Incident response, on retainer or on call.
Six-stage IR aligned to NIST SP 800-61r3 and NCSC guidance. Retainer customers get a four-hour first response. We handle ransomware, BEC, insider threats and data-breach response.

What we mean by incident response
Incident response is the structured work of detecting, containing, eradicating, and recovering from a security incident — and producing the documentation that customers, regulators, insurers and auditors will expect to see. It is a programme, not a single phone call.
Methodology aligned to NIST SP 800-61 Rev 3 (April 2025, current revision), the NCSC Incident Management collection, and ISO/IEC 27035-1:2023. Retainer customers get a contractual four-hour first-response SLA; per-engagement work has no committed SLA but is delivered by the same team.
Key facts
- Retainer first response
- 4hr
- IR phases
- 6
- UK GDPR breach window
- 72hr
- NIST reference
- 800-61r3
How we engage
Four engagement modes covering the full IR lifecycle — from preparation to active response and exercise.
IR retainer
Pre-agreed contract with a four-hour first-response SLA. Annual tabletop exercises, IR plan reviews, and contact-tree maintenance included.
Per-engagement IR
Active-incident engagement scoped on call. No committed SLA without a retainer, but the IR team you reach is the same team.
IR plan & playbook authoring
Documented incident response plan and tailored playbooks for ransomware, BEC, insider threats, and data-breach scenarios.
Tabletop exercises
Facilitated exercises for leadership and responders. Findings logged and tracked into your IR programme.
How an engagement runs
Five stages from scoping to closure. Most of the value is in the first two stages, before anything has gone wrong.
- 1
Scoping call
30 minutes, freeRetainer vs per-engagement, scope boundary, on-call pathway. We do not push everyone to a retainer — if you have a small environment and low risk profile, a per-engagement arrangement may be the right answer.
- 2
Retainer setup
1–2 weeksIR plan review, contact tree, evidence-handling procedures, tabletop scheduling. We hand over a written runbook so you know who to call and what to say at 02:00.
- 3
Activation
4-hour first response (retainer)On retainer activation, a first responder is engaged within four hours. Live-call bridge opened, triage in progress, scoping confirmed. Per-engagement work has no committed SLA — we scope on the call.
- 4
Containment & eradication
VariableSix-stage IR per NIST SP 800-61r3 and NCSC guidance. Daily updates to your nominated executive sponsor. Evidence handling per chain-of-custody procedures throughout.
- 5
Closure & lessons learned
2–4 weeks post-incidentFinal report covering timeline, impact, root cause, and prioritised follow-up actions. Lessons-learned workshop with leadership. Chain-of-custody handoff if forensic material is being retained.
The six IR phases
The classical incident response phases — preparation through lessons learned. Cross-referenced from NIST SP 800-61r3, the NCSC Incident Management collection, and ISO/IEC 27035-1:2023.
Why 1 Sequence Cyber
Standards-aligned, not improvised
Methodology aligned to NIST SP 800-61 Rev 3 (April 2025), the NCSC Incident Management collection, and ISO/IEC 27035-1:2023. The frameworks are not branding — they are the structure auditors and regulators recognise.
Same firm that runs the audit
PCI DSS Requirement 12.10 (incident response plan), ISO 27001 Annex A controls 5.24-5.30, and UK GDPR Article 33 breach notification all need IR evidence. Our QSAC and ISMS lead-implementer teams know what that evidence has to look like.
Frequently asked questions
Related services: SOC as a Service · Penetration Testing · business continuity & DR.
Need IR cover?
Active incident: call us. Considering a retainer: book a scoping call. We’ll come back with a proposal within 48 hours.
Back to all services.