Cyber Security
SECaaSSIEMSOCNetworkICS/OTComplianceEmailCloudZero Trust

Cybersecurity · IR & Forensics

Incident Response & Digital Forensics

When it counts, a team that contains the incident, finds the root cause, and gets you back to operations — available on retainer before you need it.

24×7×365

Responders on call for retainer clients

$4.88M

Average cost of a data breach — IBM 2024. Fast containment reduces it.

Guaranteed SLA

Contractual response time, agreed before you need it

When an incident hits

Four jobs, in order: stop the loss, learn exactly what happened, get you back to trustworthy operations, and give you a record that holds up.

Contain

The first task is to stop the bleeding — isolate affected systems, revoke the attacker's access, and cut lateral movement before more is lost.

  • Host isolation and account lockout
  • Attacker access revoked at endpoint and identity
  • Spread stopped before it is investigated

Investigate & forensics

We establish what happened, how, and how far it reached — forensically imaging systems, reconstructing the attacker timeline, and confirming the root cause.

  • Disk and memory forensics
  • Attacker timeline and dwell time
  • Root cause and true scope confirmed

Recover

We return you to operations you can trust — validating clean restore points, closing the entry path, and confirming the attacker is fully out before you resume.

  • Verified-clean restoration
  • Entry vector closed
  • Persistence removed and re-checked

Report

You get a defensible written account for leadership, regulators, and insurers — what happened, what we did, and what stops a repeat.

  • Executive and technical reports
  • Evidence preserved for legal use
  • Prioritized remediation plan

The retainer model

The worst time to negotiate an IR contract is mid-breach. A retainer puts the paperwork, the team, and the response time in place before the clock starts.

Pre-negotiated terms

Contracts, scope, and rates are agreed in advance, so when an incident hits there is no procurement delay — we start immediately.

  • No mid-crisis contracting
  • Locked rates and scope
  • Legal and authority pre-cleared

Guaranteed response SLA

Retainer clients get a contractual response time with responders on call 24×7×365 — you are not waiting in a queue behind someone else's breach.

Readiness hours

Unused retainer hours are not wasted — they fund tabletop exercises, IR plan reviews, and playbook development that make the next real event smaller.

A team that knows you

Because we onboard your environment before the incident, responders already understand your systems, contacts, and priorities on day one.

Ready before the breach

Preparation is the cheapest phase of the entire lifecycle. The work we do before an incident is what makes the incident survivable.

IR plans & playbooks

We build and maintain the incident response plan and per-scenario playbooks your team can actually follow under pressure — with roles, authority, and escalation defined.

Tabletop exercises

Facilitated scenarios — ransomware, business email compromise, insider threat — that test your people and decisions, not just your tooling.

Ransomware readiness

A targeted review of backups, segmentation, and recovery time objectives so a ransomware event is a bad week, not an existential one.

Why intSignal

Forensics is only useful if it is fast, defensible, and connected to the rest of your security program.

Coordinated with your SOC & MDR

When intSignal MDR/XDR and our SOC already watch your environment, detection, containment, and forensics run as one team — not a cold handoff to strangers.

  • Shared telemetry and context
  • One escalation path
  • Faster time to containment

Evidence-ready by default

Every action and artifact is documented to chain-of-custody standards, so findings hold up with auditors, insurers, and law enforcement.

  • Defensible incident timelines
  • Chain-of-custody preserved
  • Reports mapped to your frameworks

Fixes that outlast the incident

Root-cause findings feed straight into Vulnerability Management, Identity & Access Management, and hardening so the same door does not open twice.

  • Root cause, not just symptoms
  • Remediation handed to the right service
  • Detections updated to catch a repeat

The incident response lifecycle

We run to a recognized lifecycle — NIST SP 800-61 and SANS PICERL — so every engagement is structured, repeatable, and defensible.

1

Prepare

Before anything happens we onboard your environment, agree containment authority, and rehearse the plan through tabletops.

2

Detect & analyze

We validate the alert, scope the compromise, and reconstruct the attacker timeline through host, memory, and log forensics.

3

Contain & eradicate

We isolate affected systems, revoke attacker access, and remove persistence under the authority agreed in advance.

4

Recover & post-incident

We restore verified-clean operations, then deliver a post-incident report with root cause, lessons learned, and prioritized fixes.

Standards & tools we work with

We run to recognized IR and forensics standards, using tooling that stands up to scrutiny in an audit or a courtroom.

NIST SP 800-61 (incident handling)
SANS PICERL lifecycle
NIST SP 800-86 (forensic techniques)
MITRE ATT&CK
Velociraptor
KAPE
Volatility (memory forensics)
Autopsy / The Sleuth Kit
YARA
EDR forensic collection (Defender, CrowdStrike, SentinelOne)
Chain-of-custody & evidence handling
Cyber-insurance IR panels

Frequently asked questions

Why do we need an IR retainer before anything has happened?

The retainer removes the two things that slow a real response most — contracting and cold onboarding. Terms, scope, and authority are agreed in advance, and our responders already know your environment, so we begin containment in minutes instead of days. Unused hours fund tabletops and plan work, so the retainer earns its keep even in a quiet year.

How fast will you respond to an incident?

Retainer clients have a contractual response SLA with responders on call 24×7×365. We begin remote triage and containment as soon as you declare, and mobilize deeper forensics in parallel. Response time for non-retainer callers depends on current capacity, which is exactly why the retainer exists.

What happens in the first hours of an incident?

We stabilize first — isolate affected systems, revoke attacker access, and stop lateral movement — while preserving evidence rather than destroying it. In parallel we scope the compromise and begin the forensic timeline. Only once the attacker is contained and understood do we move to eradication and recovery.

Do you work with our cyber-insurance carrier?

Yes. We can operate as an approved vendor on carrier IR panels and follow the notification and evidence requirements your policy demands. Our documentation is built to support a claim, and we coordinate with breach counsel and the carrier's own experts where required.

Will you preserve evidence for legal action or law enforcement?

Every image, log, and response action is handled to chain-of-custody standards using tooling like Velociraptor, KAPE, and Volatility. That keeps your options open — whether the outcome is an insurance claim, litigation, a regulatory filing, or a law-enforcement referral. We do not contaminate evidence in the rush to recover.

How does this connect to intSignal MDR/SOC — do we need those too?

You do not need them to buy IR, but they make it dramatically faster. When our MDR/XDR and SOC already monitor your environment, we walk into an incident with telemetry, context, and containment tooling already in place instead of starting cold. Findings from an incident also flow back into detection content, Vulnerability Management, and Identity & Access Management to prevent a repeat.

Built for regulated, audited environments

We deliver the controls and evidence that make your audits possible — hardening and operating practices aligned to the frameworks your assessors and customers recognize.

SOC 2
ISO 27001
HIPAA
PCI DSS
CIS Controls
NIST CSF
GDPR

Incident Response for your environment

Tell us your stack and priorities — we return scope, ownership, and a plan.