Incident response & digital forensics

When it is already happening, minutes are the only currency

Guardian's incident response practice contains active intrusions, recovers operations and produces the evidence record your regulator, insurer and board will each demand. Retainer holders reach a responder in fifteen minutes, any hour, any day.

Under attack right now? Do not wipe, reimage or power down affected systems — you will destroy the evidence that tells us how far the adversary got. Isolate at the network layer if you can, preserve volatile memory, and open the emergency channel. Guardian accepts emergency engagements from organisations that are not existing customers.
15 min Contracted callback for retainer holders, 24 / 7 / 365
47 min Median engagement-to-containment across 2025 incidents
910 Major incidents led in the last three years
210 Responders and forensic examiners on the roster
14 Cyber-insurance carriers with Guardian on their panel

The response method

Six phases, run in parallel where the clock demands it

Guardian follows the NIST SP 800-61 lifecycle, adapted for the reality that containment and investigation have to happen at the same time. Every phase has an owner, an exit condition and a written artefact.

guardian IR › response lifecycle
H+0 H+1 H+4 H+24 D+3 D+10 D+30 01 Engage 02 Scope 03 Contain 04 Eradicate 05 Recover 06 Learn Bridge open, rules of engagement signed Patient zero and toolset identified No further adversary action possible Persistence removed Service restored from a clean baseline Report, regulator pack and control changes Scope and contain run concurrently Timeline is illustrative; a ransomware event compresses phases 1–3 into the first four hours.

Phase by phase

What actually happens, and who owns it

  1. Engage

    A duty incident manager opens a bridge and takes command within 15 minutes. Rules of engagement, communication channels and the out-of-band contact tree are confirmed in writing. We assume your primary email and chat may be adversary-visible until proven otherwise, so the bridge runs on independent infrastructure.

    Owner: Guardian incident manager

  2. Scope

    Forensic collection begins on the initially affected hosts while Sentinel or an equivalent agent is pushed estate-wide for live triage. We establish patient zero, initial access vector, the adversary's toolset and every account they touched. Scope is stated as a confidence level, not a guess.

    Owner: Lead forensic examiner

  3. Contain

    Network isolation, account disablement, token revocation, malicious-infrastructure blocking and, where required, an emergency password reset for the whole directory. Containment is staged so that we do not tip off the adversary before the eradication plan is ready to execute in a single sweep.

    Owner: Containment lead, with your change authority

  4. Eradicate

    Removal of every persistence mechanism found, including scheduled tasks, WMI subscriptions, malicious service accounts, rogue OAuth grants, golden-ticket exposure and firmware-level implants. Domain controller compromise triggers a full KRBTGT double-rotation.

    Owner: Eradication lead + your platform teams

  5. Recover

    Restoration sequencing agreed with your business continuity owners: which services return first, from which known-good point, and with what heightened monitoring. Every restored system is validated against a clean baseline before it rejoins production.

    Owner: Recovery lead + business service owners

  6. Learn

    A written incident report with a defensible timeline, the root cause, the control failures that allowed it, and a prioritised remediation plan. Separate packs are produced for regulators, the insurer and the board because each needs a different level of detail.

    Owner: Engagement lead + Guardian Labs

Contracted commitments

Containment SLAs you can hold us to

These are contractual targets in the Guardian IR retainer, measured from the moment an incident is declared on the hotline. Performance against them is reported to you quarterly, including any miss and its cause.

Incident response service levels by retainer tier. Emergency (non-retainer) engagements are accepted subject to responder availability and a signed engagement letter.
Commitment Emergency Standard retainer Priority retainer Elite retainer
Responder callback Best effort, typically 2–6 hours 1 hour, 24 / 7 30 minutes, 24 / 7 15 minutes, 24 / 7
Remote forensics begins On contract execution 4 hours 2 hours 1 hour
Initial containment actions Best effort 8 hours 4 hours 2 hours
On-site team dispatched Not included 72 hours, major metro 36 hours, global 24 hours, global
Scoping statement delivered Best effort 72 hours 48 hours 24 hours
Written incident report 20 business days 15 business days 10 business days 5 business days
Regulatory notification support Chargeable Included Included Included, with counsel liaison
Annual tabletop exercises — 1 2 4, including one executive crisis simulation
Committed hours Per engagement From 40 From 120 From 400

Scroll the table sideways to compare every tier.

Retainer hours not consumed on live incidents convert to proactive work at each quarter boundary — compromise assessments, threat hunts, playbook development or tabletop facilitation. They are never simply forfeited.

Digital forensics

Evidence that survives cross-examination

A response that stops the adversary but cannot prove what happened leaves you exposed to a regulator, an insurer and, increasingly, a class action. Guardian's forensic practice works to an evidential standard from the first acquisition onward.

  • Host forensics. Full-disk and targeted acquisitions, volatile memory capture, super-timeline reconstruction across NTFS, APFS, ext4 and XFS.
  • Cloud and SaaS forensics. CloudTrail, Azure Activity, Workspace and Microsoft 365 unified audit log reconstruction, including OAuth grant abuse and mailbox rule manipulation.
  • Identity forensics. Kerberos ticket analysis, golden and silver ticket detection, federation trust abuse and token replay reconstruction.
  • Malware analysis. Static and dynamic reversing in an isolated detonation range, with YARA and Sigma content published back to your tenant the same day.
  • Data-exfiltration assessment. What left, when, and whose records were in it — the question that determines your notification obligations.

