Incident Response
A security incident is a race between containment and spread. Handled well, it’s a bad Friday. Handled badly (or slowly), it’s weeks of downtime, a seven-figure recovery, and notification letters with your logo on them. The difference is rarely luck. It’s whether someone competent took over fast, and whether the groundwork existed before the alarm.
What our incident response covers
- Containment — isolating affected systems and accounts to stop spread, with forensically sound handling so evidence survives
- Recovery coordination — restoring from backups, rebuilding what can’t be restored, and sequencing systems back online by business priority
- Stakeholder coordination — working alongside your leadership, counsel, insurer, and — where applicable — regulators and notification obligations
- After-action summary — what happened, what was done, and what changes so it doesn’t happen twice
A real timeline (anonymized): ransomware on a Friday
A 12,000-resident Arkansas city, 4:41 p.m. on a Friday: endpoint detection flags encryption starting on the utility billing server and isolates it automatically. By 4:52 p.m. the on-call engineer has traced it to a compromised vendor account — credential disabled, tenant-wide sign-out forced. By 6:15 p.m. the scope is confirmed as one server with no lateral movement and restore begins from the immutable offsite backup. Monday, 8:00 a.m.: utility billing runs on schedule. No ransom paid, no missed collection cycle.
Every reason it stayed small — 24/7 monitoring, automated isolation, immutable tested backups, MFA, a written plan with named roles — was a budget decision made months earlier. That’s the honest lesson: incident response starts long before the incident.
What’s included, and what isn’t
We’d rather tell you now than surprise you later. Managed services cover prevention, detection, and recovery infrastructure — the monitoring, security stack, and tested backups that keep incidents small. Responding to an active incident is separate work, billed as incident response — with priority response and preferred rates for managed clients. If a provider tells you unlimited breach response is bundled into a flat monthly fee, read that agreement very closely.
Be the organization with a plan
An incident response plan is a short document that answers, in advance, the questions that panic answers badly: who isolates, who decides, who calls the carrier and counsel, who speaks to staff, and where the backups are. We build IR plans with named roles, aligned to your compliance obligations and insurance policy conditions — and we test them, because a plan that’s never been rehearsed is a theory.
In an emergency: call 877-938-9450 now.
Before one: build the plan, test the backups, and make the Friday-afternoon story above your story. Schedule an incident readiness review.
Build Your Incident Response Plan
Incident Response FAQs
We just discovered ransomware. What are the first three things to do?
One: disconnect affected machines from the network (unplug the cable, kill the Wi-Fi) but leave them powered on, because memory holds evidence. Two: call for professional help immediately — 877-938-9450. Three: notify your cyber insurance carrier early; most policies require prompt notice and many provide response resources. Do not pay, negotiate, or wipe anything before talking to professionals.
Should we pay the ransom?
Our strong general guidance is no. Payment doesn’t guarantee recovery, marks you as a payer, and most recent industry data shows the large majority of victims now refuse. But it’s ultimately a business and legal decision made with your counsel and insurer. The best position is the one where the question is academic: tested, immutable backups.
Do you have to be our IT provider to help in an emergency?
No — we take emergency calls from organizations we’ve never met, capacity permitting. Managed clients get priority response and preferred rates, and their incidents tend to be dramatically smaller because the groundwork exists. Both facts are worth knowing before you need either one.
Will our insurance cover the incident?
It depends on your policy and whether your application answers matched reality. This is why we push clients to close gaps before renewal rather than attest around them. We work alongside your carrier’s process and provide the technical documentation claims require.
