Don't fill the form. Call us.
If your systems are compromised, or you've seen activity that shouldn't be there, time matters more than process. Talk to a senior consultant on the phone, now. Everything else can wait.
The first hour: containment, while you're still on the call.
What we take care of in the first hour, so you can focus on your organisation rather than fighting the wrong fire.
Senior consultant on the call within the hour
A consultant who has run incidents before, not a triage script. We take the call, take ownership, and start co-ordinating from the first ten minutes.
Network isolation and account containment
Stop lateral movement. Isolate compromised segments, disable affected accounts, rotate credentials, and stand up out-of-band communications if email is suspect.
Insurer and counsel co-ordination
Most policies require notification within hours. We co-ordinate with your cyber insurer, legal counsel, and the ICO 72-hour reporting clock if personal data is in scope.

What happened, how, and what it touched.
The forensic work that turns a chaotic event into a clear written narrative your insurer, your board, and your regulator can act on.
- Forensic image and evidence preservation
We image affected systems before they're rebuilt, preserve memory and logs, and document the chain of custody so findings hold up with insurers, regulators, or a tribunal.
- Root cause and scope
What got in. How. When. What it touched. We trace the attack across systems and accounts so the rebuild closes the path, not just the symptom.
- Indicators of compromise across your estate
We hunt for related artefacts across endpoints, cloud, and identity to confirm the incident is contained and not just visibly stopped.
Back to operating, stronger than before.
The work that gets your organisation running again, with the controls in place to prevent the next call.
Rebuild, not just restore
Restoring from backups isn't enough if the backup is compromised. We rebuild affected systems from known-good state with the controls that prevent re-entry.
Business continuity while we work
Parallel operations where possible. Reduced-capacity workarounds. A clear written status to your leadership and your customers if external comms are needed.
Identity, MFA, and access hardened
Credentials rotated, MFA enforced, conditional access tightened, privilege reduced. The hardening that was missing before, applied now.
Post-incident, when the adrenaline has dropped.
The work many providers stop short of, and the work that turns a difficult week into a stronger organisation.
Post-incident review the board reads
Written, plain-language, with the timeline, the cost, the controls that worked, and the controls that didn't. Designed for a board meeting, not an audit appendix.
Controls strengthened
We map the gap that let the incident happen against your control framework (Cyber Essentials, ISO 27001, NHS DSPT) and close it with evidence.
Tested, not assumed
We schedule a tabletop exercise three to six months later to verify the controls hold, the runbooks work, and the team remembers the muscle memory.
A real call, and a real outcome.
Anonymised. The numbers are real wherever they appear; we don’t invent metrics, and we don’t share anything our clients wouldn’t.
Don't fill the form. Call us.
If systems are compromised or you've seen suspicious activity, time matters. Talk to a senior consultant straight away, on the phone, before anything else.
