Book online or chat with usAnswered 24/7Licensed, insured & bondedSchedule a Consultation
Request serviceUrgentConsultation

Cyber Incident Response

A breach or ransomware event is measured in hours. Honeybadger provides cyber incident response — on retainer for readiness, or as emergency help when the alarm is already going off — to contain the damage, get you back online, and preserve the evidence you may need later.

Built for
  • Businesses hit by ransomware or a breach
  • Firms with no incident plan in place
  • Organizations with compliance or notification duties
  • Insurers & counsel needing a responder

What we do in an incident

  • Triage — rapidly determine what is happening, what is affected, and how bad it is.
  • Containment — isolate affected systems to stop the spread before it reaches the rest of the network.
  • Eradication — remove the attacker’s foothold and close the entry point they used.
  • Recovery — restore operations from clean sources and verify the environment is safe.
  • Forensics & root cause — determine how it happened and document it to court-ready standards.
  • Reporting — the documentation you need for leadership, insurers, regulators and, if it comes to it, litigation.

For encryption events specifically, see our ransomware recovery service. Not sure how exposed you are yet? The free Ransomware Readiness Scorecard takes two minutes.

Retainer vs. emergency

An incident response retainer means we already know your environment and can move immediately, usually at a better rate and response time. Emergency engagement is for when something is happening right now and you have no plan in place — we still respond, we just start cold.

How it works

  1. Prepare (retainer). We learn your environment so response is fast when it counts.
  2. Detect & triage. We confirm scope and severity the moment you engage.
  3. Contain. We stop the spread and protect what is not yet affected.
  4. Eradicate & recover. We remove the threat and restore clean operations.
  5. Report & harden. We document the event and close the gap that allowed it.

Why Honeybadger

Court-ready & defensible
Documentation, chain of custody and reporting built to withstand scrutiny.
Veteran-led
Operators disciplined by the standards they carried in uniform.
Arizona direct, nationwide reach
Delivered from our Arizona headquarters to clients across all 50 states.
One accountable firm
Investigations, cyber and forensics under a single relationship.

Active incident right now? Do not power everything off — that can destroy evidence. Contact us through our urgent & after-hours channel and we will guide the first steps.

Related: Ransomware Recovery · Threat Mitigation & SOC · Cyber Security & MSSP

The first hour

What actually happens when you call

Incident response is judged on the first hour, and most of the damage in that hour is self-inflicted. The instinct is to reboot the affected machine, change every password at once, or start deleting what looks malicious. Each of those destroys evidence, and one of them can trigger the encryption routine you were trying to avoid. The sequence below is the one we work to.

01 Detect

Establish what you are seeing

Separating an incident from an outage matters, because the responses are opposite. We work from the alert, the affected systems and what the people on site observed, and confirm scope before acting on it.

02 Triage

Decide what moves first

Which systems are affected, which hold regulated or privileged data, what is still reachable, and what the business cannot operate without. That ordering determines everything that follows.

03 Contain

Stop the spread

Host isolation, account disablement and network blocks — taken in an order that preserves volatile evidence rather than wiping it. Isolating a machine is not the same as powering it off, and the difference matters later.

04 Eradicate

Remove the access, not just the symptom

Malware removal alone rarely ends an intrusion. Persistence mechanisms, added credentials, inbox rules, scheduled tasks and registered devices get removed, and the access paths used to get in are closed.

05 Recover

Rebuild to a known-good state

Secure rebuild and validated restore from a clean point, with systems verified before they are reconnected. Restoring into the same weakness that allowed the intrusion is the most common cause of a second incident.

06 Review

Document and harden

A post-incident report with timeline, root cause and corrective actions — the document your insurer, your counsel and your customers will ask for, and the basis for the hardening work that follows.

Evidence

Why we preserve before we rebuild

Recovery and evidence preservation pull against each other. The fastest route back to working systems is to wipe and restore; the route that preserves your legal and insurance position is to image first. We plan for both, and we make that call deliberately with you rather than losing it in the urgency of the moment.

This matters because a cyber incident frequently becomes several other things afterwards: an insurance claim that requires proof of what happened, a regulatory notification with statutory deadlines, a dispute with a vendor or customer about who was responsible, and occasionally a criminal matter. Each of those depends on artefacts that exist only on the affected systems, and only until somebody reformats them. Because we also run digital forensics, preservation is handled to evidentiary standard with documented chain of custody rather than as an afterthought once the systems are already gone.

