Incident assessment
An initial view of what is known, what remains uncertain, and where to investigate.
Bring structure to investigation, containment, and recovery when something looks wrong.
01 / THE SCOPE
For a suspected compromise or preparation before one happens. Active incident support depends on availability and an agreed engagement.
An initial view of what is known, what remains uncertain, and where to investigate.
Prioritised containment and recovery actions with clear responsibilities.
A record of findings and improvements to reduce repeat issues.
02 / THE PROCESS
Confirm the situation, affected systems, available evidence, and key contacts.
Investigate and agree containment actions with your team.
Review restoration priorities and record follow-up improvements.
03 / GOOD TO KNOW
We agree access to relevant logs, affected systems, and response contacts based on the incident. Evidence handling and permissions are defined before collection or investigation.
Isolating a system or restricting an account can affect operations. We discuss the tradeoffs and obtain the agreed approval before taking containment actions.
The engagement can include an incident summary, remaining uncertainties, and prioritised improvements. Follow-up validation and longer-term support are defined in the scope.
This website does not provide a guaranteed emergency response. For an active incident, use your organisation’s established incident process and response contacts.
Share a brief description, when the issue was noticed, and the type of systems involved. Do not send passwords, sensitive logs, or personal data through the website.
Yes. A scoped readiness exercise can review your response plan, escalation contacts, decision-making, and recovery dependencies.
Tell us about your systems and what you need.