Operations and defence (CyberOps)

Incident response

Containment, eradication and recovery from incidents, on retainer or on demand.

What it involves

What we do

When an incident occurs, every hour counts. We activate a response team that contains the attack, preserves evidence, eradicates the adversary, coordinates recovery and meets notification deadlines.

Flujo de operación: fuentes, plataforma, analistas y respuesta Red · Firewall Endpoints · EDR Cloud · Identidad DNS · Correo OT · Aplicaciones SIEM · XDR Correlación Inteligencia Casos de uso MITRE ATT&CK SOC 24×7 Triaje · investigación Threat hunting Respuesta Contención · erradicación Notificación · informe Dirección Regulador

Operating flow: telemetry sources, correlation platform, analysts and coordinated response.

What's included

  • Response retainer with committed activation times
  • Containment and eradication
  • Forensic analysis and evidence preservation
  • Coordination with management, legal, communications and authorities
  • Notification to regulators (NIS2, DORA, GDPR, ENS)
  • Post-incident report and lessons learned

Who it's for

  • Organisations that need a team ready to act
  • Entities with time-bound notification obligations
  • Companies suffering an incident right now

Deliverables

  • Incident response plan
  • Playbooks by incident type
  • Forensic and post-incident report

Reference frameworks and standards

NIST SP 800-61ISO 27035ENSNIS2DORA

Reference frameworks used to design, implement, review and evidence. They are not presented as our own certifications unless contractually applicable.

How we approach it

  1. DiscoverWe get to know your business, environment, risks and priorities.
  2. AnalyseWe assess maturity, exposure, compliance and real capabilities.
  3. DesignWe define strategy, roadmap, architecture and action plan.
  4. ImplementWe deliver controls, processes, technology and evidence.
  5. OperateWe monitor, respond and support continuous improvement.
  6. OptimiseWe measure results, reduce risk and evolve capabilities.

Let's talk

Does Incident response fit your situation?

Tell us about your challenges and let's design together the best strategy to protect and strengthen your business.