Skip to Content

Incident Response Services

When a breach happens, the first 72 hours determine everything.
Rapid containment, digital forensics, and recovery — available on retainer or emergency engagement.

The Challenge

A security breach is a crisis that most organisations are unprepared for. Not because they have not thought about it — most have some form of incident response plan. But the reality of a breach at 3 AM on a Saturday is fundamentally different from the tabletop exercise conducted in a conference room on a Wednesday afternoon.

What actually happens when a breach occurs:

  • Panic leads to evidence destruction. Well-meaning IT staff reboot servers, reimage workstations, or restore from backup — destroying the forensic evidence needed to understand what happened, how far the attacker got, and whether they are still present. Once evidence is destroyed, it cannot be recovered.
  • Slow response amplifies damage. In a ransomware incident, every hour of delay allows encryption to spread to additional systems. In a data exfiltration incident, every hour means more data leaving the network. In a business email compromise, every hour means more fraudulent transactions. The cost of a breach scales directly with response time.
  • Communication failures compound the crisis. Who needs to be told? When? What can you say publicly? What are your legal obligations under POPIA (72-hour notification to the Information Regulator for compromises involving personal information)? What do you tell customers? Employees? The board? Without a communication plan, organisations either say too much (creating legal liability), too little (losing stakeholder trust), or nothing at all (violating regulatory obligations).
  • Incomplete remediation leads to re-compromise. The attacker is removed from the visible systems, declared defeated, and everyone goes back to normal. But the attacker maintained persistence through a secondary backdoor, a scheduled task, or compromised credentials that were never rotated. Within weeks, they are back. This happens more often than anyone wants to admit.

Most organisations do not have the forensic capability, the containment playbooks, the legal coordination experience, or the crisis communication skills to handle a breach well. These are specialised competencies that require practice — and practice means exposure to real incidents, not annual tabletop exercises.

The Layer7 Approach

Layer7's incident response team provides end-to-end breach response — from initial containment through forensic investigation, remediation, recovery, and post-incident hardening. We are available on retainer (guaranteed response times) or emergency engagement (best-effort).

Rapid Containment

The first priority in any incident is stopping the bleeding. Our IR team deploys containment measures within hours of engagement:

  • Network isolation of compromised segments
  • Endpoint isolation via EDR (CrowdStrike, Defender, SentinelOne)
  • Account lockdown and credential rotation for compromised identities
  • Blocking of known attacker infrastructure (C2 domains, IPs, URLs)
  • Preservation of volatile evidence (memory dumps, running processes, network connections) before containment actions alter the state

Digital Forensics and Investigation

Once containment is established, we conduct a thorough investigation to answer the critical questions:

  • How did the attacker get in? Initial access vector — phishing, exploited vulnerability, compromised credentials, supply chain compromise, insider threat.
  • What did they do? Timeline of attacker activity — lateral movement, privilege escalation, data access, persistence mechanisms, staging, and exfiltration.
  • What was impacted? Systems accessed, data exposed or exfiltrated, accounts compromised, changes made to infrastructure.
  • Are they still here? Identification of all persistence mechanisms — scheduled tasks, registry modifications, implanted backdoors, compromised service accounts, modified authentication configurations.

Our forensic process follows chain-of-custody procedures that ensure evidence is admissible in legal proceedings — criminal prosecution, civil litigation, insurance claims, or regulatory investigation.

Malware Analysis

When malware is involved — ransomware, remote access trojans, information stealers, wipers — our team conducts analysis to understand the malware's capabilities, communication channels, and persistence methods. This analysis directly informs containment and remediation: you cannot eradicate what you do not understand.

Recovery and Hardening

We do not declare victory at containment. Recovery includes:

  • Verified eradication of all attacker persistence
  • System restoration from known-good backups (after verifying backup integrity)
  • Credential rotation across affected accounts and service accounts
  • Security control hardening based on attack path analysis
  • Enhanced monitoring for re-compromise indicators

Post-Incident Review

Every incident is an opportunity to improve. Our post-incident review covers root cause analysis, response effectiveness evaluation, gaps identified during the incident, and specific recommendations to prevent recurrence. This is not a blame exercise — it is a structured improvement process that makes your organisation more resilient.

What You Get

  • Emergency response — retainer and ad-hoc engagement models
  • Rapid containment and threat eradication
  • Digital forensics with chain-of-custody evidence handling
  • Malware analysis and reverse engineering
  • System recovery and integrity verification
  • Post-incident hardening recommendations
  • Detailed incident report with timeline and root cause
  • Post-incident review and lessons learned
  • Crisis communication support
  • Regulatory notification assistance (POPIA, SARB)

Retainer vs. Emergency Engagement

IR Retainer

  • Guaranteed response time (4 hours or less)
  • Pre-established access and documentation
  • Annual IR readiness assessment
  • Tabletop exercise included
  • Priority scheduling over ad-hoc engagements
  • Fixed annual retainer fee with pre-agreed rates

Emergency Engagement

  • Best-effort response time
  • Available when retainer clients are not consuming capacity
  • Higher hourly rates than retainer clients
  • Onboarding time required (access, documentation, context)
  • No pre-established baseline or readiness assessment

The retainer model is strongly recommended. Establishing access, documenting your environment, and conducting a readiness assessment before an incident occurs saves critical hours during an actual event. The cost of the retainer is a fraction of the cost of those lost hours during a breach.

Frequently Asked Questions

A retainer is recommended but not required. Retainer clients receive guaranteed SLAs, priority response, and pre-negotiated rates — critical advantages when every minute counts.

We execute immediate triage, containment strategy, evidence preservation, stakeholder notification, and begin initial forensic analysis — all within the first 60 minutes.

Yes — we support POPIA Information Regulator notification, affected party communication, and coordination with legal counsel throughout the regulatory process.

Retainer clients receive 24/7/365 availability with guaranteed response times. Emergency engagements are handled on a best-effort basis.

Be Prepared Before It Happens

Establish an IR retainer now. When the call comes at 3 AM, you will be glad you did.

Discuss IR Retainer Options