Incident Response & Cyber Recovery
When an attack hits, have experienced responders on your side fast to contain the damage, restore operations safely and come out stronger than before.
Is this for you?
You might need this if…
If ransomware hit tomorrow, you’re not sure who you would call or who would make the decisions.
Your incident response plan exists on paper but has never been tested with management.
You suspect a breach, such as unusual logins, encrypted files or a warning from a supplier, and need answers now.
NIS2, DORA or GDPR require you to report serious incidents quickly, and you don’t know how you would gather the facts in time.
What we deliver
What it covers
Incident response retainer
Agreed in advance, a retainer gives you access to experienced responders with defined response times. Contracts, contacts and access are already in place, so no time is lost when an incident starts.
Digital forensics
We collect and analyse evidence from devices, servers, cloud services and logs to establish what happened, how the attacker got in and which data was affected. Evidence is handled so it can support regulatory reporting, insurance claims and legal action.
Ransomware response and recovery
We contain the attack, establish what was hit and plan a safe recovery from clean backups, rebuilding critical systems in priority order. We also support management with the difficult decisions and communication with authorities that follow.
Crisis management and tabletop exercises
We help set up crisis management with clear plans and roles, then test them in realistic scenario exercises with management and technical teams. People learn their role before they need it for real.
Lessons learned and resilience improvement
After an incident or exercise, we analyse root causes and what worked, and turn the findings into concrete improvements. Each event leaves you better protected than before.
Our approach
How we work
01
Prepare
Plans, playbooks, contacts and a retainer in place before anything happens, tested through exercises.
02
Respond
Triage, containment and forensic investigation to stop the attack and understand its scope.
03
Recover
Systems restored from verified clean backups in business-priority order, with the attacker’s access removed.
04
Improve
A lessons-learned review turns root causes into hardening, better detection and updated plans.
Best practices
What we bring to every engagement
Prepare before you need it
A retainer, contact lists and pre-approved access save critical hours when an incident starts.
Contain before you clean
Stopping the spread comes first; investigation and remediation follow in a controlled order.
Preserve the evidence
Forensic data is secured before systems are rebuilt, so you can understand the attack and meet reporting obligations.
Recover clean, not just fast
Restoring from a compromised backup or leaving the attacker’s access in place only restarts the incident.
Communicate out of band
Assume email and chat may be compromised, and have alternative channels ready for the crisis team.
Exercise with management
Decisions on shutdowns, communication and reporting belong to leadership, and they need practice.
Outcomes
What you get
- An incident response plan and playbooks for likely scenarios
- A retainer with agreed contacts and response times
- Forensic findings on what happened and what was affected
- Systems restored from verified clean backups
- Support for reporting to authorities, insurers and customers
- A lessons-learned report with concrete improvements
AI-powered
Unleash the power of AI
We offer the possibility of using AI throughout this work: ready-to-use AI tools, or a customised version built for your organisation that can run inside your own infrastructure. In incident response, AI processes large volumes of logs and forensic data to reconstruct timelines, spots indicators of compromise across systems and drafts incident reports, so responders reach the root cause and meet reporting needs faster.
Starter offer
Incident Readiness Assessment
A fixed-scope, four-week engagement that tests how prepared you are for a serious cyberattack and leaves you with an updated plan and a team that has practised it.
Week 1
Review
Kick-off and review of current incident response plans, roles, backups, logging and reporting routines.
Week 2
Analyse
Interviews with IT, management and key suppliers to find gaps in detection, decision-making and recovery.
Week 3
Exercise
A realistic tabletop exercise, such as a ransomware scenario, with management and technical teams.
Week 4
Improve
An updated plan, key playbooks and recommendations presented to management, with clear next steps.
You receive
- An assessment of your incident readiness
- A tabletop exercise with management and technical teams
- An updated incident response plan and key playbooks
- A prioritised list of improvements
FAQ
Frequently asked questions
We think we’re under attack right now. What should we do?
Contact us straight away. Avoid switching off affected systems unless they are actively spreading the attack; isolate them from the network instead, so evidence is preserved. We will help you decide the next steps and bring in the right responders.
How long does recovery from ransomware take?
It depends on how far the attack spread and on the state of your backups. Critical systems can sometimes be restored within days, while full recovery and hardening often take weeks; preparation and tested backups make the biggest difference.
What does an incident response retainer include?
Typically a number of hours, agreed response times, onboarding so responders understand your environment in advance, and named contacts. Depending on the agreement, unused hours can be put towards exercises or readiness work.
How does Altechy coordinate an incident?
You get a single point of contact who coordinates responders and forensic specialists from our partner network with your IT team, existing suppliers, insurer and legal advisers. Everyone works from one picture of the situation, so decisions are made quickly.
Related services
Security Operations (SOC & MDR) Backup & Disaster Recovery Security Strategy, Risk & Compliance Offensive Security & Testing OT & IoT Security Cloud, Network & Data Security
Let’s prepare for your worst day
Book a free 60-minute idea session. We explore your challenges and opportunities with you, and suggest where to start — with no obligation.