Discussion-based tabletop
Facilitated scenario walk-through with the security and IT leadership team. Best first exercise: cheap, low risk, and reliably surfaces gaps in the call tree.
Incident response & digital forensics
Guardian's incident response practice contains active intrusions, recovers operations and produces the evidence record your regulator, insurer and board will each demand. Retainer holders reach a responder in fifteen minutes, any hour, any day.
The response method
Guardian follows the NIST SP 800-61 lifecycle, adapted for the reality that containment and investigation have to happen at the same time. Every phase has an owner, an exit condition and a written artefact.
Phase by phase
A duty incident manager opens a bridge and takes command within 15 minutes. Rules of engagement, communication channels and the out-of-band contact tree are confirmed in writing. We assume your primary email and chat may be adversary-visible until proven otherwise, so the bridge runs on independent infrastructure.
Owner: Guardian incident manager
Forensic collection begins on the initially affected hosts while Sentinel or an equivalent agent is pushed estate-wide for live triage. We establish patient zero, initial access vector, the adversary's toolset and every account they touched. Scope is stated as a confidence level, not a guess.
Owner: Lead forensic examiner
Network isolation, account disablement, token revocation, malicious-infrastructure blocking and, where required, an emergency password reset for the whole directory. Containment is staged so that we do not tip off the adversary before the eradication plan is ready to execute in a single sweep.
Owner: Containment lead, with your change authority
Removal of every persistence mechanism found, including scheduled tasks, WMI subscriptions, malicious service accounts, rogue OAuth grants, golden-ticket exposure and firmware-level implants. Domain controller compromise triggers a full KRBTGT double-rotation.
Owner: Eradication lead + your platform teams
Restoration sequencing agreed with your business continuity owners: which services return first, from which known-good point, and with what heightened monitoring. Every restored system is validated against a clean baseline before it rejoins production.
Owner: Recovery lead + business service owners
A written incident report with a defensible timeline, the root cause, the control failures that allowed it, and a prioritised remediation plan. Separate packs are produced for regulators, the insurer and the board because each needs a different level of detail.
Owner: Engagement lead + Guardian Labs
Contracted commitments
These are contractual targets in the Guardian IR retainer, measured from the moment an incident is declared on the hotline. Performance against them is reported to you quarterly, including any miss and its cause.
| Commitment | Emergency | Standard retainer | Priority retainer | Elite retainer |
|---|---|---|---|---|
| Responder callback | Best effort, typically 2–6 hours | 1 hour, 24 / 7 | 30 minutes, 24 / 7 | 15 minutes, 24 / 7 |
| Remote forensics begins | On contract execution | 4 hours | 2 hours | 1 hour |
| Initial containment actions | Best effort | 8 hours | 4 hours | 2 hours |
| On-site team dispatched | Not included | 72 hours, major metro | 36 hours, global | 24 hours, global |
| Scoping statement delivered | Best effort | 72 hours | 48 hours | 24 hours |
| Written incident report | 20 business days | 15 business days | 10 business days | 5 business days |
| Regulatory notification support | Chargeable | Included | Included | Included, with counsel liaison |
| Annual tabletop exercises | — | 1 | 2 | 4, including one executive crisis simulation |
| Committed hours | Per engagement | From 40 | From 120 | From 400 |
Scroll the table sideways to compare every tier.
Retainer hours not consumed on live incidents convert to proactive work at each quarter boundary — compromise assessments, threat hunts, playbook development or tabletop facilitation. They are never simply forfeited.
Digital forensics
A response that stops the adversary but cannot prove what happened leaves you exposed to a regulator, an insurer and, increasingly, a class action. Guardian's forensic practice works to an evidential standard from the first acquisition onward.
Chain of custody — every artefact, every time
Anatomy of a real engagement
Reconstructed from a 2025 engagement with a 9,000-seat distribution business. The adversary had held valid VPN credentials for eleven days before acting. Details are anonymised; the timings are as recorded.
