Live or suspected cyber incident

Don't fill the form. Call us.

If your systems are compromised, or you've seen activity that shouldn't be there, time matters more than process. Talk to a senior consultant on the phone, now. Everything else can wait.

Incident line · 24/7
01603 964914
hello@osirisit.co.ukSenior consultants · within the hour
01Contain

The first hour: containment, while you're still on the call.

What we take care of in the first hour, so you can focus on your organisation rather than fighting the wrong fire.

  1. Senior consultant on the call within the hour

    A consultant who has run incidents before, not a triage script. We take the call, take ownership, and start co-ordinating from the first ten minutes.

  2. Network isolation and account containment

    Stop lateral movement. Isolate compromised segments, disable affected accounts, rotate credentials, and stand up out-of-band communications if email is suspect.

  3. Insurer and counsel co-ordination

    Most policies require notification within hours. We co-ordinate with your cyber insurer, legal counsel, and the ICO 72-hour reporting clock if personal data is in scope.

Osiris consultant working through forensic analysis on a laptop during an incident.
02Investigate

What happened, how, and what it touched.

The forensic work that turns a chaotic event into a clear written narrative your insurer, your board, and your regulator can act on.

  1. Forensic image and evidence preservation

    We image affected systems before they're rebuilt, preserve memory and logs, and document the chain of custody so findings hold up with insurers, regulators, or a tribunal.

  2. Root cause and scope

    What got in. How. When. What it touched. We trace the attack across systems and accounts so the rebuild closes the path, not just the symptom.

  3. Indicators of compromise across your estate

    We hunt for related artefacts across endpoints, cloud, and identity to confirm the incident is contained and not just visibly stopped.

03Recover

Back to operating, stronger than before.

The work that gets your organisation running again, with the controls in place to prevent the next call.

  1. Rebuild, not just restore

    Restoring from backups isn't enough if the backup is compromised. We rebuild affected systems from known-good state with the controls that prevent re-entry.

  2. Business continuity while we work

    Parallel operations where possible. Reduced-capacity workarounds. A clear written status to your leadership and your customers if external comms are needed.

  3. Identity, MFA, and access hardened

    Credentials rotated, MFA enforced, conditional access tightened, privilege reduced. The hardening that was missing before, applied now.

04Review

Post-incident, when the adrenaline has dropped.

The work many providers stop short of, and the work that turns a difficult week into a stronger organisation.

  1. Post-incident review the board reads

    Written, plain-language, with the timeline, the cost, the controls that worked, and the controls that didn't. Designed for a board meeting, not an audit appendix.

  2. Controls strengthened

    We map the gap that let the incident happen against your control framework (Cyber Essentials, ISO 27001, NHS DSPT) and close it with evidence.

  3. Tested, not assumed

    We schedule a tabletop exercise three to six months later to verify the controls hold, the runbooks work, and the team remembers the muscle memory.

Live or suspected cyber incident

Don't fill the form. Call us.

If systems are compromised or you've seen suspicious activity, time matters. Talk to a senior consultant straight away, on the phone, before anything else.