Incident Response

Meet your incident responders before the incident.

Most teams meet their forensics firm on the worst day of the year, then spend the first six hours explaining their own network. We keep senior responders on call, and for retainer clients we already have the map: your identity, your endpoints, your logs, your escalation path. When something moves, we contain it and we document it well enough to hold up with your insurer, your regulator, and your lawyers.

In an incident right now?
888.234.5990 ext. 9999
Answered 24x7, client or not

Netrix has run and secured mid-market environments since 1989, with a security operations center that never closes and responders who have worked the incident you are worried about.

600+
Engineers on staff
1989
Securing IT since
24x7
Security operations center
1hr
Retainer response commitment
What we do

The work, from the first alert to the final report.

Some of this happens in the first hour. Some of it happens six weeks later, when your insurer asks for the report. We do all of it.

Emergency incident response

Senior responders on a bridge, not a queue. We make containment decisions with your team, not for them, and we keep a running record from minute one.

  • 24x7 activation, client or not
  • A named senior responder running the incident
  • Containment across endpoints, identity, and cloud
  • Hourly status your exec team can actually read
  • Coordination with your carrier and outside counsel

Incident response retainer

Prepaid hours, a signed contract, and a team that already knows your environment. The paperwork is done before you need it.

  • A guaranteed response window, in writing
  • Environment onboarding, so we start with the map
  • Annual plan review and a live tabletop
  • Unused hours roll into readiness work
  • Works alongside your carrier's panel firm

Digital forensics

We find out what actually happened, and we prove it. Evidence is handled so it holds up in a claim, an audit, or a courtroom.

  • Chain of custody from first collection forward
  • Endpoint, cloud, and mailbox forensics
  • Root cause and a full attacker timeline
  • Data exposure scoping for notification decisions
  • A written report your carrier and counsel can use

Readiness and tabletop

The cheapest incident is the one you rehearsed. We write the plan, then we run your team through it until the gaps show up.

  • An incident response plan written for your environment
  • Executive and technical tabletop exercises
  • Ransomware readiness assessment
  • Backup and recovery validation, tested not assumed
  • Insurance and regulatory requirement mapping
How it goes

The first 72 hours, in order.

Nobody is improvising. This is the sequence we run, and what your team is doing while we run it.

Hour 0

Activate

One call starts it. A senior responder gets on a bridge with your team, and everyone agrees on who is deciding what before anyone touches a machine.

Hours 1 to 12

Scope

We find out how far in they got: which accounts, which endpoints, which data. Guessing at this stage is what makes an incident expensive.

Hours 2 to 24

Contain

Isolate what is compromised and cut the attacker's access, while keeping the parts of the business running that can safely keep running.

Days 1 to 5

Evict

Remove persistence, reset the credentials that matter, and close the door they came in through. Eviction fails when it is rushed, so we verify.

Days 2 to 10

Recover

Bring systems back in an order that does not reinfect you. We validate each tier before it reopens to users, starting with the ones the business needs first.

Weeks 2 to 6

Report

Root cause, attacker timeline, and a written report for your insurer, your regulator, and your board. Then a short list of what to fix first.

What it looks like

A Friday night at a manufacturer.

Three shifts, one file server, and a plant that could not afford to lose Monday.

Encryption started on a file server at 9:40 on a Friday night. The plant ran three shifts and the ERP system sat two hops away from the machine that lit up first.

Because the retainer was already in place, a responder was on the bridge before eleven with a diagram we had built during onboarding. Nobody spent the night asking which subnet the plant floor was on. Identity was contained by midnight and the domain was clean by Sunday. First shift ran Monday morning, and the carrier had the forensic report three weeks later.

52 min
From call to responder on the bridge
1
Shift affected, out of a possible six
2 days
To a clean, validated domain
3 wks
To a report the carrier accepted
Why Netrix

Why teams keep us on retainer.

Five things that change what the first day looks like.

Straight answers

The questions we get every time.

Our cyber policy already names a panel firm. Do we need you too?
What does a retainer cost, and what happens if we never use it?
How fast can you actually be on a call?
We are in an incident right now and we are not a client. Can you help?
Will your report hold up with our insurer and our regulator?
Talk to us

Have this conversation on aTuesday,not on a Friday night.

Thirty minutes with an incident responder. We will walk your environment, look at what you would actually do in the first hour, and tell you whether a retainer is worth it for you.

Talk to an incident response engineer

No pitch deck. If your plan is already solid, we will say so, and you will have spent half an hour finding that out.