IR-A
Incident response retainer
A standing relationship with a designated practitioner familiar with your environment and pre-negotiated terms. Tiers define included hours, response SLAs, and on-site availability.
SERVICE 01 · INCIDENT RESPONSE
Strace responds to active threats, contains the damage, and recovers your environment. Whether you've been hit today or you want a team on retainer for when it happens, we're built for the call.
THE PROBLEM
Breaches succeed when early signals are missed, response is delayed, and the team handling the incident is learning on the environment. Strace is built to reduce that friction: clear intake, pre-negotiated terms, standardized methodology, and practitioner-led execution from first call to final report.
WHAT WE OFFER
IR-A
A standing relationship with a designated practitioner familiar with your environment and pre-negotiated terms. Tiers define included hours, response SLAs, and on-site availability.
IR-B
Active engagement when an incident is already underway. We deploy on confirmed compromise: ransomware, business email compromise, insider activity, data exfiltration, prolonged unauthorized access. We lead containment, eradication, recovery, and post-incident reporting through to closure.
IR-C
Forensic imaging, timeline reconstruction, artifact analysis, and litigation-support documentation for breach investigations, internal misconduct, IP theft, and regulatory disclosure. Defensible methodology and full chain-of-custody documentation.
IR-D
Facilitated tabletop scenarios for executive and technical teams. We simulate ransomware, business email compromise, insider threat, and supply-chain compromise scenarios specific to your industry, and produce a written gap report with prioritized remediation.
IR-E
A written incident response plan tailored to your business: escalation matrix, communication protocols, evidence handling workflow, executive decision tree, vendor contact roster, and regulatory disclosure guidance. Delivered as a document plus a 90-minute walkthrough with leadership.
IR-F
A proactive search for adversary presence across endpoints, logs, identity, mailbox, and cloud, typically a two-to-four-week engagement. We look for adversary tactics, techniques, and indicators of compromise, and document the findings in a written assessment.
WHO THIS IS FOR
Organizations without a dedicated incident response function · Companies facing an active incident or post-incident recovery · Managed service providers needing surge IR capacity · Defense contractors and regulated firms with disclosure obligations · Cyber insurance brokers placing IR vendor coverage · Legal counsel managing breach response · Organizations needing a senior incident response lead to work with their internal team
HOW WE WORK
01 · DETECT
We confirm the incident, scope its extent, and brief leadership within the first response window.
02 · CONTAIN
We isolate affected systems, cut attacker access, and stop active damage before recovery begins.
03 · ERADICATE
We follow the attacker path, remove persistence mechanisms, and close the gaps that allowed entry.
04 · RECOVER
We restore your environment, validate clean operations, and produce the executive and technical reports leadership and counsel need.
WHAT'S INCLUDED — IR RETAINER
ENGAGEMENT STRUCTURE
Retainers, tabletops, and IR plans receive a fixed-scope proposal. Reactive engagements are scoped at incident confirmation, with rates and authorization agreed before forensic work begins. Availability for new incidents is confirmed at intake; retainer response follows the agreed SLA.
MSP PARTNERSHIPS
White-label and co-engagement incident response support is available for MSPs serving small and mid-market organizations.
FAQ
READY WHEN YOU ARE
To discuss a retainer, IR plan, or tabletop exercise, request a 30-minute consultation.