Oman United Kingdom Norway Support portal
Talk to an expert
AboutContact

Incident response

Retained response with pre-agreed terms and named contacts, so triage starts in hours. Containment that preserves evidence, and a review that turns the incident into control improvements.

Prepare for an incident
Regions
Oman · UK · Norway
Scope
Written before it is quoted

The problem this solves

Most organisations do not lack security tools. They lack the time, the coverage and the evidence to prove those tools are working. Incident response is built to close that gap with people who do this every day.

What the service covers

Each area below is a defined part of the engagement, with an owner, an output and a date.

Retainer

Pre-agreed terms and contacts so the response starts in hours, not days.

Triage

Rapid scoping to establish what happened, what is affected and what to protect first.

Containment

Actions that stop the spread while preserving evidence.

Investigation

Forensic analysis of how access was gained and what was reached.

Recovery

A sequenced return to service with hardening applied as systems come back.

Lessons learned

A structured review that turns the incident into control improvements.

The response sequence

DETECTminutesTRIAGEhoursCONTAINhoursINVESTIGATEdaysRECOVERdaysREVIEWweeksContainment happens before investigation, not after.Evidence is preserved while the spread is stopped — the two are not sequential.A retainer removes the contracting delay, which is usually the longest part of hour one.
Where the hours actually go.

How the work runs

The same sequence on every engagement, so you know what happens next.

STEP 01

Scope

A scoping call establishes what is in scope, what is explicitly out, and which constraints apply. You get a written scope before any quotation.

STEP 02

Mobilise

Named consultants, access, escalation contacts and a delivery schedule are agreed and recorded.

STEP 03

Deliver

Work is carried out by the consultants you met at scoping, with progress visible rather than reported only at the end.

STEP 04

Report

Findings are peer-reviewed by a second consultant before release, then walked through with your team.

STEP 05

Improve

Remediation support, retesting and a follow-up review so the work produces a measurable change.

What you get out of it

Evidence you can show

Reports written so they can be handed to an auditor, a regulator or a board without translation.

Fewer surprises

Coverage gaps identified explicitly, including the ones outside our scope.

Regional delivery

Consultants based in Oman, the UK and Norway, not flown in for the week.

Standards and references: ISO/IEC 27001:2022 · NIST CSF 2.0 · MITRE ATT&CK · OWASP ASVS · CIS Benchmarks

Before you enquire

How quickly can this start?
Scoping usually takes one call. Delivery start depends on access and approvals; we will give you a date in the proposal rather than after you sign.
Who actually does the work?
Named consultants from our regional teams. You will meet them before the engagement begins, and the same people write the report.
How is this priced?
A fixed price against a written scope wherever the work can be scoped that way, and a day rate where it genuinely cannot. Either way you see the basis before you commit.

Prepare for an incident

One scoping call with the consultant who would run the work. No obligation, no charge.

Prepare for an incident
Talk to an expert