Incident Response

24x7 containment, eradication, and recovery during active breaches. CSIRT-aligned, seven-phase framework — built to stop the bleeding fast, then put you back on solid ground.

Active breach? Call +47 94 10 20 30 or use DFIR Emergency now. Read the rest once contained.

CSIRT phases

Our response follows the recognised seven-phase CSIRT lifecycle. Each phase has owners, runbooks, and clear exit criteria so the engagement always moves forward.

  1. PreparationPlans, playbooks, tooling, and a drilled team ready before the call comes.
  2. IdentificationDetection, triage, and scope assessment to confirm the incident and its blast radius.
  3. ContainmentStop the bleeding — short-term isolation first, then a strategic containment posture.
  4. EradicationRemove the attacker, persistence mechanisms, and the vulnerabilities they exploited.
  5. RecoveryRestore services with confidence, verify integrity, and monitor for re-entry.
  6. Lessons learnedStructured post-incident review that turns the event into structural improvements.
  7. ReportingBrief stakeholders, regulators, and insurers — appropriately scoped and evidence-backed.

Contain & remediate

The operational heart of a live response: Take control of the environment, evict the adversary, and rebuild trust in the systems you depend on.

Containment

Limit damage and deny the attacker freedom of movement while we preserve the evidence the investigation needs.

  • Isolate systemsSegment or quarantine affected hosts without tipping off the intruder.
  • Block trafficCut command-and-control and lateral pathways at the network edge.
  • Disable accountsSuspend compromised identities, rotate keys, and revoke active sessions.

Eradication & remediation

Once contained, remove the root cause for good and close the gaps that let the incident happen.

  • Eradicate malwareRemove implants, web shells, and every persistence foothold.
  • Patch & hardenFix exploited vulnerabilities and tighten exposed configurations.
  • Reset credentialsForce enterprise-wide rotation where compromise is suspected.

Recovery

Bring operations back deliberately, verifying integrity at each step rather than rushing systems online.

  • Restore from clean backupsRebuild from a known-good state, never the compromised one.
  • Verify integrityValidate systems and data before they re-enter production.
  • Heightened monitoringWatch closely for re-entry through the post-incident window.

NIST CSF functions

Response does not stand alone. We map each engagement to the NIST Cybersecurity Framework functions, so containment today strengthens your posture tomorrow.

  • IdentifyKnow your assets, risks, and threat landscape before an incident strikes.
  • ProtectSafeguards, patching, and access controls that shrink the attack surface.
  • DetectContinuous monitoring and testing to surface anomalies fast.
  • RespondContain, eradicate, and communicate under a rehearsed incident plan.
  • RecoverRestore services and integrity, then fold lessons back in.
  • GovernResourcing, accountability, and oversight that keep defences current.
Preparedness is its own discipline. Building the readiness behind these functions — drills, plans, and culture — is covered in depth on our Preparedness service page.

Lessons learned

Every engagement closes with a blameless review that converts a hard day into lasting resilience.

  • Root-cause reviewTrace the full attack path and the conditions that enabled it.
  • Structural improvementsConcrete fixes to controls, detection, and process.
  • Playbook updatesFeed findings back into runbooks and future drills.
π