Incident response — retainer + emergency, with platform-backed evidence
Retainer-backed IR with KeenSafe-derived attack-path evidence to accelerate scoping, containment and lessons-learned. Emergency response within named SLAs.
Where teams get stuck
Incident response without attack-path context is reactive archaeology. Teams chase alerts, miss adjacent compromised assets, and close incidents without knowing whether the original entry path is still open.
How we engage
KeenSafe IR uses the same platform engine that finds attack paths offensively to scope incidents — within hours we know which assets are compromised, which paths are still open, and what containment will actually close them. Retainer clients also receive proactive readiness exercises and run-books.
Four-step engagement model
Same rigour every engagement, calibrated to your environment, threat model and regulatory exposure.
Triage & scoping
Initial telemetry collection, IOC pivoting, attack-path reconstruction within hours.
Containment
Identity, endpoint and network containment guided by validated attack-path evidence.
Eradication & recovery
Persistence cleanup, identity reset, control rebuild — verified by re-running the attack path.
Lessons learned
Detection gaps, control gaps and process gaps captured with measurable follow-up.
Deliverables
Every engagement ships these outputs — reproducible, evidence-backed and ready for executives, engineers and auditors.
Named IR SLA
Retainer with first-responder SLA in business hours and emergency hours.
Attack-path scoping
Within hours we map every compromised asset and every still-open ingress.
Containment plan
Identity, endpoint, network and cloud containment guided by validated paths.
Lessons-learned report
Measurable follow-ups: detection engineering, hardening, run-book updates.
What this engagement covers
Concrete coverage. Clear boundaries. Optional add-on tracks where customers want to extend.
- Named IR retainer with 24×7 hotline (customers receive direct phone + Signal)
- Initial-response SLA: 15 min hotline pickup, 1h scoping, 4h on-call lead
- Triage + scoping using KeenSafe attack-path graph for instant context
- Containment guidance across identity, endpoint, network, cloud
- Forensic acquisition (memory, disk, network) without spoliation
- Eradication validation: original attack path replayed after fix
- Lessons-learned report with detection + hardening backlog
- Regulator + insurer narrative drafting (GDPR / NIS2 / sectoral)
- Cleared-personnel response (defence / government engagements)
- Onsite physical presence within 24h for declared major incidents
- Pre-incident readiness exercises (tabletop, threat-actor specific)
- Insurance-led panel coordination (work with your insurer's panel)
- Long-term forensic investigation extension
- ✕Routine 24×7 monitoring (covered by MDR / SOC service)
- ✕Legal counsel — we coordinate with, not replace, your legal team
- ✕Public-relations work — we provide technical narrative for your PR team
How we deliver
- Enterprises with crown-jewel data
- NIS2 essential entities (regulator-facing IR)
- Regulated industries with breach-notification obligations
- Insured organisations with cyber-insurance retainer requirements
What lands on your desk
Sections customers actually see in the engagement deliverable.
- 01Initial scoping report
Within 4–8h of engagement start: known compromised assets, still-open ingress paths, immediate containment actions.
- 02Containment plan
Identity, endpoint, network and cloud containment guided by validated attack-path evidence. Sequenced for safe execution.
- 03Forensic timeline
Reconstructed adversary timeline from earliest evidence through containment, with every artefact preserved.
- 04Regulator narrative draft
GDPR Article 33 / NIS2 / sectoral notification draft ready for your legal team to adapt.
- 05Lessons-learned report
Detection gaps, control gaps, process gaps with measurable follow-up backlog.
Frameworks & regulations
Frequently asked
Do you take live emergency calls?
Can you support GDPR breach reporting?
What does post-IR retesting look like?
Pairs well with
MDR / SOC
24×7 detection, response and SOC operations augmented with continuous attack-path validation that closes the loop between offensive evidence and detection engineering.
Read moreSecurity architecture & hardening
Architecture-level review and operational hardening across cloud, identity, network and endpoint — driven by validated attack paths from the KeenSafe platform.
Read moreCompliance readiness
Gap assessments, remediation programs and audit-ready evidence packs for ISO 27001, SOC 2, PCI DSS, NIS2, KVKK and sectoral regulators.
Read moreWork with the team behind KeenSafe
Continuous adversarial validation, managed security operations and executive-grade risk visibility — delivered by senior offensive security engineers.