Incident Response
Active breach? We respond within 30 minutes.
Rapid-response cybersecurity engagement for active or suspected incidents. We contain, eradicate, and recover — then run a forensic post-mortem so it doesn't happen twice. 30-minute response SLA when retained in advance.
ROE signed before any work · 30 minutes response
The problem
A signed retainer isn't the same as a rehearsed one.
Retainers that were never tested
The named contact from onboarding left the company, the pre-provisioned access expired with a credential rotation nobody re-tested, or the trigger table was written but never reviewed by whoever is actually on call at 2 a.m. A retainer is only as fast as its last rehearsal.
Cold engagements start from zero
Without a retainer, the first hour goes to getting oriented — confirming scope, requesting access, understanding the stack — before containment work can even begin. That's the hour a live foothold does the most damage.
Generalist responders without stack or industry context
A responder who has never worked your platform, your compliance obligations, or your architecture spends billable hours re-learning what a retained team already knew going in.
Notification clocks that don't pause for forensics
GDPR's 72-hour and NIS2's 24-hour reporting windows start counting from the moment you're aware of an incident, not once containment finishes — a response that only produces a regulator-ready report at the very end is already behind the clock.
Scope of work
What's included
Everything below is delivered by senior engineers — no scanner-only reports, no junior hand-offs.
- 30-minute response time when on retainer
- Immediate triage and containment
- Eradication of attacker presence
- Forensic timeline reconstruction
- Recovery validation and hardening recommendations
- Post-incident report for regulators and stakeholders
Methodology
How we run it
- 01Triage: classify severity and contain spread
- 02Eradicate attacker presence and persistence
- 03Recover affected systems with hardened baselines
- 04Forensic analysis with full attacker timeline
- 05Post-incident hardening to prevent recurrence
Comparison
IR retainer vs cold call.
| Feature | AnySec | Generic firm | DIY |
|---|---|---|---|
| Response time | 30 min on retainer | 4–24 hours typical | Hours to days |
| Pre-engagement context | We know your stack already | Start from zero | Your team in firefight mode |
| Regulator-ready reporting | Included | Add-on | Your responsibility |
“AnySec was on a Zoom with our SOC 23 minutes after our pager fired. Within 90 minutes the attacker had no live foothold. Game-changing.”
— Director of Security · European fintech (Series C)
Deliverables
What you receive
- Forensic timeline with attacker actions
- Containment and recovery documentation
- Hardening recommendations
- Regulator-ready incident report
Our commitments
Skin in the game.
- 30-minute SLA on retainer — refunded if missed
- Direct senior engineer on every escalation, no triage queue
- Regulator-ready report within 5 business days of containment
FAQ
Questions we get asked
Can we retain you in advance?+
Yes — and you should. Advance retainers get the 30-minute SLA. Cold engagements still get rapid response but no formal SLA.
Do you coordinate with law enforcement?+
If you direct us to. We never contact law enforcement without your authorization.
What counts as an incident worth calling you for?+
Ransomware or suspected ransomware, a confirmed intrusion, data exfiltration, suspicious privileged-account activity, or a DDoS beyond your provider's capacity. Call early — a false alarm costs far less than a foothold that spreads while you deliberate.
Do you help with GDPR or NIS2 breach notification?+
Yes. We produce a regulator-ready incident report and help you meet notification timelines, including the GDPR 72-hour window and NIS2 reporting obligations for in-scope entities.
What do you need from us to start?+
A point of contact, access to the affected systems, and a signed engagement. On a retainer we collect all of this in advance, which is what makes the 30-minute SLA real — a cold engagement spends its first hour just getting oriented.
More from AnySec
Related cybersecurity services
Incident Response pairs with the rest of the AnySec catalog — offensive testing, 24/7 defensive operations, incident response, and resilient infrastructure, all delivered by the same EU-registered team.
Response · IR-RAPID
Ready to start Incident Response?
Request a fixed quote, or book a free 30-minute scoping call first. 30 minutes response either way.
ROE signed before any test fires · varies (rapid response)




