Incident Response & Focused Forensics
Respond methodically. Establish the facts.
Unusual access, a suspicious system or an application outage can raise many questions at once. We help you prepare for incidents and conduct an agreed technical investigation. Clear records of evidence, decisions and actions connect containment, recovery and follow-up work.

Your options
Services that move your project forward
Prepare contacts and responsibilities
Critical processes, contact channels, access and decision-making powers are clarified before an incident occurs. Necessary external parties are taken into account.
Less time lost due to unclear responsibilities in the event of an incident.
Establish the situation
We record known indications, affected systems and measures that have already been taken. Uncertainties are separated from confirmed findings.
A joint situation picture as a basis for the next decisions.
Coordinate containment
Containment options are assessed with their possible operational consequences. Approvals, dependencies and follow-up monitoring are documented.
Interventions are carried out in a controlled manner and with comprehensible responsibility.
Examine technical evidence
Available logs, configurations and selected artifacts are considered within the agreed scope of investigation. The origin and processing of relevant data are recorded.
Comprehensible insights into affected processes and open questions.
Plan recovery
Remediation, suitable backups and controlled restoration are planned with operations and business stakeholders. Agreed checks support the decision to restore service.
A justified way back to a verified operating condition.
Turn findings into improvements
The process, decisions and technical causes are processed as far as verifiable. Measures are given priorities and those responsible.
The incident provides specific starting points for more resilient processes.
Where to start
Incident Response & Focused Forensics Use cases
Three example situations show how we can help.
Plan your response before the emergency
An organization wants to test contact chains and technical readiness. Preparation and a practical exercise reveal gaps before an incident creates time pressure.
Classify suspicious activity
Unusual accesses or system messages must be evaluated. A focused investigation separates reliable indications from assumptions and identifies necessary next steps.
Targeted improvement after an incident
Services have been restored, but causes and remaining tasks need clearer documentation. We support the technical review and prioritize improvements.
From requirements to results
A clear process with agreed milestones
Agree the mandate and scope
Affected areas, contact persons, availability and examination limits are agreed.
Preserve and assess evidence
Existing data and measures already taken are recorded in a comprehensible manner.
Coordinate actions
Containment and recovery are planned and reviewed with those responsible.
Explain findings and follow-up work
Findings, remaining uncertainties and prioritized improvements are explained.
Your benefit
What you receive
- Documented situation report with confirmed findings and open questions.
- Comprehensible technical investigation to the agreed extent.
- Coordinated measures and criteria for recovery.
- Final meeting with prioritized improvements and responsibilities.
Ways to work with us
Choose a starting point that fits your needs. We agree the scope and required effort in a tailored proposal.
Incident readiness review
For preparation: contact persons, technical requirements and prioritized improvements.
Request a quote: Incident readiness reviewFocused investigation
For a specific question: agreed data sources, comprehensible analysis and discussion of results.
Request a quote: Focused investigationExercise and follow-up
For better processes: realistic scenarios, joint evaluation and revised procedures.
Request a quote: Exercise and follow-upQuestions before you get started
Can we request support immediately in the event of an acute incident?
Contact us through the published channels. Availability, start time and scope are confirmed explicitly. The general website form does not establish an immediate-response commitment. Sensitive evidence is exchanged through an agreed channel.
What does a focused forensic investigation involve?
The scope may cover selected time periods, systems or event sources. Methods and limitations are documented. Examination of every device, expert testimony or specialist analysis requires a separate agreement.
Should we shut down suspicious systems immediately?
A blanket decision can influence operational processes and available traces. Measures should be coordinated with the responsible incident managers based on the specific situation. Priority is given to the established emergency procedures and necessary protective measures.
How are investigation findings documented and protected?
Relevant data sources, collection methods, time references and processing steps are recorded in a comprehensible manner. If necessary, integrity checks and suitable access restrictions are agreed. Conclusions are separated from unverifiable assumptions.
Do you take over reports to authorities or affected persons?
Reporting and communication obligations will be clarified with the responsible departments of your company and, if necessary, legal advice. We can supply technical facts and timelines. Representation or independent reporting is not automatically part of the order.
Can existing IT service providers be integrated?
Yes. We coordinate access, responsibilities, interventions and handovers with your teams and existing service providers. Joint documentation helps to avoid contradictory measures and loss of information.
How is service restoration approved?
We agree on verification criteria, remaining risks and the responsible decision-makers. Remediation, credential replacement, recovery and monitoring are considered for the affected systems.
Can we rehearse our response in advance?
Yes. A moderated exercise can check decisions, contact channels and technical requirements on the basis of an agreed scenario. This results in an action plan to improve the ability to act and documentation.
Discuss your next step
How prepared is your organization for an incident?
Describe the support you need without including sensitive investigation data. We will clarify responsibility, availability and a suitable channel for exchanging evidence.
Incident Response & Focused Forensics
Your next step
Tell us what you need. We will route your enquiry to the right team and discuss the next steps with you.
Fields marked * are required. Phone, company and postal address are optional.