Incident Response
Urgent technical containment, investigation and recovery support when a cyber security incident is suspected or confirmed.
Rapid technical triage
Threat containment
Evidence-led investigation
Recovery coordination
When an Incident Is Active, Speed and Clear Decisions Matter
Ransomware, compromised accounts, malicious email and unauthorised access can spread quickly. ITFR helps establish what happened, contain active threats and coordinate technical recovery while preserving useful evidence and keeping business priorities visible.
✓Initial triage
Establish the suspected incident, affected services, immediate risk and required specialists.
✓Containment
Isolate affected systems, disable compromised accounts and limit further attacker activity.
✓Investigation
Review available logs, alerts, devices and account activity to determine scope and likely cause.
✓Eradication
Remove malicious access, persistence, compromised credentials and unsafe configurations.
✓Recovery
Restore systems and services carefully, validate operation and monitor for recurrence.
✓Incident documentation
Record evidence, decisions, actions, impact and improvements for management, insurers and advisers.
The result: a structured technical response that limits damage, supports recovery and creates a clearer path for legal, insurance and business decisions.
Benefits at a glance
Faster Containment
Clearer Scope
Safer Recovery
Useful Evidence
SECURE IT · INCIDENT RESPONSE
Choose the Right Incident Response Access
Use emergency assistance for an active incident or establish a retainer so contacts, access and response capacity are agreed before an event.
Emergency Incident Response
Time & Materials
subject to availability and scope
Urgent technical help for suspected or confirmed compromise
For organisations dealing with ransomware, account takeover, malicious access or another active cyber security event.
✓Rapid Triage & Severity Assessment
Confirm the concern, immediate risk, affected services and next response actions.
✓Technical Containment
Isolate systems, disable accounts and block active attack paths where possible.
✓Evidence Collection
Preserve available logs, alerts, devices and records needed for investigation.
✓Incident Investigation
Determine affected systems, users, activity, likely entry point and persistence.
✓Recovery Coordination
Support restoration, credential resets, validation and heightened monitoring.
✓Incident Report & Improvement Actions
Document findings, decisions, response work and priority control improvements.
BEST FOR
Businesses that need immediate technical assistance with an active or suspected cyber security incident.
Incident Response Retainer
10 Response Hours
subject to availability and scope
Pre-agreed access to incident response support
For organisations that want response contacts, access preparation and technical capacity arranged before an incident occurs.
✓Response Onboarding
Confirm contacts, escalation, authority, environment and relevant third parties.
✓Ten Included Response Hours
Use the included technical response allocation when an incident occurs.
✓Priority Response Access
Use the agreed escalation path and response process, subject to the retainer terms.
✓Environment & Evidence Readiness
Identify essential access, logging, security tools and recovery dependencies.
✓Incident Coordination Support
Work with leadership, insurers, legal advisers and other specialists as authorised.
✓Additional Hours at Agreed Rates
Continue investigation, containment and recovery beyond the included allocation.
✓Post-Incident Review
Review cause, impact, response effectiveness and priority improvements.
BEST FOR
Businesses that want practical response readiness and pre-arranged technical support before a cyber incident.
Live Response Is Separate From Incident Response Planning
This page covers technical action during a suspected or confirmed incident.
Playbooks, tabletop exercises, roles, communications and broader readiness belong under Govern IT on the Incident Response Planning page.
The two services connect, but they solve different needs and should remain separate.
INCIDENT RESPONSE EXPERTISE
Think You May Have Been Compromised?
Disconnect affected systems from the network where safe, avoid destroying evidence and contact ITFR using the Talk to Us button for urgent triage.
Ransomware Response
Contain affected systems, investigate scope and coordinate controlled recovery.
Account Compromise
Secure identities, revoke access and investigate suspicious activity.
Business Email Compromise
Review accounts, rules, messages, payments and related identity activity.
Unauthorised Data Access
Investigate access, preserve logs and support containment and evidence needs.
$
Incident response scaled to severity, scope and business impact.
Use emergency assistance or a retainer according to current risk, internal capacity and assurance requirements.





