RES / RES-01
Incident response and digital investigation — DFIR
Help understand an incident, limit its effects, preserve useful evidence and prepare controlled recovery. Investigation separates established facts, hypotheses and missing data; it does not cover all legal or communication decisions on its own.

WHEN IT HELPS
A focused response
to a defined need.
Suspected compromise, ransomware, hijacked administrator account, suspected data leak or abnormal behaviour confirmed by the SOC.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Emergency scoping
- authorised collection
- timeline
- known scope
- approved containment
- root-cause investigation
- evidence preservation
- eradication and recovery recommendations
- lessons learned
Deliverables
- Decision log
- evidence inventory
- qualified timeline
- situation report
- recommendations
- investigation report
- recovery and remediation plan
Acceptance evidence
Investigated scope is explicit; evidence is tracked; decisions are approved; facts and hypotheses are separated; recovery conditions are agreed; uncertainty and outstanding actions are recorded.
DELIVERY
How the work is structured.
Approach
Define objectives and ownership; prepare scenarios and resources; perform authorised response or exercise; document evidence; improve and revise.
Prerequisites & responsibilities
Customer: decision-makers, operations, business owners, legal/insurer where required, permissions and recovery resources. Provider: contracted expertise with evidence preservation.
Scope factors
Criticality, scope, investigation depth, data volume, dependencies, scenarios and mobilisation terms. Preparation, response, rebuilding and licensing are separate.
Questions to clarify
Is the incident active? Which systems and evidence are available? Who authorises actions and coordinates leadership, legal advisers, insurers and operations?
IMPORTANT BOUNDARIES
Response depends on availability and contract; immediate availability is not implied. Regulatory notification and insurance decisions require responsible parties; evidential handling must suit the context.
Recovery and investigation have limits; no total recovery or absolute resolution-time promise. Exercise results remain specific to the tested scenario.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A company observes file encryption. Project: coordinate containment, evidence collection and recovery priorities with its teams. Target outcome: limit progression within available capabilities and rebuild using verified evidence, without promising full recovery.
Scenario 02
An executive account appears to have been used abroad. Project: analyse access, sessions and mailbox rules. Target outcome: confirm compromise or reject the hypothesis based on available evidence; missing history is flagged when it prevents a conclusion.
Technology and reference context
Reference: NIST SP 800-61 Rev. 3; collection and investigation tools suited to systems, permissions and preservation requirements.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
