Cyber Incident Response

The organisations that come through an incident well are not the ones that were never breached. They are the ones that had decided in advance who does what.

Response
Containment & forensics
Preparation
Plans & tabletop exercises
Coverage
Remote UK-wide, onsite West Midlands
Reporting
Board and regulator ready

If you are dealing with an incident now

Do not power systems off unless they are actively causing damage — you will destroy volatile evidence. Disconnect from the network instead. Do not delete anything. Preserve logs before retention windows expire. Then get in touch: info@solusec.co.uk.

Response

When something has happened, the priorities are containment, understanding, and evidence — in that order, and usually under significant time pressure with incomplete information.

Containment

Stopping the spread without destroying the evidence you will need afterwards. This is a genuine tension and it is handled badly under pressure. Wiping and rebuilding a compromised machine feels decisive and eliminates any prospect of understanding what happened, what was taken, or whether the attacker still has access elsewhere.

Investigation and forensics

Establishing initial access, the timeline, what the attacker touched, whether data was exfiltrated, and whether persistence remains. That last question determines whether you can safely return to operating, and it is the one organisations most often fail to answer before declaring the incident closed.

Recovery

Working with your IT provider on a rebuild sequence that does not restore the attacker along with the data — a real and common outcome when backups predate detection but postdate compromise.

Reporting

Documentation for your board, your insurer, your clients and, where applicable, the ICO. UK GDPR requires notification of qualifying personal data breaches within seventy-two hours of becoming aware, and that clock does not wait for the investigation to finish. A clear factual account of what is known, what is not, and what is being done is worth a great deal in that conversation.

Preparation

Preparation is dramatically cheaper than response and almost nobody buys it until after their first incident.

  • Incident response plan — who decides, who calls the insurer, who talks to clients, who has authority to disconnect production. Written down, and available offline for when the network is the thing that is compromised.
  • Tabletop exercises — walking your leadership team through a realistic scenario. Consistently surfaces the same gaps: nobody knows the insurer's number, nobody has authority to take systems offline, the contact list is on the file share that is now encrypted.
  • Retained response — an agreement in place so that when something happens you are not negotiating terms during the worst week of your year.
  • Readiness review — whether you would have the logs, backups and access needed to investigate. Most organisations discover their retention is thirty days after needing ninety.

Working with insurers

If you hold cyber insurance, check the policy now rather than during an incident. Many require you to use a panel provider and may decline costs incurred elsewhere. We will work alongside a panel firm where that is what your policy requires — being straight with you about that is more useful than winning the engagement.

Common questions

What should we do first if we think we have been breached?

Contain without destroying evidence: disconnect affected systems from the network rather than powering them off, since shutting down loses memory-resident evidence. Do not delete anything. Preserve logs immediately, as retention windows are often short. Then get expert help involved early — the first few hours shape how much you can establish later.

Do you offer a retainer?

Yes. A retained arrangement means terms, contacts and authority are agreed in advance and you get a guaranteed response commitment. It also means we already understand your environment, which materially shortens the time to containment.

Do we have to report to the ICO?

If personal data is involved and the breach poses a risk to individuals, UK GDPR requires notification within seventy-two hours of becoming aware. Not every incident qualifies, and the assessment needs care. We help you gather the facts to make and evidence that decision, though the determination and any legal advice sit with you and your advisers.

Can you help if the incident is already over?

Yes. Post-incident review establishes what happened, whether the attacker still has access, and what needs to change. Organisations that skip this step have a habit of being compromised again through the same route.

Related

Ready to talk?

Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.