# Cyber incident response.

> Cyber incident response for London businesses: a tested plan before an incident, and calm, practical help to contain and recover.

Canonical: https://cybersecuritylondon.com/incident-response


When something goes wrong, the first hours matter most. We help you prepare a plan before you need it, and support you to contain, investigate and recover when you do.

Covers: Response planning, Containment, Investigation, Recovery.

## Overview

Ransomware, a compromised email account, a lost laptop full of client data: incidents rarely arrive at a convenient time. Businesses with a plan recover faster and lose less.

We help you write a short, usable response plan and test it. If an incident happens, we work alongside your team to contain it, find out what happened and get you back to normal.

### A good fit if

- You don't have a written incident response plan
- You have a plan but have never tested it
- You need to show insurers you are prepared
- You are dealing with an incident right now (email us)

## What's included

- **Incident response plan**: A clear, short plan: who does what, who to call and when.
- **Tabletop exercise**: A guided walk-through of a realistic scenario with your team.
- **Containment**: Steps to stop the spread and protect critical systems.
- **Investigation**: Establishing what happened, how and what was affected.
- **Recovery support**: Restoring systems safely and closing the gap that let the attacker in.
- **Post-incident review**: Lessons learned and the changes that prevent a repeat.

## How it works

1. **Prepare**: Write and test your response plan.
2. **Contain**: Limit the damage as soon as an incident is spotted.
3. **Investigate**: Work out what happened and what was affected.
4. **Recover**: Restore safely and strengthen defences.

## How we help

- **Incident response planning**: A practical plan and playbooks for your most likely incidents.
- **Tabletop exercises**: Scenario sessions that test your plan and decision making.
- **Emergency response**: Hands-on support during a live incident.
- **Digital forensics**: Evidence gathering to understand exactly what happened.

## What affects the cost

- **Preparation or live**: Planning work is fixed price; live response depends on the incident.
- **Scale**: How many systems and people are affected.
- **Investigation depth**: A quick root-cause check is faster than a full forensic investigation.
- **Retainer**: Agreeing terms in advance means faster help when you need it.

Planning and exercises are fixed price. For live incidents, get in touch and we will agree next steps straight away.

## Frequently asked questions

### What should we do first if we think we have been hacked?

Don't switch everything off or delete anything. Disconnect affected devices from the network if you can, change passwords from a clean device, and email us at enquiry@cybersecuritylondon.com.

### What is an incident response plan?

A short document that sets out who does what when a security incident happens: who leads, who to contact, how to contain the problem and how to communicate.

### Do we need to report a cyber incident?

If personal data is affected you may need to report it to the ICO within 72 hours. We help you assess what needs reporting and to whom.

### Can you help after ransomware?

Yes. We help contain the attack, assess what was affected, support recovery from backups and close the route the attacker used.

## Related services

- [24/7 Monitoring (SOC)](https://cybersecuritylondon.com/managed-soc-monitoring)
- [Cyber Security Assessments](https://cybersecuritylondon.com/cyber-security-assessments)
- [GDPR & Data Protection](https://cybersecuritylondon.com/gdpr-consultancy)

## Contact

Email enquiry@cybersecuritylondon.com or use the enquiry form at https://cybersecuritylondon.com/#contact. Cyber Security London, The Leather Market, London Bridge, London.
