Incident Response

Managed incident response, the moment it matters.

When an attack hits, hours matter. SubRosa's managed incident response puts a dedicated team on call to detect, contain, and evict the threat, then restore operations and make sure it does not happen again.

24/7 · Containment · Eradication · Recovery · Retainer

Managed incident response, defined

What is managed incident response?

Managed incident response is an outsourced service where an expert team stands ready to handle security incidents on your behalf around the clock. Often set up in advance as a retainer, it covers the full lifecycle: detection and triage, containment and eradication of the threat, recovery of operations, and a post-incident review, so you have specialists on the line from the first alert instead of scrambling to find help mid-breach.

What's included

The full response lifecycle.

From the first alert to the after-action report, we run the entire response.

24/7 detection & triage

Round-the-clock monitoring and triage so an incident is caught and scoped fast, before it spreads.

Rapid containment

Immediate action to isolate affected systems and cut off the attacker's access and lateral movement.

Eradication & recovery

Removing the threat and safely restoring operations, with evidence preserved for any investigation.

Post-incident review

A clear analysis of what happened, how it was handled, and the changes that stop it recurring.

How an engagement runs

What happens when you call.

Retained clients get a defined path from first call to closed incident. This is that path, including the parts that determine whether an incident becomes a breach notification.

  1. 01

    First contact and triage

    You reach an engineer, not a queue. The first conversation establishes what you are seeing, what is still running and what has already been changed — that last one matters, because well-meant early action frequently destroys the evidence needed later.

  2. 02

    Scoping the compromise

    Before containment we establish how far it has gone. Pulling the wrong system offline first can tip off an attacker who then accelerates, so the sequence is deliberate rather than reflexive.

  3. 03

    Containment

    Cutting off access and stopping spread, coordinated with you so business impact is a decision you make with information rather than a surprise.

  4. 04

    Evidence preservation

    Forensic images and logs are preserved properly and early. If this later becomes a regulatory matter, an insurance claim or litigation, evidence gathered correctly at the start is what makes those survivable.

  5. 05

    Eradication and recovery

    Removing persistence and restoring cleanly. Restoring from a backup that already contains the attacker's foothold is one of the most common ways an incident recurs a fortnight later.

  6. 06

    Post-incident review

    A written account of what happened, how, and what would have prevented it — plus the changes worth making. Findings feed into Sable so remediation is tracked rather than forgotten once the pressure lifts.

Why SubRosa

Ready before you need us.

Response in minutes

Set up as a retainer, we already know your environment, so response starts in minutes rather than after a lengthy onboarding.

Seasoned responders

Our team has handled real breaches across every kind of environment, from ransomware to nation-state intrusions.

Retainer or on-demand

Engage us as a standing retainer for guaranteed response times, or call us in when an incident strikes.

Every incident, one timeline.

From alert to after-action.

Your incident runs in Sable: a live timeline of detection, containment, and recovery, evidence and actions in one place, and the after-action items tracked to done, so nothing is lost in the chaos of a response.

Response in Sable
Live incidentRansomware
  1. 1
    Detected: ransomware on hostContained
    T+00:04
  2. 2
    Isolated 3 affected hostsDone
    T+00:19
  3. 3
    Eradicated persistenceDone
    T+01:12
  4. 4
    Operations restoredRecovering
    T+04:30
Detect · contain · recoverEvidence preserved

Common questions

What is managed incident response?
Managed incident response is an outsourced service where an expert team stands ready to handle security incidents on your behalf around the clock. Often set up in advance as a retainer, it covers the full lifecycle: detection and triage, containment and eradication, recovery, and a post-incident review, so you have specialists on the line from the first alert instead of scrambling mid-breach.
What is an incident response retainer?
An incident response retainer is an agreement set up before an incident that guarantees a response team and defined response times when you need them. Because SubRosa already knows your environment, response starts in minutes rather than after a lengthy onboarding. You can also engage us on demand when an incident strikes.
What should we do first if we think we are compromised?
Call, and avoid changing things before you do. The instinct to reimage the affected machine or delete the malicious file is understandable and frequently destroys the evidence needed to work out how far the compromise went — and to answer a regulator or an insurer later. Isolate rather than wipe, preserve rather than clean, and get an engineer on the phone.
Do we need a retainer, or can we call during an incident?
We take both. A retainer means faster engagement, agreed response times and a team that already knows your environment — which matters, because the first hours of an incident are largely spent learning the environment when there is no retainer. We would rather you had one, and we will still take the call if you do not.
Will you help with regulators, insurers and legal?
We support them with proper evidence and a defensible account of what happened. Preserving forensic evidence correctly at the outset is what makes a regulatory response, an insurance claim or litigation survivable, and it is the step most commonly skipped in the first panicked hour.
What happens after the incident is contained?
A written account of what happened, how it happened and what would have prevented it, with concrete changes worth making. Findings feed into Sable so remediation is tracked to closure rather than forgotten once the pressure lifts — which is when most post-incident actions quietly die.

Have responders on the line before you need them.

Set up a managed incident response retainer so an expert team is ready the moment something goes wrong.