When a breach happens, the first 48 hours matter most.
When a breach or suspected cyber incident happens, the priority is containment first, understanding second — but both have to be done in a way that preserves evidence, in case the matter needs to go further, to a regulator, an insurer, or a court.
We investigate the technical root cause while documenting everything to a standard that holds up, whoever ends up needing to see it.
Report a Suspected IncidentEvery incident is triaged and classified on this scale from the first hour.
Technical investigation matched to the kind of incident you're facing.
Tracing exactly how an attacker gained access and what they did once inside.
Understanding what the malicious software actually did, and how it spread.
Determining whether, and what, data actually left your environment.
Reconstructing the timeline of an incident from logs and network traffic.
Investigating suspected misuse of access by employees or contractors.
Handling evidence to a standard suitable for legal or regulatory use.
Every finding is documented with a timeline, technical evidence, and impact assessment.
Below is an illustrative example of how a single finding is presented.
An internet-facing Remote Desktop Protocol port was left exposed with weak credentials, providing the initial point of unauthorised access.
Illustrative example only — for demonstration of report format, not an actual finding from a client engagement.
The same disciplined sequence, from the first hour of an incident.
Stop the incident from spreading further while investigation begins.
Preserve logs, images and artefacts before they can be lost or altered.
Determine exactly how the incident happened and what was affected.
Assess what data or systems were actually compromised.
Deliver findings and a remediation plan to prevent recurrence.
Investigations are documented to standards suitable for these contexts.
Don't shut down affected systems before speaking with us if possible — that can destroy evidence needed for investigation. Contact us immediately and we'll guide the first steps.
Yes — we help determine whether an incident triggers mandatory reporting and support the reporting process itself.
Evidence is preserved and documented with that possibility in mind, though admissibility ultimately depends on the specific matter and your legal counsel's guidance.
We prioritise active incidents and mobilise as quickly as possible — reach out immediately rather than waiting.
Yes — every investigation ends with a remediation plan specifically aimed at preventing the same root cause from recurring.
Contact us immediately — early containment makes the biggest difference.