Security Incident Response

Incident response, on retainer or on call.

Six-stage IR aligned to NIST SP 800-61r3 and NCSC guidance. Retainer customers get a four-hour first response. We handle ransomware, BEC, insider threats and data-breach response.

A monitor displaying analytics charts in a dark room, illustrating live incident triage

What we mean by incident response

Incident response is the structured work of detecting, containing, eradicating, and recovering from a security incident — and producing the documentation that customers, regulators, insurers and auditors will expect to see. It is a programme, not a single phone call.

Methodology aligned to NIST SP 800-61 Rev 3 (April 2025, current revision), the NCSC Incident Management collection, and ISO/IEC 27035-1:2023. Retainer customers get a contractual four-hour first-response SLA; per-engagement work has no committed SLA but is delivered by the same team.

Key facts

Retainer first response
4hr
IR phases
6
UK GDPR breach window
72hr
NIST reference
800-61r3

How we engage

Four engagement modes covering the full IR lifecycle — from preparation to active response and exercise.

IR retainer

Pre-agreed contract with a four-hour first-response SLA. Annual tabletop exercises, IR plan reviews, and contact-tree maintenance included.

Per-engagement IR

Active-incident engagement scoped on call. No committed SLA without a retainer, but the IR team you reach is the same team.

IR plan & playbook authoring

Documented incident response plan and tailored playbooks for ransomware, BEC, insider threats, and data-breach scenarios.

Tabletop exercises

Facilitated exercises for leadership and responders. Findings logged and tracked into your IR programme.

How an engagement runs

Five stages from scoping to closure. Most of the value is in the first two stages, before anything has gone wrong.

  1. 1

    Scoping call

    30 minutes, free

    Retainer vs per-engagement, scope boundary, on-call pathway. We do not push everyone to a retainer — if you have a small environment and low risk profile, a per-engagement arrangement may be the right answer.

  2. 2

    Retainer setup

    1–2 weeks

    IR plan review, contact tree, evidence-handling procedures, tabletop scheduling. We hand over a written runbook so you know who to call and what to say at 02:00.

  3. 3

    Activation

    4-hour first response (retainer)

    On retainer activation, a first responder is engaged within four hours. Live-call bridge opened, triage in progress, scoping confirmed. Per-engagement work has no committed SLA — we scope on the call.

  4. 4

    Containment & eradication

    Variable

    Six-stage IR per NIST SP 800-61r3 and NCSC guidance. Daily updates to your nominated executive sponsor. Evidence handling per chain-of-custody procedures throughout.

  5. 5

    Closure & lessons learned

    2–4 weeks post-incident

    Final report covering timeline, impact, root cause, and prioritised follow-up actions. Lessons-learned workshop with leadership. Chain-of-custody handoff if forensic material is being retained.

The six IR phases

The classical incident response phases — preparation through lessons learned. Cross-referenced from NIST SP 800-61r3, the NCSC Incident Management collection, and ISO/IEC 27035-1:2023.

Why 1 Sequence Cyber

Standards-aligned, not improvised

Methodology aligned to NIST SP 800-61 Rev 3 (April 2025), the NCSC Incident Management collection, and ISO/IEC 27035-1:2023. The frameworks are not branding — they are the structure auditors and regulators recognise.

Same firm that runs the audit

PCI DSS Requirement 12.10 (incident response plan), ISO 27001 Annex A controls 5.24-5.30, and UK GDPR Article 33 breach notification all need IR evidence. Our QSAC and ISMS lead-implementer teams know what that evidence has to look like.

Frequently asked questions

Related services: SOC as a Service · Penetration Testing · business continuity & DR.

Need IR cover?

Active incident: call us. Considering a retainer: book a scoping call. We’ll come back with a proposal within 48 hours.

Back to all services.