Urgent help
Incident Response
Call us when you think something is actively wrong.
Test line only — this number doesn’t connect to anything.
- Starting price
- From $350/hour, $3,500 minimum
- How it works
- We start immediately, then agree a plan to contain it and recover
- What changes the price
- Billed hourly with a $3,500 minimum. We tell you what it’s costing as we go, rather than sending a surprise invoice at the end.
What problem this solves
For when something is wrong right now: admin accounts nobody created, a ransom note, a payment sent to the wrong bank account, email rules forwarding messages out, or systems behaving in ways nobody can explain. We work out what is happening, stop it spreading, help you decide who needs to be told, and write up what happened so it can’t happen the same way twice.
What we take off your team's plate
- 01
The first call
We establish what you know, what you suspect, and what has to stop right now.
- 02
Stopping it spreading
Resetting passwords, kicking out active sessions, pulling affected machines off the network, locking down email.
- 03
Keeping the evidence
We capture the records before cleanup destroys them, so your lawyer and insurer have something to work with.
- 04
Getting you running again
Restoring things in the right order, checking each one, and writing down what we did.
- 05
A written account afterwards
What happened and when, how they most likely got in, what we did, and how to stop a repeat.
This is right if
- You think, or know, someone is in your systems
- Someone in your email, or a payment sent to a fake bank account
- Ransomware, or files you think have been stolen
- Your insurer or lawyer has told you to get technical help immediately
This is the wrong choice if
- General slowness, one broken laptop, or the usual outages
- A guaranteed 24/7 answer — we don’t run a staffed round-the-clock emergency desk
- Legal advice, insurance claims, or deciding who must be notified — that belongs with your lawyer
How it goes
- Hour 0
Call us. Don’t delete anything or rebuild any machines before we speak.
- Hours 1–4
We work out what’s going on and stop it spreading, with your team.
- Days 1–5
Digging into what happened, getting you running again, and working with your insurer or lawyer.
- After
A written account and a short plan to stop it happening again.
Questions we get
- Are you available 24/7?
- Not as a guarantee. The line is answered during extended business hours, and outside them when we can, but we won’t sell you a round-the-clock promise we can’t keep.
- Should we call our insurer first?
- If you have cyber insurance, tell them early — some policies require you to use a firm from their list. We work alongside those firms regularly.
- What should we do before you arrive?
- Leave things alone. Don’t wipe or rebuild affected machines, don’t delete suspicious email rules, and write down what happened and when.
Not sure what you need?
Answer a few questions and we'll suggest the service that fits — or tell you plainly if we're not the right company for this.