Incident Response
Urgent technical containment, investigation and recovery support when a cyber security incident is suspected or confirmed.
Rapid technical triage
Threat containment
Evidence-led investigation
Recovery coordination
When an Incident Is Active, Speed and Clear Decisions Matter
Ransomware, compromised accounts, malicious email and unauthorised access can spread quickly. ITFR helps establish what happened, contain active threats and coordinate technical recovery while preserving useful evidence and keeping business priorities visible.
✓Initial triage
Establish the suspected incident, affected services, immediate risk and required specialists.
✓Containment
Isolate affected systems, disable compromised accounts and limit further attacker activity.
✓Investigation
Review available logs, alerts, devices and account activity to determine scope and likely cause.
✓Eradication
Remove malicious access, persistence, compromised credentials and unsafe configurations.
✓Recovery
Restore systems and services carefully, validate operation and monitor for recurrence.
✓Incident documentation
Record evidence, decisions, actions, impact and improvements for management, insurers and advisers.
The result: a structured technical response that limits damage, supports recovery and creates a clearer path for legal, insurance and business decisions.
Benefits at a glance
Faster Containment
Clearer Scope
Safer Recovery
Useful Evidence
SECURE IT · INCIDENT RESPONSE
Choose the Right Incident Response Access
Use emergency assistance for an active incident or establish a retainer so contacts, access and response capacity are agreed before an event.
Emergency Incident Response
Time & Materialssubject to availability and scope
Urgent technical help for suspected or confirmed compromise
For organisations dealing with ransomware, account takeover, malicious access or another active cyber security event.
- Included: Rapid Triage & Severity AssessmentConfirm the concern, immediate risk, affected services and next response actions.
- Included: Technical ContainmentIsolate systems, disable accounts and block active attack paths where possible.
- Included: Evidence CollectionPreserve available logs, alerts, devices and records needed for investigation.
- Included: Incident InvestigationDetermine affected systems, users, activity, likely entry point and persistence.
- Included: Recovery CoordinationSupport restoration, credential resets, validation and heightened monitoring.
- Included: Incident Report & Improvement ActionsDocument findings, decisions, response work and priority control improvements.
BEST FOR
Businesses that need immediate technical assistance with an active or suspected cyber security incident.
Incident Response Retainer
10 Response Hourssubject to availability and scope
Pre-agreed access to incident response support
For organisations that want response contacts, access preparation and technical capacity arranged before an incident occurs.
- Included: Response OnboardingConfirm contacts, escalation, authority, environment and relevant third parties.
- Included: Ten Included Response HoursUse the included technical response allocation when an incident occurs.
- Included: Priority Response AccessUse the agreed escalation path and response process, subject to the retainer terms.
- Included: Environment & Evidence ReadinessIdentify essential access, logging, security tools and recovery dependencies.
- Included: Incident Coordination SupportWork with leadership, insurers, legal advisers and other specialists as authorised.
- Included: Additional Hours at Agreed RatesContinue investigation, containment and recovery beyond the included allocation.
- Included: Post-Incident ReviewReview cause, impact, response effectiveness and priority improvements.
BEST FOR
Businesses that want practical response readiness and pre-arranged technical support before a cyber incident.
Use the arrows or swipe sideways to view every plan.
Live Response Is Separate From Incident Response Planning
This page covers technical action during a suspected or confirmed incident.
Playbooks, tabletop exercises, roles, communications and broader readiness belong under Govern IT on the Incident Response Planning page.
The two services connect, but they solve different needs and should remain separate.
COMMON QUESTIONS
Your incident response questions, answered
What should we do if we suspect an incident now?
Contact ITFR by phone and describe what you have observed, the systems affected and the business impact. Avoid deleting logs or evidence. Immediate scope, availability and next actions are confirmed with your team.
Which incidents can you assist with?
Support can be scoped for ransomware, account compromise, business email compromise and unauthorised data access, including technical containment, recovery and evidence coordination.
Do you handle legal or breach-notification decisions?
ITFR can support technical investigation and evidence. Legal advice, notification decisions and business communications remain with the organisation and its appointed advisers.
Can we arrange support before an incident occurs?
A retainer or preparedness engagement can clarify contacts, access, scope and responsibilities. Incident Response Planning provides a separate pathway for playbooks and exercises.
READY TO GET STARTED?
Get help with a suspected cyber incident
Talk to us about your current environment, priorities and the next step that fits your business.






