Skip to content
8bytes

Breach response,
from minute one.

Containment, eradication, recovery. Available as a one-off engagement or as an on-call retainer for when the next call comes at 3am.

Engagement types

How we engage.

Four shapes of incident-response engagement, from immediate breach response through to ongoing retainer coverage. Pick the one that matches the situation.

Active breach response

Immediate, hands-on response to an unfolding incident. Containment, eradication, recovery — supporting your team or leading the response.

Forensic investigation

Post-incident or historical investigation. Disk, memory, and network forensics. Establish root cause and full scope of compromise.

Ransomware & extortion

Containment, decryption-key assessment, negotiation support, recovery planning. Coordinated handling with insurers and counsel.

IR retainer

Pre-arranged response capacity with defined SLAs. When the next call comes, we already know your environment, contacts, and runbook.

Methodology

How we work.

01

Triage & containment

Within hours: stop the bleeding. Isolate affected hosts, revoke compromised credentials, cut attacker access. Preserve evidence in the process.

02

Evidence preservation

Forensic-quality acquisition of disk, memory, and relevant logs. Chain of custody preserved in case litigation or law enforcement involvement follows.

03

Investigation & attribution

Reconstruct the attack timeline. Identify initial access, full scope of compromise, data accessed, and (where possible) attacker identity.

04

Eradication & recovery

Remove attacker persistence, rotate credentials at scope, validate clean state, restore services. Verify the attacker is actually out before recovery.

05

Post-incident reporting

Full timeline, root cause, and recommendations for the controls that would have prevented or detected the incident. Suitable for regulators where required.

Deliverables

What you receive.

Everything you need to fix what we found — and prove it to your auditors.

  • Incident timeline with reconstructed attacker actions
  • Root cause analysis identifying initial access vector
  • Forensic evidence package with chain of custody
  • Attacker TTP documentation mapped to MITRE ATT&CK
  • Hardening and detection recommendations to prevent recurrence
  • Regulator-ready report on request (GDPR, DPDP, HIPAA, etc.)

FAQs

Common questions.

01

How quickly can you respond?

Retainer clients get a guaranteed SLA — typically a senior responder on a call within 1 hour, hands-on within 4 hours. Non-retainer engagements are best-effort but we will tell you honestly what is available; if we cannot respond fast enough, we will name people who can.

02

Do you work with our existing tools (EDR, SIEM)?

Yes. Most engagements use the tooling already in your environment — your EDR, SIEM, and cloud-native logs. We bring our own forensic kit for evidence acquisition but plug into what you have for live response.

03

What if we are already breached when we call?

That is the most common case. Phase 1 (triage and containment) starts immediately. The first hour is about stopping further damage and preserving evidence — investigation and attribution come after the bleeding stops.

04

What does an IR retainer cost?

Retainers are sized based on the SLA, environment complexity, and prepaid response hours. Most mid-market clients land in a recurring quarterly arrangement. A 30-minute call lets us scope it accurately.

05

Do you communicate with law enforcement and regulators?

On your behalf where you ask us to. We coordinate with the relevant national CERTs, sector regulators, and law enforcement liaison units. We do not make those disclosures without your sign-off and your counsel in the loop.

Get in touch

Need a responder on call?

Book a call

Free 30-min scoping call. No commitment.