Incident Response and Digital Forensics

During an incident the two most valuable things are usually in tension: getting systems back, and understanding what happened. Move too fast and you destroy the evidence that would tell you how they got in and whether they are still there. Move too slowly and the business bleeds.

Incident response is the discipline of doing both properly — containing the problem while preserving the record.

What We Do

  • Containment guidance — limit the damage without destroying the evidence trail.
  • Evidence preservation — captures, images and logs collected defensibly, in case this becomes a legal or insurance matter.
  • Traffic and log analysis — reconstruct sessions, identify command-and-control patterns, trace data movement. Tooling described on our forensics page.
  • Root-cause reconstruction — how entry was gained, what was reached, what was taken.
  • Scope determination — the question everyone asks first and that takes the longest to answer honestly.
  • Reporting — a written account that stands up to auditors, insurers and regulators.

When It Crosses Into OT

An incident that reaches building or industrial systems needs someone fluent in both worlds. Corporate IR tooling and instincts do not transfer cleanly to a network running BACnet and a Niagara station, and treating OT like IT during an incident is how a security event becomes an operational one.

Prevention Is Cheaper, Obviously

If you are reading this before an incident, the useful work is testing, secure development, and proving your recovery actually works — which is exactly what our recovery validation platform is being built to do.

Get in touch — whether you are in an incident now or want a responder who already knows your environment before you need one.

Related services

What the First Hour Costs You

Before any outside responder arrives, someone inside has already made decisions that shape the whole investigation. Reimaging the affected machine and getting the user working again is the understandable instinct, and it destroys the host side of the evidence: running processes, open connections, loaded modules, and whatever the intruder left in memory. Where you can afford to isolate a host at the network level and leave it powered on, do that first.

Memory holds things that never reach disk. Some of it survives a shutdown in a hibernation file, a pagefile, a crash dump or a suspended virtual machine, and those are worth collecting, but none of them substitutes for a capture taken while the system is still running. Two other habits help more than they look like they will. Start a plain written timeline the moment you notice something, with timestamps and who did what, because reconstructing your own actions later is surprisingly hard. And decide early who is authorized to speak about the incident, internally and externally, so a partial picture does not reach a customer or a regulator before anyone understands it.

Who Else Belongs in the Room

Technical containment is one track. Legal counsel, your cyber insurer and, depending on sector and jurisdiction, one or more notification clocks run in parallel. Your policy may set a notification deadline and may restrict which responders can be engaged, sometimes to a named panel, so read it before anyone is appointed, including us. Some organizations run investigations under legal privilege, which affects how the work is commissioned and how reports are worded. That is a decision for your counsel, and it is far easier to make at the start than to retrofit halfway through. We will work under whatever structure counsel sets, and we will tell you early if the policy rules us out.

Authorization Before Anyone Touches a Disk

Response work is intrusive by definition: isolating hosts, capturing memory and disk images, pulling logs from systems that may belong to a provider rather than to you. It runs under written authorization from a party entitled to grant it, against a scope naming the systems and accounts in play. Where a cloud platform, a hosting provider or a managed service provider owns part of the environment, their authorization is needed too, and obtaining it takes time nobody has once an incident is live. Evidence handling belongs in the same document: how images are stored, who holds them, how long they are kept, and how they are destroyed. This is the authorization chain set out on our service delivery and coverage page, agreed in advance rather than negotiated at two in the morning.

What Forensics Can and Cannot Recover

How much of the story comes back depends almost entirely on what was recorded before the incident. Endpoint telemetry, authentication logs, DNS and proxy records, firewall flows and cloud audit trails each answer different questions, and each has a retention period that may already have expired. Where an intruder cleared logs or operated only in memory, some questions stay open permanently. A report worth paying for separates conclusions supported by evidence from inference, and states plainly what could not be established. Confirming that the right things are being logged, and kept long enough to be useful, is much easier before you need them, and that work sits inside platform security and compliance readiness rather than inside a response.

Not Every Incident Needs an Investigation

A single phished mailbox where multifactor held, the session was revoked, and audit logs show no rule creation or bulk downloads may be well within reach of your own team. What changes the answer is obligation and uncertainty: a contract or regulation requiring you to establish scope, any suspicion of lateral movement, any sign of persistence, or a system holding regulated data. If you cannot say confidently what the intruder could reach, that uncertainty is itself the argument for bringing someone in.

What a Retainer Buys, and What It Does Not

A retainer buys familiarity. Someone has already seen the network diagram, knows where the logs live, and has an agreed contact path, so the early hours go on analysis instead of orientation. The trade is that you are paying for readiness you may never use. What it does not buy is unlimited availability: response windows, contact paths and escalation exist only where they have been written into engagement terms, and without terms in place we cannot promise you a time. If you already have an internal team with forensic capability and a plan that has been exercised, a retainer may add little. If the plan has never been rehearsed and the person who knows the environment best is also the person who would be restoring it, the case is stronger.