Incident Response & Digital Forensics
Incident-response planning, playbooks and exercises plus reactive DFIR — rapid triage, containment, host, network, cloud and email forensics, evidence preservation and regulatory notification across the full incident lifecycle.
Effective incident response depends on decisions made before an incident: assigned roles, communication channels, evidence-handling procedures, escalation criteria and tested recovery steps. We help establish and exercise these capabilities.
The programme can be aligned with NIS2, GDPR, sector-specific requirements, cyber-insurance conditions and customer contracts. Exercises validate whether the plan works under realistic time pressure.
When a compromise is suspected, the immediate priorities are to determine what happened, how access was obtained, which systems and data were affected, whether the activity is ongoing and which containment actions are safe. We reconstruct activity from endpoints, logs, cloud audit trails, network data and email while preserving relevant evidence, coordinating containment to reduce risk without destroying information needed for root-cause analysis or later proceedings.
Deliverables can include an incident timeline, root cause, affected assets and data, indicators of compromise, containment and recovery actions, and the information needed to support regulatory notifications, insurance claims or coordination with authorities.
- 241 days
- average to identify & contain a breach
- Source: IBM Cost of a Data Breach 2025 , opens in a new tab
- $2.66M
- saved with a tested incident-response plan
- Source: IBM Cost of a Data Breach 2025 , opens in a new tab
How it works
-
01
Readiness assessment & gap analysis
Evaluate response readiness, obligations, maturity and existing documentation.
-
02
Plan & playbook development
Classification, response procedures, comms templates, technical playbooks and tabletop exercises.
-
03
Emergency intake & triage
On call-out, rapidly establish the incident scope, provide immediate containment guidance and define how evidence is preserved before it is overwritten.
-
04
Containment & evidence capture
Isolate affected systems and cut attacker access while forensically preserving disks, memory, logs and cloud/email trails.
-
05
Investigation, eradication & recovery
Reconstruct the attack timeline, scope the access and data impact, extract indicators of compromise, remove footholds and validate clean restoration.
-
06
Reporting, notification & review
Plain-language and technical report with IOCs; support for NIS2 / GDPR notification, insurers and CERT.LV; and a post-incident review so the same path cannot be reused.
Packages
- Readiness
- IR plan, playbooks and a tabletop exercise so the team is ready before an incident.
- Emergency Response Popular
- One-off rapid engagement: triage, containment, forensics and a full incident report.
- Forensic Investigation
- Deep-dive host, memory and malware forensics for a confirmed or complex compromise.
- Response Retainer
- Pre-agreed terms and priority access with rehearsed IR planning, so we are ready before the next incident.
Supported by our own threat-intelligence platform
Incident-response work is supported by our existing threat intelligence and investigation capabilities, reducing the need to establish a separate toolset after an incident begins.
- OffSeq Mirage , opens in a new tabExplore
Honeypot IOCs and ATT&CK-mapped attacker telemetry help us attribute activity and recognise the campaign fast.
- OffSeq Threat Radar , opens in a new tabExplore
CVE intelligence pinpoints the vulnerability behind the intrusion and what else in your estate is exposed.
- OffSeq Breach , opens in a new tabExplore
Helps determine whether exposed credentials contributed to access and identify related accounts requiring remediation.
- OffSeq Pulse , opens in a new tabExplore
Endpoint posture and remote device control — lock, locate or isolate a compromised machine straight from the console.
Experience this scenario interactively
A hands-on 3D simulation of this threat, followed by an explanation of how we test it in a real engagement.
Frequently asked questions
Can you help during an actual security incident?
We prioritise emergency requests and can provide remote or on-site support subject to availability and the agreed terms. Guaranteed 24/7 availability and response times are provided only under a response retainer or another SLA that explicitly includes them.
We think we have been breached. What is the first thing we should do?
Contact the response team and preserve evidence wherever possible. Do not wipe affected systems or delete logs; whether a device should remain powered on, be isolated or be shut down depends on the incident and should be decided with a responder. We provide immediate containment guidance and begin an investigation that preserves evidential integrity for insurers, regulators or law enforcement where required.
Do we need specialized staff for incident response?
Not necessarily. We design incident response plans that leverage your existing IT and security personnel, with clear procedures that can be followed even without deep security expertise. For organizations with minimal internal capabilities, we can provide ongoing support or managed incident response services.
How often should we test our incident response plan?
Test the plan at least annually and after material changes to systems, teams or obligations. Higher-risk organisations may need more frequent tabletop or technical exercises. Scenarios should rotate so that decision-making, communication, containment and recovery are all exercised.
What types of incidents should our plan cover?
We recommend developing response procedures for multiple incident types including malware infections, phishing attacks, data breaches, denial of service, unauthorized access, insider threats, and ransomware. The specific focus areas depend on your risk profile and industry.
Do you handle ransomware?
Yes. We help determine the affected systems and data, remove attacker persistence, support recovery from known-clean backups and document the intrusion path. We can provide technical and risk information for management and legal decision-making, but we do not guarantee recovery or negotiate with threat actors unless that activity is expressly included and lawful.
Can your report be used for NIS2 and GDPR notification?
Our report can provide the technical facts needed to support NIS2, GDPR, insurance or CERT.LV notifications: timeline, root cause, affected assets and data, indicators of compromise, containment and recovery actions. The organisation and its legal or data-protection advisers remain responsible for determining whether notification is required and for submitting it within the applicable deadline.
How do you measure incident response effectiveness?
We establish key metrics including time to detection, time to containment, time to recovery, incident impact scores, and process adherence measurements. These metrics provide ongoing visibility into response capability and identify improvement opportunities.
Helpful tools
- Scope a test
Create a scoped brief in one minute
- Security maturity assessment
Assess your organization across six domains
All services
- Cloud Security & Posture Assessment
Identify cloud misconfigurations, posture drift and privilege-escalation paths.
- Kubernetes & Container Security
Assess cluster configuration, workloads, secrets and attack paths.
- Proactive Security Monitoring
Continuous monitoring, detection and response support.
Scope a test
[email protected] +371 2256 5353
Direct access to a senior specialist · Reply within 24 hours · NDA available on request