgent technical containment, investigation and recovery support when a cyber security incident is suspected or confirmed.

Incident Response

Rapid technical triage

Threat containment

U

Evidence-led investigation

Recovery coordination

When an Incident Is Active, Speed and Clear Decisions Matter

Ransomware, compromised accounts, malicious email and unauthorised access can spread quickly. ITFR helps establish what happened, contain active threats and coordinate technical recovery while preserving useful evidence and keeping business priorities visible.

Initial triage
Establish the suspected incident, affected services, immediate risk and required specialists.

Containment
Isolate affected systems, disable compromised accounts and limit further attacker activity.

Investigation
Review available logs, alerts, devices and account activity to determine scope and likely cause.

Eradication
Remove malicious access, persistence, compromised credentials and unsafe configurations.

Recovery
Restore systems and services carefully, validate operation and monitor for recurrence.

Incident documentation
Record evidence, decisions, actions, impact and improvements for management, insurers and advisers.

The result: a structured technical response that limits damage, supports recovery and creates a clearer path for legal, insurance and business decisions.

Benefits at a glance

Faster Containment

Take practical action to stop active compromise and reduce further spread.

Clearer Scope

Identify affected users, systems, information and likely attacker activity.

Safer Recovery

Restore services carefully and address the cause before returning to normal operation.

Useful Evidence

Document findings and actions for leadership, insurers, legal advisers and regulators.
SECURE IT · INCIDENT RESPONSE

Choose the Right Incident Response Access

Use emergency assistance for an active incident or establish a retainer so contacts, access and response capacity are agreed before an event.

Emergency Incident Response

Time & Materials

subject to availability and scope

Urgent technical help for suspected or confirmed compromise

For organisations dealing with ransomware, account takeover, malicious access or another active cyber security event.

Rapid Triage & Severity Assessment
Confirm the concern, immediate risk, affected services and next response actions.

Technical Containment
Isolate systems, disable accounts and block active attack paths where possible.

Evidence Collection
Preserve available logs, alerts, devices and records needed for investigation.

Incident Investigation
Determine affected systems, users, activity, likely entry point and persistence.

Recovery Coordination
Support restoration, credential resets, validation and heightened monitoring.

Incident Report & Improvement Actions
Document findings, decisions, response work and priority control improvements.

 

BEST FOR
Businesses that need immediate technical assistance with an active or suspected cyber security incident.

Incident Response Retainer

10 Response Hours

subject to availability and scope

Pre-agreed access to incident response support

For organisations that want response contacts, access preparation and technical capacity arranged before an incident occurs.

Response Onboarding
Confirm contacts, escalation, authority, environment and relevant third parties.

Ten Included Response Hours
Use the included technical response allocation when an incident occurs.

Priority Response Access
Use the agreed escalation path and response process, subject to the retainer terms.

Environment & Evidence Readiness
Identify essential access, logging, security tools and recovery dependencies.

Incident Coordination Support
Work with leadership, insurers, legal advisers and other specialists as authorised.

Additional Hours at Agreed Rates
Continue investigation, containment and recovery beyond the included allocation.

Post-Incident Review
Review cause, impact, response effectiveness and priority improvements.

BEST FOR
Businesses that want practical response readiness and pre-arranged technical support before a cyber incident.

Live Response Is Separate From Incident Response Planning

This page covers technical action during a suspected or confirmed incident.

Playbooks, tabletop exercises, roles, communications and broader readiness belong under Govern IT on the Incident Response Planning page.

The two services connect, but they solve different needs and should remain separate.

INCIDENT RESPONSE EXPERTISE

Think You May Have Been Compromised?

Disconnect affected systems from the network where safe, avoid destroying evidence and contact ITFR using the Talk to Us button for urgent triage.

1

Ransomware Response

Contain affected systems, investigate scope and coordinate controlled recovery.

2

Account Compromise

Secure identities, revoke access and investigate suspicious activity.

3

Business Email Compromise

Review accounts, rules, messages, payments and related identity activity.

4

Unauthorised Data Access

Investigate access, preserve logs and support containment and evidence needs.

$

Incident response scaled to severity, scope and business impact.

Use emergency assistance or a retainer according to current risk, internal capacity and assurance requirements.