Book a Security Assessment letstalk@networklondon.co.uk · London Bridge
Service 06 / 12

Cyber incident
response.

When something goes wrong, the first hours matter most. We help you prepare a plan before you need it, and support you to contain, investigate and recover when you do.

  • Response planning
  • Containment
  • Investigation
  • Recovery

Last reviewed

Dark architectural lines of a modern building
01 — Overview

What it is,
and why it matters.

Ransomware, a compromised email account, a lost laptop full of client data: incidents rarely arrive at a convenient time. Businesses with a plan recover faster and lose less.

We help you write a short, usable response plan and test it. If an incident happens, we work alongside your team to contain it, find out what happened and get you back to normal.

A good fit if…

  • You don't have a written incident response plan
  • You have a plan but have never tested it
  • You need to show insurers you are prepared
  • You are dealing with an incident right now (email us)
02 — What's included

Everything you need,
nothing you don't.

01

Incident response plan

A clear, short plan: who does what, who to call and when.

02

Tabletop exercise

A guided walk-through of a realistic scenario with your team.

03

Containment

Steps to stop the spread and protect critical systems.

04

Investigation

Establishing what happened, how and what was affected.

05

Recovery support

Restoring systems safely and closing the gap that let the attacker in.

06

Post-incident review

Lessons learned and the changes that prevent a repeat.

03 — How it works

Four clear
steps.

  1. Step 1

    Prepare

    Write and test your response plan.

  2. Step 2

    Contain

    Limit the damage as soon as an incident is spotted.

  3. Step 3

    Investigate

    Work out what happened and what was affected.

  4. Step 4

    Recover

    Restore safely and strengthen defences.

04 — Options

How we help

A

Incident response planning

A practical plan and playbooks for your most likely incidents.

B

Tabletop exercises

Scenario sessions that test your plan and decision making.

C

Emergency response

Hands-on support during a live incident.

D

Digital forensics

Evidence gathering to understand exactly what happened.

05 — Cost

What affects
the cost.

1

Preparation or live

Planning work is fixed price; live response depends on the incident.

2

Scale

How many systems and people are affected.

3

Investigation depth

A quick root-cause check is faster than a full forensic investigation.

4

Retainer

Agreeing terms in advance means faster help when you need it.

Planning and exercises are fixed price. For live incidents, get in touch and we will agree next steps straight away.

Get a quote
06 — FAQs

Questions,
answered.

Don't switch everything off or delete anything. Disconnect affected devices from the network if you can, change passwords from a clean device, and email us at letstalk@networklondon.co.uk.

A short document that sets out who does what when a security incident happens: who leads, who to contact, how to contain the problem and how to communicate.

If personal data is affected you may need to report it to the ICO within 72 hours. We help you assess what needs reporting and to whom.

Yes. We help contain the attack, assess what was affected, support recovery from backups and close the route the attacker used.

07 — Guides

Further
reading.

Next step

Let's talk about
incident response.

A short call, no obligation. We'll listen, ask a few questions and suggest a sensible first step.

Contact

Start with
an assessment.

Tell us a little about your business. We'll arrange a short, no-obligation conversation and suggest a sensible first step.

Studio

The Leather Market
London Bridge

Dealing with a live incident? Put “urgent” in your message or email letstalk@networklondon.co.uk. We use your details only to reply, see our privacy notice.