1. Acknowledge and triage
Adam acknowledges your report and begins triage. For P1/P2, this is immediate. We access your SIEM environment, review telemetry, and establish the scope of the incident.
2. Contain
Once the threat vector is identified, we move to contain it - isolating affected endpoints, revoking compromised credentials, blocking malicious IPs, or disabling affected services. We will always inform you before taking containment actions that affect business operations.
3. Eradicate and recover
We remove the attacker's foothold - malware, persistence mechanisms, unauthorised accounts - and verify clean state before restoring services. Recovery timelines depend on scope.
4. Post-incident report
After resolution, you receive a written post-incident report covering timeline, root cause, actions taken, and recommendations to prevent recurrence.
Need more help? Contact Adam directly.
Use email for general support, or phone for active P1/P2 incidents.