Skip to content

Cybersecurity

Security monitoring and incident response

When an incident happens, every hour counts. We watch the alerts from your security tools and, if something happens, help you contain it, get back to work and understand what went wrong.

What is included

  • Alert monitoring

    Review of alerts from EDR, email and accounts to spot suspicious activity.

  • Incident response

    Containing infected devices, locking compromised accounts and cutting off the attacker’s access.

  • Recovery

    Restoring from backups, cleaning devices and an orderly return to operations.

  • Post-incident analysis

    What happened, how the attacker got in and which changes prevent a repeat.

  • Threat tracking

    Keeping an eye on threats relevant to your sector and adjusting protections in advance.

  • Response plan

    A written procedure so everyone knows who does what if an incident happens.

Problems we solve

  • An email account started sending messages nobody wrote.
  • Encrypted files and a note demanding a ransom.
  • Security alerts going to an inbox nobody reads.
  • No plan for what to do if you are attacked.

How we work

  1. Contain

    We isolate affected devices and accounts to stop the damage.

  2. Investigate

    We establish the scope: which systems and data were affected.

  3. Recover

    We restore services and data, and confirm the attacker no longer has access.

  4. Learn

    We deliver a report and strengthen protections.

In detail

Acting fast without making things worse

During an incident it is easy to destroy evidence or reinstall a device before understanding how the attacker got in. We follow a clear order: contain, investigate, recover and learn. That limits the damage and keeps the same problem from returning the following week.

What we do, and what we don’t

We monitor alerts from the security tools we manage and respond to incidents. We are not a corporate security operations centre (SOC) with dedicated staff on shifts; for organisations that need one, we help evaluate and integrate a specialised service.

Tools we work with

  • Microsoft Defender
  • SentinelOne
  • Guardz
  • Microsoft 365
  • Datto
  • Axcient

Tools we know first-hand. They do not represent partnerships or company certifications.

Frequently asked questions

What should I do if I think we’ve been attacked?

Message us on WhatsApp straight away. In the meantime, don’t switch off affected devices, disconnect them from the network and don’t pay any ransom.

Can you handle an incident even if we’re not clients?

Yes. We respond to incidents for new companies too and, once the situation is under control, propose how to prevent the next one.

Interested in this service?

Tell us about your situation and we will reply with next steps and a clear quote.