Incident Response
Under attack? We contain it, then make sure it stays gone
In an active incident, every hour of delay costs money. Our Rapid Response team, delivered with Sophos’s 24/7 incident responders, deploys quickly to triage, contain and remove the threat. If you only suspect something is wrong, a Compromise Assessment tells you for certain whether an attacker is, or was, inside your network.
Who we help
- Organizations hit by ransomware, business email compromise or a suspected breach
- Businesses that have seen strange logins, unexpected encryption or missing funds
- Companies that need proof they are clean after an incident, or before an acquisition
What's included
What you get.
Rapid Response: triage and containment
Remote incident responders, threat-intelligence analysts and threat hunters take immediate action to triage, contain and remove active threats.
Rapid Response: 45 days of monitoring
After the incident, 45 days of ongoing threat monitoring and response, so any return of the attacker is handled immediately.
Rapid Response: fixed-fee pricing
The price is set by the number of users and servers in your environment, so remediation costs are known up front, even in a crisis.
Compromise Assessment: hunt
Threat hunters and response specialists check whether an attacker is operating undetected in your environment, now or in the past.
Compromise Assessment: scope and impact
We establish how far the threat reached and quantify the risk of a widespread incident.
Compromise Assessment: report
A written report with technical evidence for your IT team and a plain-language executive summary for leadership, insurers and counsel. If we find an attacker, we move straight into Rapid Response.
Deliverables
What you can hold us to.
Concrete outputs, not vague promises.
- Immediate triage call when you reach us
- Containment and removal of active threats
- Root-cause and scope findings to support breach-notification decisions
- A hardening plan so the same thing does not happen again
Questions
Common questions.
Should we pay the ransom?
Do not decide in the first hour. Call us, and call your cyber insurer if you have one. Paying does not guarantee recovery, and it may carry legal risk. We will help you assess backups and recovery options first.
Do we have to report a breach?
In Canada, organizations covered by PIPEDA must report breaches of security safeguards that create a real risk of significant harm to the Privacy Commissioner of Canada and notify affected individuals. Alberta’s PIPA and Health Information Act have their own notification requirements. Our investigation gives you and your legal counsel the facts needed to make that decision.
What should we do right now?
Do not power off affected machines; disconnect them from the network instead. Do not wipe anything. Preserve logs, and call us at the number above.
Works well with
Related services.
Managed Detection & Response (MDR)
24/7 threat hunting and response by analysts who act, not just alert.
Learn more →Govern & recoverBackup & Disaster Recovery (BCDR)
Tested backups and a recovery plan that works when it matters.
Learn more →Govern & recovervCISO Services
Senior security leadership, policy and risk management, part-time.
Learn more →Let's talk about your IT and security.
Book a free 30-minute assessment. We will look at where you stand, what your insurer and clients expect, and the few things worth fixing first. No obligation.