Incident response and digital forensics

Incident response is the work done once something has already happened: confirm it, contain it, find out how far it reached and preserve the evidence. Digital forensics is the evidence half of that work, reconstructing what the intruder did from disks, memory, logs and network traffic. We coordinate both with your people, your counsel and your insurer.

What incident response covers

Triage settles whether this is an incident at all and how serious it is. Containment cuts the intruder off without destroying what you will need later, which usually means isolating at the network rather than switching machines off. Scoping answers the question everyone asks next: which systems, which accounts, which data, and since when.

Recovery follows from the scope. Restoring before the entry point is known is how an organization gets compromised twice in a month.

How digital forensic analysis works

Disks are imaged and hashed, and the analysis runs on the copy, never the original. Memory captured before shutdown shows running malware, injected code and live network connections that the disk never records. Packet captures and network flow logs, where they exist, show what left the building.

Logs often decide the case: the identity provider, the Microsoft 365 audit log, cloud control-plane logs, the EDR console. Each has its own retention clock, so preservation starts on day one. The first decisions are set out in preserving evidence after a breach.

Mapping the intrusion to MITRE ATT&CK

Findings are written as a timeline and mapped to MITRE ATT&CK techniques: how the intruder got in, how they persisted, how they moved and what they took. The mapping turns one bad week into a detection backlog, and it feeds directly into threat-informed defence.

Working with counsel, insurers and police

Many organizations have counsel engage the forensic work. Whether privilege attaches is counsel’s call, not ours. Insurers want a scoping statement and a timeline they can read. If you report to police, we can prepare the evidence package and act as the technical contact; what that involves is covered in working with police after a cyber incident.

Incident response versus incident readiness

This page is about responding. Plans, playbooks and rehearsal before anything happens are incident response readiness and tabletop exercises. The readiness work is what makes the response fast.

What you receive

  • An incident timeline, kept from the first call
  • A scoping statement: affected systems, accounts and data
  • An evidence register with hashes and chain of custody
  • Findings mapped to ATT&CK, including the most likely entry point and how confident the evidence lets us be
  • A containment and hardening list, sequenced
  • A report written for counsel and the insurer

How the work is bounded

The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.

Investigation and forensic work is delivered with appropriately licensed partners where the law requires it.

SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.

Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.

Questions we are asked

What should we do if we are in an incident right now?

Call your counsel and your insurer first, then us. Many cyber policies name panel responders, so check the policy before you engage anyone, including us, or the response may not be covered.

Are you available 24/7?

No. We are not a 24/7 retainer SOC. Response hours, named contacts and a callback commitment can be agreed in advance under a written retainer; without one, we tell you on the first call when we can start.

Who carries out the forensic work?

Investigation and forensic work is delivered with appropriately licensed partners where the law requires it, and the engagement is structured that way before any evidence is touched.

Will you decide whether we have to notify?

No. We are not lawyers; we work alongside your counsel. Whether a breach must be reported to a privacy regulator or to the people affected is counsel’s determination, and our part is to give them facts they can rely on.

Talk to us about an incident

The contact form is not an emergency channel, and replies come within one business day. If you are in an active incident, call your counsel and your insurer first. To arrange support, tell us what was observed, when, and who has been told so far; the reply says what we can take on and how soon. See also all security services.

Discuss incident support