Chain of custody — every artefact, every time

Acquire Hash on capture Seal and transfer Analyse the copy Attest and release Write-blocked imaging or agent-based collection, examiner logged. SHA-256 computed at source; recorded before the artefact moves. Encrypted transit to the evidence vault in your residency region. Originals are never touched; every working copy is re-verified. Signed attestation of integrity, released to you and your counsel. t0 sha256 AES-256 read-only signed

Anatomy of a real engagement

A ransomware attempt, stopped before encryption

Reconstructed from a 2025 engagement with a 9,000-seat distribution business. The adversary had held valid VPN credentials for eleven days before acting. Details are anonymised; the timings are as recorded.

0systems encrypted
3 h 51 mdeclaration to eradication
2hosts requiring rebuild
0days of operational downtime
Why the retainer mattered The engagement letter, data-processing agreement and evidence-handling protocol were already signed. The first 47 minutes went to investigation instead of to legal review.
21:04 — H+0

Escalation and declaration

The customer's night analyst escalated an unexplained cluster of failed logons against a domain admin account. A Guardian duty incident manager joined the bridge at 21:11 and declared a major incident.

21:19 — H+0:15

Evidence preservation ordered

Snapshotting of the two suspect hosts and the domain controllers was ordered before any remediation. Memory capture started on the jump server first, since it was the artefact most likely to be lost.

21:48 — H+0:44

Initial access identified

A VPN account belonging to a contractor, without MFA enforced, had authenticated from a residential proxy range eleven days earlier. Sessions from that range were still active on three hosts.

22:31 — H+1:27

Staged containment executed

All three hosts were isolated simultaneously, the contractor account and two harvested service accounts were disabled, and outbound traffic to the adversary's command channel was blocked at the perimeter — in one coordinated action, so the operator could not react to a partial cut.

23:52 — H+2:48

Encryptor recovered before deployment

A staged payload was found on a file server, pre-positioned but not yet executed, along with a scheduled task set for 03:00. The task was removed and the binary preserved for analysis.

00:55 — H+3:51

Eradication complete

Persistence removed from all three hosts, KRBTGT rotated twice, 41 privileged credentials reset, and every remaining session token revoked. Heightened monitoring rules were pushed tenant-wide.

Day 4

Report and control changes

Written incident report delivered with a defensible timeline. MFA was made mandatory for all third-party VPN access, contractor accounts moved to a 90-day expiry, and two new detections were promoted from the engagement into the customer's production ruleset.

Retainers

Sign the paperwork on a quiet Tuesday, not at 3 a.m.

A retainer is mostly a legal and logistical instrument. It removes procurement, contracting, NDA negotiation and access provisioning from the critical path of an incident, and it puts contracted hours on our roster with your name against them.

Standard

Core protection for organisations with an internal team that can hold the first hour.

40 h committed annually
  • 1-hour callback, 24 / 7 / 365
  • Remote forensics within 4 hours
  • One tabletop exercise per year
  • Pre-signed engagement and data-handling terms
  • Unused hours convert to proactive work
Discuss Standard
Elite

For systemically important estates where a four-hour delay is a board-level event.

400 h committed annually
  • 15-minute callback, 24 / 7 / 365
  • Remote forensics within 1 hour; on-site in 24
  • Four exercises, including executive crisis simulation
  • Quarterly threat hunt against your estate
  • Counsel and insurer liaison from hour one
  • Written report in 5 business days
Discuss Elite

All tiers are available to organisations running any security stack. See how retainers combine with a platform subscription.

Readiness

Tabletop exercises that make people uncomfortable on purpose

A plan that has never been tested is a hypothesis. Guardian facilitates four exercise formats, each with a written after-action report and a tracked remediation list. Roughly two thirds of first exercises surface a broken assumption about who can authorise what.

2 hours

Discussion-based tabletop

Facilitated scenario walk-through with the security and IT leadership team. Best first exercise: cheap, low risk, and reliably surfaces gaps in the call tree.

Half day

Executive crisis simulation

Board, general counsel, communications and the CEO, under injected media enquiries and a simulated regulator clock. Focused on decision-making, not technology.

2 days

Technical purple team

Guardian operators execute a real attack chain in a controlled window while your defenders respond live. Every missed detection becomes a rule the same week.

1 week

Full-scale recovery drill

Restore a business-critical service from backup into an isolated environment under time pressure. The only honest test of your recovery-time objective.

Where first-time exercises break down — 240 exercises facilitated

Decision authority unclear Out-of-band comms untested No legal or regulatory clock Backups never restore-tested Third-party escalation missing Public comms unprepared 71% 64% 58% 46% 39% 33%

Every exercise produces an artefact

An after-action report naming the decision that stalled, the person who could not be reached, and the assumption that turned out to be false — with an owner and a date against each.

Scenarios drawn from live casework

Injects are built from the intrusions Guardian Labs is actually seeing this quarter in your sector, not from a library written three years ago.

See analyst and responder training

Working under privilege

Where your counsel directs it, Guardian engages through the law firm so that the investigation and its work product sit under legal privilege. We are experienced in running the engagement this way from hour one, rather than retrofitting it later.

Insurer panel status

Guardian is an approved incident response vendor for fourteen major cyber-insurance carriers and their principal London and Bermuda markets, which usually removes the pre-approval delay before response work can begin.

Regulatory clocks

GDPR's 72 hours, DORA's initial notification, SEC Item 1.05 materiality, HIPAA, NIS2 and the sector-specific regimes. We track the clocks that apply to you and produce the packs in the format each authority expects.

We had rehearsed this exact scenario nine weeks earlier with the same Guardian team. When it happened for real, nobody argued about who could authorise pulling the site offline — that decision had already been made once, in a room, on a Tuesday.

Seán O’Rourke
Director of IT, national distribution business · 9,000 seats

Put the paperwork behind you now

A retainer takes about two weeks to put in place and removes hours from your worst day. If today is already that day, say so on the form and it routes straight to the duty incident manager.