
Detection, Response and Recovery
Assuming something will get through, and being ready to see it, stop it, and come back.
Assuming something will get through, and being ready to see it, stop it, and come back.
How this is bought: Bought as a defined project to set it up, then a monthly managed service to run it. Build an estimate for your case.
Logs gathered in one place where patterns across systems become visible.
Writing and tuning rules against real attacker behaviour, mapped to MITRE ATT&CK techniques.
Written response steps, partly automated, so the first hour does not depend on who is awake.
Roles, thresholds, evidence handling and communication lines agreed in advance, following NIST SP 800-61.
Log retention and evidence preservation sufficient to reconstruct what happened.
Copies that cannot be altered or deleted for a set period, tested by actually restoring.
Recovery time and recovery point objectives (RTO / RPO) agreed with the business, not assumed by IT.
Walking through a realistic incident with the people who would handle it, before it is real.
Knowing who must be told, in what form, and inside what deadline.
We follow the structure and controls these standards describe. We do not claim to be certified against them - where you need a formal certificate, we prepare the evidence and an accredited body performs the audit.
These are the areas clients most often ask us to improve. Your project sets its own targets, measured and agreed with you.