Reg. No. 40203410806 VAT LV40203410806

Theme

Book a consultation Book

3.04 Incident response

Incident Response & Digital Forensics

Incident-response planning, playbooks and exercises plus reactive DFIR — rapid triage, containment, host, network, cloud and email forensics, evidence preservation and regulatory notification across the full incident lifecycle.

Effective incident response depends on decisions made before an incident: assigned roles, communication channels, evidence-handling procedures, escalation criteria and tested recovery steps. We help establish and exercise these capabilities.

The programme can be aligned with NIS2, GDPR, sector-specific requirements, cyber-insurance conditions and customer contracts. Exercises validate whether the plan works under realistic time pressure.

When a compromise is suspected, the immediate priorities are to determine what happened, how access was obtained, which systems and data were affected, whether the activity is ongoing and which containment actions are safe. We reconstruct activity from endpoints, logs, cloud audit trails, network data and email while preserving relevant evidence, coordinating containment to reduce risk without destroying information needed for root-cause analysis or later proceedings.

Deliverables can include an incident timeline, root cause, affected assets and data, indicators of compromise, containment and recovery actions, and the information needed to support regulatory notifications, insurance claims or coordination with authorities.

241 days
average to identify & contain a breach
Source: IBM Cost of a Data Breach 2025 , opens in a new tab
$2.66M
saved with a tested incident-response plan
Source: IBM Cost of a Data Breach 2025 , opens in a new tab
72 hours
GDPR deadline to report a personal-data breach
Source: GDPR Art. 33 , opens in a new tab

01

How it works

  1. 01

    Readiness assessment & gap analysis

    Evaluate response readiness, obligations, maturity and existing documentation.

  2. 02

    Plan & playbook development

    Classification, response procedures, comms templates, technical playbooks and tabletop exercises.

  3. 03

    Emergency intake & triage

    On call-out, rapidly establish the incident scope, provide immediate containment guidance and define how evidence is preserved before it is overwritten.

  4. 04

    Containment & evidence capture

    Isolate affected systems and cut attacker access while forensically preserving disks, memory, logs and cloud/email trails.

  5. 05

    Investigation, eradication & recovery

    Reconstruct the attack timeline, scope the access and data impact, extract indicators of compromise, remove footholds and validate clean restoration.

  6. 06

    Reporting, notification & review

    Plain-language and technical report with IOCs; support for NIS2 / GDPR notification, insurers and CERT.LV; and a post-incident review so the same path cannot be reused.

02

Packages

Readiness
IR plan, playbooks and a tabletop exercise so the team is ready before an incident.
Emergency Response Popular
One-off rapid engagement: triage, containment, forensics and a full incident report.
Forensic Investigation
Deep-dive host, memory and malware forensics for a confirmed or complex compromise.
Response Retainer
Pre-agreed terms and priority access with rehearsed IR planning, so we are ready before the next incident.

03

Supported by our own threat-intelligence platform

Incident-response work is supported by our existing threat intelligence and investigation capabilities, reducing the need to establish a separate toolset after an incident begins.

04

Experience this scenario interactively

A hands-on 3D simulation of this threat, followed by an explanation of how we test it in a real engagement.

05

Frequently asked questions

Can you help during an actual security incident?

We prioritise emergency requests and can provide remote or on-site support subject to availability and the agreed terms. Guaranteed 24/7 availability and response times are provided only under a response retainer or another SLA that explicitly includes them.

We think we have been breached. What is the first thing we should do?

Contact the response team and preserve evidence wherever possible. Do not wipe affected systems or delete logs; whether a device should remain powered on, be isolated or be shut down depends on the incident and should be decided with a responder. We provide immediate containment guidance and begin an investigation that preserves evidential integrity for insurers, regulators or law enforcement where required.

Do we need specialized staff for incident response?

Not necessarily. We design incident response plans that leverage your existing IT and security personnel, with clear procedures that can be followed even without deep security expertise. For organizations with minimal internal capabilities, we can provide ongoing support or managed incident response services.

How often should we test our incident response plan?

Test the plan at least annually and after material changes to systems, teams or obligations. Higher-risk organisations may need more frequent tabletop or technical exercises. Scenarios should rotate so that decision-making, communication, containment and recovery are all exercised.

What types of incidents should our plan cover?

We recommend developing response procedures for multiple incident types including malware infections, phishing attacks, data breaches, denial of service, unauthorized access, insider threats, and ransomware. The specific focus areas depend on your risk profile and industry.

Do you handle ransomware?

Yes. We help determine the affected systems and data, remove attacker persistence, support recovery from known-clean backups and document the intrusion path. We can provide technical and risk information for management and legal decision-making, but we do not guarantee recovery or negotiate with threat actors unless that activity is expressly included and lawful.

Can your report be used for NIS2 and GDPR notification?

Our report can provide the technical facts needed to support NIS2, GDPR, insurance or CERT.LV notifications: timeline, root cause, affected assets and data, indicators of compromise, containment and recovery actions. The organisation and its legal or data-protection advisers remain responsible for determining whether notification is required and for submitting it within the applicable deadline.

How do you measure incident response effectiveness?

We establish key metrics including time to detection, time to containment, time to recovery, incident impact scores, and process adherence measurements. These metrics provide ongoing visibility into response capability and identify improvement opportunities.

06

Helpful tools

07

All services

Scope a test

[email protected] +371 2256 5353

Direct access to a senior specialist · Reply within 24 hours · NDA available on request