The customer's night analyst escalated an unexplained cluster of failed logons against a domain admin account. A Guardian duty incident manager joined the bridge at 21:11 and declared a major incident.
Snapshotting of the two suspect hosts and the domain controllers was ordered before any remediation. Memory capture started on the jump server first, since it was the artefact most likely to be lost.
A VPN account belonging to a contractor, without MFA enforced, had authenticated from a residential proxy range eleven days earlier. Sessions from that range were still active on three hosts.
All three hosts were isolated simultaneously, the contractor account and two harvested service accounts were disabled, and outbound traffic to the adversary's command channel was blocked at the perimeter — in one coordinated action, so the operator could not react to a partial cut.
A staged payload was found on a file server, pre-positioned but not yet executed, along with a scheduled task set for 03:00. The task was removed and the binary preserved for analysis.
Persistence removed from all three hosts, KRBTGT rotated twice, 41 privileged credentials reset, and every remaining session token revoked. Heightened monitoring rules were pushed tenant-wide.
Written incident report delivered with a defensible timeline. MFA was made mandatory for all third-party VPN access, contractor accounts moved to a 90-day expiry, and two new detections were promoted from the engagement into the customer's production ruleset.
Retainers
A retainer is mostly a legal and logistical instrument. It removes procurement, contracting, NDA negotiation and access provisioning from the critical path of an incident, and it puts contracted hours on our roster with your name against them.
Core protection for organisations with an internal team that can hold the first hour.
The common enterprise choice: fast callback, global dispatch and two rehearsals a year.
For systemically important estates where a four-hour delay is a board-level event.
All tiers are available to organisations running any security stack. See how retainers combine with a platform subscription.
Readiness
A plan that has never been tested is a hypothesis. Guardian facilitates four exercise formats, each with a written after-action report and a tracked remediation list. Roughly two thirds of first exercises surface a broken assumption about who can authorise what.
Facilitated scenario walk-through with the security and IT leadership team. Best first exercise: cheap, low risk, and reliably surfaces gaps in the call tree.
Board, general counsel, communications and the CEO, under injected media enquiries and a simulated regulator clock. Focused on decision-making, not technology.
Guardian operators execute a real attack chain in a controlled window while your defenders respond live. Every missed detection becomes a rule the same week.
Restore a business-critical service from backup into an isolated environment under time pressure. The only honest test of your recovery-time objective.
Where first-time exercises break down — 240 exercises facilitated
An after-action report naming the decision that stalled, the person who could not be reached, and the assumption that turned out to be false — with an owner and a date against each.
Injects are built from the intrusions Guardian Labs is actually seeing this quarter in your sector, not from a library written three years ago.
Where your counsel directs it, Guardian engages through the law firm so that the investigation and its work product sit under legal privilege. We are experienced in running the engagement this way from hour one, rather than retrofitting it later.
Guardian is an approved incident response vendor for fourteen major cyber-insurance carriers and their principal London and Bermuda markets, which usually removes the pre-approval delay before response work can begin.
GDPR's 72 hours, DORA's initial notification, SEC Item 1.05 materiality, HIPAA, NIS2 and the sector-specific regimes. We track the clocks that apply to you and produce the packs in the format each authority expects.
We had rehearsed this exact scenario nine weeks earlier with the same Guardian team. When it happened for real, nobody argued about who could authorise pulling the site offline — that decision had already been made once, in a room, on a Tuesday.
Reduce the odds you ever call
Most incidents Guardian responds to were visible in telemetry for days. A watched estate turns a breach into an alert.
Explore MDRFind the contractor VPN account without MFA before somebody else buys the credentials for forty dollars.
Explore offensive testingSentinel playbooks isolate, revoke and roll back in under nine seconds, which is faster than any human bridge can convene.
Automation & responseA retainer takes about two weeks to put in place and removes hours from your worst day. If today is already that day, say so on the form and it routes straight to the duty incident manager.