Incident Response

What Happens After You Report an Incident

The steps iCoreFusion takes from first contact to resolution.

1. Acknowledge and triage

Adam acknowledges your report and begins triage. For P1/P2, this is immediate. We access your SIEM environment, review telemetry, and establish the scope of the incident.

2. Contain

Once the threat vector is identified, we move to contain it - isolating affected endpoints, revoking compromised credentials, blocking malicious IPs, or disabling affected services. We will always inform you before taking containment actions that affect business operations.

3. Eradicate and recover

We remove the attacker's foothold - malware, persistence mechanisms, unauthorised accounts - and verify clean state before restoring services. Recovery timelines depend on scope.

4. Post-incident report

After resolution, you receive a written post-incident report covering timeline, root cause, actions taken, and recommendations to prevent recurrence.

Need more help? Contact Adam directly.

Use email for general support, or phone for active P1/P2 incidents.

Related articles