AnySec
All services
Response·varies (rapid response)

Incident Response

Active breach? We respond within 30 minutes.

Rapid-response cybersecurity engagement for active or suspected incidents. We contain, eradicate, and recover — then run a forensic post-mortem so it doesn't happen twice. 30-minute response SLA when retained in advance.

All sectors
From€3,500/ per incident

ROE signed before any work · 30 minutes response

30 min
Response SLA on retainer
24/7
Year-round availability
Regulator-ready
Reports drafted for EU + US frameworks

The problem

A signed retainer isn't the same as a rehearsed one.

Retainers that were never tested

The named contact from onboarding left the company, the pre-provisioned access expired with a credential rotation nobody re-tested, or the trigger table was written but never reviewed by whoever is actually on call at 2 a.m. A retainer is only as fast as its last rehearsal.

Cold engagements start from zero

Without a retainer, the first hour goes to getting oriented — confirming scope, requesting access, understanding the stack — before containment work can even begin. That's the hour a live foothold does the most damage.

Generalist responders without stack or industry context

A responder who has never worked your platform, your compliance obligations, or your architecture spends billable hours re-learning what a retained team already knew going in.

Notification clocks that don't pause for forensics

GDPR's 72-hour and NIS2's 24-hour reporting windows start counting from the moment you're aware of an incident, not once containment finishes — a response that only produces a regulator-ready report at the very end is already behind the clock.

Scope of work

What's included

Everything below is delivered by senior engineers — no scanner-only reports, no junior hand-offs.

  • 30-minute response time when on retainer
  • Immediate triage and containment
  • Eradication of attacker presence
  • Forensic timeline reconstruction
  • Recovery validation and hardening recommendations
  • Post-incident report for regulators and stakeholders

Methodology

How we run it

  1. 01Triage: classify severity and contain spread
  2. 02Eradicate attacker presence and persistence
  3. 03Recover affected systems with hardened baselines
  4. 04Forensic analysis with full attacker timeline
  5. 05Post-incident hardening to prevent recurrence

Comparison

IR retainer vs cold call.

FeatureAnySecGeneric firmDIY
Response time30 min on retainer4–24 hours typicalHours to days
Pre-engagement contextWe know your stack alreadyStart from zeroYour team in firefight mode
Regulator-ready reportingIncludedAdd-onYour responsibility
AnySec was on a Zoom with our SOC 23 minutes after our pager fired. Within 90 minutes the attacker had no live foothold. Game-changing.

Director of Security · European fintech (Series C)

Deliverables

What you receive

  • Forensic timeline with attacker actions
  • Containment and recovery documentation
  • Hardening recommendations
  • Regulator-ready incident report

Our commitments

Skin in the game.

  • 30-minute SLA on retainer — refunded if missed
  • Direct senior engineer on every escalation, no triage queue
  • Regulator-ready report within 5 business days of containment

FAQ

Questions we get asked

Can we retain you in advance?+

Yes — and you should. Advance retainers get the 30-minute SLA. Cold engagements still get rapid response but no formal SLA.

Do you coordinate with law enforcement?+

If you direct us to. We never contact law enforcement without your authorization.

What counts as an incident worth calling you for?+

Ransomware or suspected ransomware, a confirmed intrusion, data exfiltration, suspicious privileged-account activity, or a DDoS beyond your provider's capacity. Call early — a false alarm costs far less than a foothold that spreads while you deliberate.

Do you help with GDPR or NIS2 breach notification?+

Yes. We produce a regulator-ready incident report and help you meet notification timelines, including the GDPR 72-hour window and NIS2 reporting obligations for in-scope entities.

What do you need from us to start?+

A point of contact, access to the affected systems, and a signed engagement. On a retainer we collect all of this in advance, which is what makes the 30-minute SLA real — a cold engagement spends its first hour just getting oriented.

Response · IR-RAPID

Ready to start Incident Response?

Request a fixed quote, or book a free 30-minute scoping call first. 30 minutes response either way.

ROE signed before any test fires · varies (rapid response)

Incident Response
€3,500 · per incident