
Incident Response and Digital Forensics
A team on call for the day it happens - and the evidence to explain it afterwards.
A team on call for the day it happens - and the evidence to explain it afterwards.
How this is bought: Bought as a monthly managed service on a rolling term, with a written service schedule. Build an estimate for your case.
Response times apply to clients holding a signed retainer. Without a retainer we respond on a best-efforts basis, subject to team availability.
These are the platforms we work with on client estates. Where a client already owns a different platform, we work with theirs - ARRIX is not tied to any one vendor.
Terms and contacts agreed in advance so the clock starts at the incident, not at the contract.
Stopping the spread, removing the foothold, and confirming it is gone.
Images, logs and chain of custody kept so findings stand up to challenge.
What entered, when, how far it reached and what left.
The written account each party requires, within their deadline.
We follow the structure and controls these standards describe. We do not claim to be certified against them - where you need a formal certificate, we prepare the evidence and an accredited body performs the audit.
These are the areas clients most often ask us to improve. Your project sets its own targets, measured and agreed with you.
Response work begins from a signed engagement letter that sets scope, our authority to act, evidence handling, confidentiality, liability limits and insurance. Nothing in these pages is a promise of prevention or of a particular outcome; cyber incidents are adversarial and results depend on facts outside anyone’s control. Where a cyber insurer is involved, we work to the terms of your policy and coordinate with your appointed counsel.