Skip to content

Home Expertise / Response & resilience

RES / RES-01

Incident response and digital investigation — DFIR

Help understand an incident, limit its effects, preserve useful evidence and prepare controlled recovery. Investigation separates established facts, hypotheses and missing data; it does not cover all legal or communication decisions on its own.

WHEN IT HELPS

A focused response
to a defined need.

Suspected compromise, ransomware, hijacked administrator account, suspected data leak or abnormal behaviour confirmed by the SOC.

AT A GLANCE

Family
Response & resilience

Engagement
Project or assistance

Reference
RES-01

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Emergency scoping
  • authorised collection
  • timeline
  • known scope
  • approved containment
  • root-cause investigation
  • evidence preservation
  • eradication and recovery recommendations
  • lessons learned

Deliverables

  • Decision log
  • evidence inventory
  • qualified timeline
  • situation report
  • recommendations
  • investigation report
  • recovery and remediation plan

Acceptance evidence

Investigated scope is explicit; evidence is tracked; decisions are approved; facts and hypotheses are separated; recovery conditions are agreed; uncertainty and outstanding actions are recorded.

DELIVERY

How the work is structured.

Approach

Define objectives and ownership; prepare scenarios and resources; perform authorised response or exercise; document evidence; improve and revise.

Prerequisites & responsibilities

Customer: decision-makers, operations, business owners, legal/insurer where required, permissions and recovery resources. Provider: contracted expertise with evidence preservation.

Scope factors

Criticality, scope, investigation depth, data volume, dependencies, scenarios and mobilisation terms. Preparation, response, rebuilding and licensing are separate.

Questions to clarify

Is the incident active? Which systems and evidence are available? Who authorises actions and coordinates leadership, legal advisers, insurers and operations?

IMPORTANT BOUNDARIES

Response depends on availability and contract; immediate availability is not implied. Regulatory notification and insurance decisions require responsible parties; evidential handling must suit the context.

Recovery and investigation have limits; no total recovery or absolute resolution-time promise. Exercise results remain specific to the tested scenario.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A company observes file encryption. Project: coordinate containment, evidence collection and recovery priorities with its teams. Target outcome: limit progression within available capabilities and rebuild using verified evidence, without promising full recovery.

Scenario 02

An executive account appears to have been used abroad. Project: analyse access, sessions and mailbox rules. Target outcome: confirm compromise or reject the hypothesis based on available evidence; missing history is flagged when it prevents a conclusion.

Technology and reference context

Reference: NIST SP 800-61 Rev. 3; collection and investigation tools suited to systems, permissions and preservation requirements.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.