Skip to main content

Managed Security Services

Cyber Forensics & Incident Response

Containment, evidence preservation, forensic analysis and recovery support.

Incident Response as-a-Service

Every engagement includes manual validation, a two audience report and free re-testing.

Get a scoped quote+91 96682 00222

What this actually is

When it happens, the first hour matters more than the next month. Wrong moves early destroy the evidence you will need and sometimes make the containment worse.

We respond, contain and recover, and we do it in a way that preserves the trail so you can answer your regulator, your insurer and your board afterwards.

Retainer clients get a named team who already know their estate. That is the difference between a response starting immediately and a response starting after four hours of onboarding.

What we go after

  • Immediate triage and severity assessment
  • Evidence preservation before containment
  • Containment and eradication
  • Malware and ransomware analysis
  • Recovery planning and validation
  • Regulatory notification support within required timelines
  • Post-incident review and hardening
  • Communications support for internal and external audiences

How we run it

  1. 01

    Onboard

    Log sources, agents and integrations connected, with a baseline of what normal looks like for you.

  2. 02

    Tune

    Detection rules written for your environment. We would rather spend two weeks tuning than send you noise for a year.

  3. 03

    Monitor

    Round the clock triage with severity-based response times, including nights and weekends.

  4. 04

    Respond

    Playbook-driven containment with approval gates on anything that touches production.

  5. 05

    Report and improve

    Monthly reporting your board understands, and detection coverage that grows every quarter.

What you receive

  • Incident timeline and impact assessment
  • Containment and eradication actions log
  • Forensic report suitable for regulator and insurer
  • Recovery validation
  • Post-incident hardening plan

Who needs this

Everyone, ideally before they need it. Retainers exist so the call is already answered when the day comes.

How long it takes

Response begins within hours for retainer clients, same or next business day otherwise.

Standards this satisfies

  • NIST SP 800-61
  • ISO 27035
  • CERT-In reporting
  • DPDP Act

Why it matters

Detection is not a product you buy, it is a capability you operate. Most organisations that have bought the tooling still do not have the capability, because coverage thins overnight and at weekends, which is precisely when intrusions begin.

Dwell time is the single largest driver of what a breach costs. Everything managed defence does is aimed at that one number: seeing it sooner, understanding it faster, and containing it before it becomes a recovery exercise.

Choose how you want this delivered

Most of the price difference between quotes comes down to this one choice, and it is rarely explained. Pick one to see what it covers, what it suits and what it costs you.

We take monitoring, triage, investigation and first response, around the clock, with a named service lead who knows your environment. Escalation reaches a person with context rather than a queue, which is the difference that matters at three in the morning.

Choose this when

  • No internal security operations capability
  • Regulatory expectation of continuous monitoring
  • You want one accountable party for detection and response

Effort and cost

Monthly, scaled by estate size and log volume. Predictable, which is usually the point.

Scope it yourself, before you call anyone

Answer a few questions and you get an indicative number, the working behind it and what your answers tell us. It runs in your browser, so nothing you type reaches us.

1/5

Roughly how many personal records do you hold?

What we look for, and keep finding

These are the classes of problem this work exists to surface. Not every engagement finds all of them, but these are the ones that turn up often enough to be worth naming.

  • Coverage gaps in telemetry

    Systems producing no logs, or logs going nowhere. You cannot detect what you cannot see, and the gaps are almost never in the systems people expect.

  • Alerts nobody acts on

    High volume, low value alerting that trains analysts to dismiss. We tune for what is actionable rather than for what is easy to generate.

  • Detection that has never been validated

    Rules written against a threat model and never tested against the actual technique. We validate detections by performing the action and confirming it fires.

  • Handover and out of hours weakness

    Most incidents begin outside working hours. Coverage that degrades at night or across a shift change is where dwell time comes from.

  • No path from alert to containment

    Detection without the authority or the runbook to act. Knowing sooner is worth little if the response still waits for a meeting.

Who runs your engagement

A named service lead and a real team behind them

You get a named lead who knows your environment, backed by an analyst team running around the clock. Escalation reaches a person who has context rather than a queue, which is the difference that matters at three in the morning.

Questions we get asked

Should we pay a ransom?

That is your decision and it has legal and practical dimensions we will walk through with you. What we will tell you honestly is whether decryption is likely to work, whether the data is already gone, and what recovery without payment looks like.

How fast must we report to CERT-In?

Within six hours of noticing, for the incident types the directions specify. That clock is short, which is why the reporting workflow needs to exist before the incident rather than during it.

Ready to scope your cyber forensics & incident response?

Thirty minutes with a senior engineer, and you leave with a written scope and indicative effort.