Incident response

The alert fired. Here's what happens next.

When our security operations console detects a real threat, a rehearsed response begins in minutes — not a ticket queue. This page walks through a genuine incident, step by step.

A real response, minute by minute

Anatomy of an account takeover — stopped in 60 minutes

This is a realistic example of the most common incident we see: a stolen Microsoft 365 password used from overseas. The timeline below shows how detection turns into containment before real damage is done.

  1. T+0 min

    Alert fires in the SOC

    A Microsoft 365 sign-in from an impossible location triggers a Critical alert. The correlation engine attaches the user's recent email, device and VPN activity so the analyst sees the whole story in one screen.

  2. T+2 min

    Analyst validates the threat

    A human analyst reviews the signal: the user signed in from Perth 40 minutes ago, and the new session is 11,000 km away with an unfamiliar device. This is a genuine account takeover attempt — not noise.

  3. T+4 min

    Automated containment

    The approved playbook executes: all sessions revoked, password reset forced, the account blocked from new sign-ins, and any inbox rules the attacker created are stripped automatically.

  4. T+6 min

    Client notified

    Your nominated contact receives a call and a written summary: what happened, what we did, what we need from you (confirm the user wasn't travelling) and whether any business action is required.

  5. T+20 min

    Scope check

    The analyst hunts for lateral movement: did the attacker read email, send phishing from the mailbox, touch SharePoint, or create forwarding rules before containment? Every artefact is checked and logged.

  6. T+45 min

    Eradication and hardening

    The phishing email that stole the credentials is pulled from every mailbox, the sender domain is blocked, and the affected user is re-secured with fresh MFA registration before access is restored.

  7. T+60 min

    Safe access restored

    The user signs back in with a new password and re-registered MFA. Business impact: roughly one hour of inconvenience for one person, instead of days of recovery for the whole company.

  8. T+24 hrs

    Written incident report

    You receive a plain-English report: timeline, evidence, actions taken, business impact and recommendations — such as tightening sign-in policies for the finance team.

Clear on the night

Who does what

Incidents go wrong when nobody knows their role. Before anything ever happens, we agree exactly who acts, who decides and who communicates.

What the SOC does

  • Validate every high-risk alert with a human analyst
  • Execute your approved containment playbook
  • Isolate devices, revoke sessions, disable accounts
  • Pull malicious email from all mailboxes
  • Hunt for lateral movement and persistence
  • Document every action with timestamps

What we ask of you

  • Nominate primary and after-hours contacts
  • Approve playbooks before incidents happen
  • Confirm user context when we call (travel, new devices)
  • Decide on any business-level actions (e.g. notifying clients)
  • Review the incident report and recommendations

What you receive

  • Immediate phone and written notification for critical events
  • A complete evidence and action log
  • Plain-English incident report within 24 hours
  • Monthly trends across all incidents and near-misses
  • Practical hardening recommendations that actually get done

Rehearsed, not improvised

Playbooks we run for you

Each scenario has a pre-approved response plan, so the first minutes of an incident are spent containing it — not debating what to do.

Account takeover

Revoke sessions, reset credentials, re-register MFA, review mailbox rules and sent items.

Ransomware behaviour

Isolate the device from the network, disable the user account, protect backups, image the device for evidence.

Phishing campaign

Remove messages from every mailbox, block sender and links, warn recipients, reset any credentials entered.

Malware on a server

Isolate the server, snapshot for forensics, rebuild from clean backup, rotate credentials that touched it.

Business email compromise

Freeze affected mailboxes, audit forwarding rules, notify your contact before any payments change hands.

Lost or stolen device

Remote lock and wipe, revoke tokens, confirm encryption was active, issue replacement hardware.

Threat response questions

What businesses ask about the response side of security operations.

Be ready before it happens

Put a rehearsed response behind your monitoring

Book a security review and we'll map your incident-response plan — contacts, playbooks and reporting included.