Response & containment

  • Alert triage, escalation and incident command
  • Host isolation, account disablement and network blocks
  • Ransomware response and recovery
  • Business email compromise investigation
  • Eradication, secure rebuild and validation
  • Stakeholder communications and status updates

Forensics & post-incident

  • Evidence preservation and chain of custody
  • Timeline reconstruction and root-cause analysis
  • Malware and log analysis
  • Breach notification and regulatory support
  • Coordination with legal counsel and cyber insurers
  • Post-incident report, lessons learned and hardening plan

Retainer

Why readiness is bought before the incident

An incident response retainer exists because the worst time to negotiate terms, exchange contracts and explain your environment to a stranger is while an attacker is still inside it. A retainer puts pre-agreed terms, priority response targets and an annual readiness review in place, so help is already under contract when it is needed.

It also front-loads the part that otherwise costs hours: we already know your environment, who can authorize containment, where the backups are, what your notification obligations look like and who your insurer is. Organizations without a retainer routinely lose their first half-day to procurement and orientation, and that is the half-day in which scope expands.

On the question everyone asks: should you pay a ransom? That is a decision for you, your counsel and your insurer, and it carries sanctions and legal exposure that vary by circumstance. What we can tell you plainly is that paying does not reliably return your data — decryption tools supplied by attackers are frequently slow, incomplete or broken — and it does not remove their access. Any provider promising a specific recovery outcome before examining your environment is telling you what you want to hear. Our job is to establish your real recovery position, ideally before you ever need it, which is what tested, immutable backup exists to provide.

Response phases follow NIST SP 800-61, Computer Security Incident Handling Guide. Recovery planning follows NIST SP 800-34. Ongoing detection is delivered through our security operations centre, and prevention through managed IT and network security.

Before you call anyone

What to do, and what to avoid, in the first ten minutes

If you are reading this during an incident, this section is the useful one. None of it requires a specialist, and getting it right materially improves every option available afterwards.

Do

  • Disconnect affected machines from the network — unplug the cable or disable the wireless adapter. This limits spread while leaving the system’s memory and state intact.
  • Leave affected machines powered on. Volatile memory holds evidence about what is running and what credentials were used, and it is lost the moment the machine is shut down.
  • Write down what you observed and when, including the first symptom and who noticed it. Timelines reconstructed from memory a week later are unreliable and get challenged.
  • Check whether backups are reachable and separated from the affected network, without connecting them to it to find out.
  • Notify your insurer early. Many cyber policies require prompt notification and some require using an approved responder, and failing that condition can affect cover.
  • Assume email may be compromised and coordinate through a channel the attacker is unlikely to be reading.

Avoid

  • Do not reboot or power down the affected systems. It destroys volatile evidence and, with some ransomware, accelerates encryption.
  • Do not delete files, mailboxes or logs that look malicious. They are evidence, and log retention windows are often short enough to lose the answer entirely.
  • Do not restore from backup immediately onto a network that has not been examined. Restoring into an environment the attacker still occupies is how second incidents happen.
  • Do not reset every password at once before scoping. It tips off an intruder still inside and can lock out the accounts needed to investigate.
  • Do not contact the attacker or engage with a ransom demand before speaking to counsel and your insurer. There are sanctions and disclosure implications.
  • Do not reimage the first affected machine. It is usually the one carrying the evidence of how entry was gained.

One further note on scope. The instinct during an incident is to treat it as confined to the machine where it was noticed. In practice, by the time ransomware is visible the attacker has usually held access for some time and has moved laterally, and the visible encryption is the last step rather than the first. That is why containment is scoped from evidence rather than from the symptom, and why an investigation that stops at the first affected host tends to be followed by a second call a few weeks later.

Common questions

Cyber incident response: frequently asked questions

What should we do first if we think we have been hacked?

Disconnect affected machines from the network rather than powering them off, leave logs and suspicious files in place, and bring in an incident responder before restoring anything. Use the urgent intake form and we will guide the first steps.

Should we turn off infected computers?

Usually not. Powering a machine off destroys volatile evidence and, with some ransomware, can make recovery harder. Isolating it from the network contains the spread while keeping what investigators, insurers and counsel will need.

What is the difference between an incident response retainer and emergency response?

With a retainer we already know your environment, so response starts immediately on terms agreed in advance. Emergency response is for an incident happening now with no plan in place. We still respond, but we start without that groundwork.

Can you work with our cyber insurer and legal counsel?

Yes. We coordinate with your insurer and counsel, preserve evidence with documented chain of custody, and deliver a post-incident report with the timeline, root cause and corrective actions they will ask for.

Do you handle incidents outside Arizona?

Yes. Incident response is delivered from our Arizona headquarters to clients in all 50 states, remotely and on site where the incident requires it.

How do we get started?

Request incident response online for a retainer or a scoped engagement. Picking the service routes it straight to the cyber and forensics team, so there is no phone tag. For anything happening right now, use the urgent intake form.

Guides on this topic