Report an Incident Become a Partner Careers Contact
Book a Demo

Incident response service

Improve your organisation’s ability to manage and respond to cyber threats with our 24x7x365 incident response service.

The four phases of an incident response, on a timeline A horizontal timeline. Preparation sits before the incident occurs. An incident is marked, then three phases follow in order: detection and analysis, containment and recovery, and post-incident review. A marker sweeps along the timeline from left to right. 01 · PREPARATION before the incident INCIDENT 02 · DETECTION and analysis 03 · CONTAINMENT and recovery 04 · REVIEW post-incident

What is incident response?

24x7x365
incident response

Incident response is what an organisation does once a cyber security incident is already underway: establish what has happened, contain it, remove the attacker, restore normal operation, and close the route that was used. NIST SP 800-61 is the reference model, and it divides that work into four phases.

Failing to respond to cyber incidents quickly and effectively can lead to breaches, operational disruption and reputational damage. A slow response drastically increases the likelihood that a threat will negatively affect your infrastructure, so it is vital that you can respond swiftly at all times of the day.

At Wizard Cyber we offer a comprehensive incident response service, providing your organisation with the infrastructure, expertise and strategy required to mitigate cyber security incidents.

Our service is designed to be bespoke to your organisation’s requirements and existing cyber security infrastructure. This ensures that whether the attack is external or internal, we are able to respond decisively without any integration or implementation issues. Our team of analysts, threat investigators and incident response experts are on hand at all times to help as fast as possible.

Key features

Key features of our
incident response service

Access 24x7x365 incident response and support, detailed reporting and threat advice, and comprehensive threat investigation.

24x7x365 incident response

Our experienced incident response team are capable of responding to threats quickly and effectively at any time of the day, no matter where your organisation is based.

Detailed reporting and threat advice

We communicate with your team to ensure that the impact of any incident is clearly explained. Remediation advice is also provided to further reduce the impact of an incident, as well as comprehensive reporting on every incident.

Thorough incident investigation

Our team of expert threat investigators provide comprehensive incident investigation. This ensures that the cause of an incident is explored and any associated vulnerabilities can be remediated for the future.

The response lifecycle

How an incident
is handled

Our engagements follow the four phases defined in NIST SP 800-61, the reference model most incident response teams and regulators work from.

Preparation

NIST SP 800-61 Phase 01 of 4

NIST puts preparation first because most of what determines how an incident goes is decided before it starts: who is called, what they are allowed to do, and whether the data needed to answer the question is being collected at all.

In this engagementThe service is shaped around your existing security infrastructure rather than requiring a particular stack, so the response path is agreed against the estate you actually have.

Detection and analysis

NIST SP 800-61 Phase 02 of 4

Establishing that something has happened, what it is, how far it reaches and how serious it is. This is the phase where most time is lost, because an incident that is not understood cannot be contained safely.

In this engagementInvestigation runs around the clock, establishing the cause rather than only the symptom, so containment decisions are made against what actually happened.

Containment, eradication and recovery

NIST SP 800-61 Phase 03 of 4

Stopping the incident spreading, removing the attacker and what they left behind, and returning systems to normal operation — in that order, because recovering a system the attacker still has access to simply restarts the incident.

In this engagementResponse covers both external and internal attacks, and the aim through this phase is that the attacker is out before anything is restored.

Post-incident activity

NIST SP 800-61 Phase 04 of 4

The review. What happened, what was done, what it cost, and what has to change so the same route is not available twice. NIST treats this as part of the response rather than an optional extra.

In this engagementEvery incident produces a written report and remediation advice, covering the vulnerabilities the incident exposed so the same route can be closed.

Who answers

Multiple centres,
one continuous watch

Whoever picks up your incident is on shift because it is their shift, not because it happens to be daytime where they are.

  • SOC 1 Online
  • SOC 2 Online
  • SOC 3 Online
On shift in every centre

Senior analysts, incident responders, L3 analysts and AI developers.

Each centre is online around the clock in its own right. Nothing is handed to another region at the end of a shift.

Microsoft Solutions Partner

Running Microsoft Sentinel since 2019.

ISO 27001 and ISO 9001

Certified as a company — Wizard Cyber Security Ltd — rather than as any single platform or service.

Offices in four more countries

The UK, USA, Pakistan and Kuwait, alongside the operations centres.

Questions

Incident response, answered.

What is incident response?

Incident response is the structured process an organisation follows to detect a cyber security incident, contain it, remove the attacker, restore normal operation and learn from what happened. The reference model most teams work from is NIST SP 800-61, which divides it into preparation, detection and analysis, containment and recovery, and post-incident review.

What is the difference between incident response and managed detection and response?

Managed detection and response is a standing service: a SOC watches your estate continuously and handles what it finds. Incident response is engaged for a specific incident and ends when that incident is closed. Organisations often have both, and an MDR customer will usually have incident response included in the way their service is run rather than buying it separately.

How quickly can you respond to an incident?

Our SOCs are manned around the clock, every day, so an incident raised at three in the morning is picked up by people who are already on shift rather than by an on-call rota being woken. Specific response and containment commitments depend on the scope agreed for your organisation, and are set out in the engagement rather than quoted as a single number.

Who actually handles the incident?

Senior analysts, incident responders and L3 analysts, on shift in every one of our SOCs around the clock. We run multiple security operations centres, each manned 24/7 in its own right rather than handing work over at the end of a regional day.

Do we need to be an existing customer, or run a particular platform?

No. The service is shaped around the security infrastructure you already have. We have run Microsoft Sentinel since 2019 and are a Microsoft Solutions Partner, so a Microsoft estate is familiar ground, but incident response is not limited to organisations already working with us.

What do we get at the end of an incident?

A written report covering what happened, what was done and what it affected, together with remediation advice for the vulnerabilities the incident exposed. NIST treats this post-incident review as part of the response rather than an optional extra, because it is what stops the same route being used twice.

Responsive expertise, assured guidance

Need cyber security guidance?
We’re here to help.

If an incident is already underway, start there. Otherwise: feeling overwhelmed by cyber security options or uncertain about your next move? At Wizard Cyber, navigating the complexities of protecting your digital landscape is our specialty. We’re dedicated to offering clear, comprehensive cyber security solutions tailored to your unique needs. Whether you’re looking to bolster your defences or simply seeking advice on preventing cyber threats, our team is ready to provide the insight and support you need.