Skip to content

INCIDENT RESPONSE

Cyber Incident Response & Recovery

Suspected compromise of a website, web app or hosting environment? We help contain the damage, preserve available evidence and recover safely. Confirm our availability before relying on a response: this is not a 24/7 emergency hotline or a formal forensic investigation.

Ask about incident availability

Not a 24/7 emergency hotline. If you need immediate help, use your agreed escalation route or contact your hosting provider rather than waiting for an unconfirmed reply.

What we can scope

  • Containment without destroying useful evidence
  • Malware cleanup and known-good recovery
  • Credential and access-key rotation
  • Root-cause review and practical hardening

For suspected compromise of a website, web app or hosting environment, we help establish what is affected, contain further harm and restore a usable service. Work depends on the access available, the incident and our confirmed capacity.

Before you contact us

This is not a 24/7 emergency hotline. Submitting an enquiry does not start an incident response or reserve cover. Existing clients should use the escalation route in their agreement. If you need immediate help and we have not confirmed availability, contact your hosting provider or a specialist incident response provider rather than waiting for this form.

Use a trusted device and an unaffected contact account if your usual email may be compromised. Tell us which public service is affected, when you noticed the problem, the symptoms, any actions already taken and what access is still available. Do not send credentials, raw logs, personal data or confidential evidence through chat or the public form; we will agree a suitable transfer route.

Avoid wiping servers, deleting suspicious files or repeatedly changing the affected system before evidence and recovery options have been considered. If users are at risk, ask your host to help restrict or isolate the affected service. A maintenance page alone does not remove an attacker's access.

Containment and available evidence

We agree authority to act and priorities, then help limit further damage. Depending on the environment, this may involve restricting traffic or administrative access, isolating a service and preserving protected copies of relevant files, logs and timestamps. We record the actions taken and the limits of what we can establish.

If insurance, legal proceedings, regulated data or a wider network compromise may be involved, involve the relevant specialist early. We preserve what we reasonably can, but do not sell this work as a formal forensic investigation or promise court-admissible evidence.

Cleanup and recovery

We review malicious changes and persistence within scope, then plan cleanup or rebuilding from trusted sources. A backup must be checked before it is treated as known-good. We address the likely entry route, review accounts and sessions, and rotate relevant passwords, keys and application secrets through a trusted access route.

Recovery checks cover the affected service, its important user journeys and signs of recurrence before normal access is restored. Timings depend on the evidence, data integrity, backups and external providers: a fixed recovery time cannot be promised before assessment.

A useful record and follow-up

You receive a technical summary of the available timeline, affected systems we could verify, actions taken, likely root cause, remaining uncertainty and recommended next steps. It is not a guarantee that no hidden compromise remains.

We can then scope Web & Infrastructure Security Assurance to close remaining gaps and agree recurring checks. Recovery and ongoing assurance are separate engagements.

Agree the work before it starts

We confirm availability, authorised systems, containment actions, communication, fees and the next decision point before work begins. Scope changes and specialist referrals are discussed rather than assumed. Routine website faults belong under WordPress care or server management; a suspected compromise takes this incident path.

Initial scoping conversation is free

Agree the next step

Tell us what you need help with. We’ll talk through the options and next steps.

  • Deliverables and fees in writing
  • Follow-up and open actions recorded
  • Access and responsibilities agreed
Ask about incident availability

Enquiries: Mon–Fri, 9am–6pm UK time. Incident response subject to confirmed availability and agreed cover.