Skip to main content
All services

SERVICE 01 · INCIDENT RESPONSE

When the breach happens, every minute changes the cost.

Strace responds to active threats, contains the damage, and recovers your environment. Whether you've been hit today or you want a team on retainer for when it happens, we're built for the call.

THE PROBLEM

Breaches succeed when early signals are missed, response is delayed, and the team handling the incident is learning on the environment. Strace is built to reduce that friction: clear intake, pre-negotiated terms, standardized methodology, and practitioner-led execution from first call to final report.

WHAT WE OFFER

Six productized engagements.

IR-A

Incident response retainer

A standing relationship with a designated practitioner familiar with your environment and pre-negotiated terms. Tiers define included hours, response SLAs, and on-site availability.

IR-B

Reactive incident response

Active engagement when an incident is already underway. We deploy on confirmed compromise: ransomware, business email compromise, insider activity, data exfiltration, prolonged unauthorized access. We lead containment, eradication, recovery, and post-incident reporting through to closure.

IR-C

Digital forensics & investigations

Forensic imaging, timeline reconstruction, artifact analysis, and litigation-support documentation for breach investigations, internal misconduct, IP theft, and regulatory disclosure. Defensible methodology and full chain-of-custody documentation.

IR-D

Tabletop exercises & IR readiness

Facilitated tabletop scenarios for executive and technical teams. We simulate ransomware, business email compromise, insider threat, and supply-chain compromise scenarios specific to your industry, and produce a written gap report with prioritized remediation.

IR-E

Incident response plan development

A written incident response plan tailored to your business: escalation matrix, communication protocols, evidence handling workflow, executive decision tree, vendor contact roster, and regulatory disclosure guidance. Delivered as a document plus a 90-minute walkthrough with leadership.

IR-F

Threat hunting & compromise assessment

A proactive search for adversary presence across endpoints, logs, identity, mailbox, and cloud, typically a two-to-four-week engagement. We look for adversary tactics, techniques, and indicators of compromise, and document the findings in a written assessment.

WHO THIS IS FOR

Organizations without a dedicated incident response function · Companies facing an active incident or post-incident recovery · Managed service providers needing surge IR capacity · Defense contractors and regulated firms with disclosure obligations · Cyber insurance brokers placing IR vendor coverage · Legal counsel managing breach response · Organizations needing a senior incident response lead to work with their internal team

HOW WE WORK

Four phases. Senior ownership throughout.

01 · DETECT

We confirm the incident, scope its extent, and brief leadership within the first response window.

02 · CONTAIN

We isolate affected systems, cut attacker access, and stop active damage before recovery begins.

03 · ERADICATE

We follow the attacker path, remove persistence mechanisms, and close the gaps that allowed entry.

04 · RECOVER

We restore your environment, validate clean operations, and produce the executive and technical reports leadership and counsel need.

WHAT'S INCLUDED — IR RETAINER

  • Defined response SLAs by tier (4-hour, 8-hour, or next-business-day)
  • Pre-negotiated MSA and IR-specific SOW for activation under the agreed SLA
  • Designated lead practitioner familiar with your environment
  • Quarterly tabletop or readiness review
  • Annual IR plan review and update
  • Hours bank applicable to active incidents or proactive work
  • Post-incident executive and technical reporting

ENGAGEMENT STRUCTURE

Retainers, tabletops, and IR plans receive a fixed-scope proposal. Reactive engagements are scoped at incident confirmation, with rates and authorization agreed before forensic work begins. Availability for new incidents is confirmed at intake; retainer response follows the agreed SLA.

MSP PARTNERSHIPS

White-label and co-engagement incident response support is available for MSPs serving small and mid-market organizations.

FAQ

READY WHEN YOU ARE

If you're in an active incident, call now.

To discuss a retainer, IR plan, or tabletop exercise, request a 30-minute consultation.