Service

Incident Response

Incident response support for NZ businesses—containment guidance, recovery coordination, and post-incident improvements when security events hit.

The first hours should be calm, not improvised

During a suspected breach, every action can help or make the situation harder to understand. Teams need a known escalation path, clear decision ownership, and technical guidance before panic turns into mass resets and lost evidence. We bring structure to containment, investigation, and recovery, then turn the lessons into practical hardening work.

Prepare the decisions before the pressure arrives

Help before, during, and after an incident:

  • Response planning and contact paths
  • Containment and triage support
  • Coordination with specialist forensics when required
  • Recovery sequencing with business priorities
  • Post-incident review and hardening recommendations

Contain carefully and preserve what happened

Isolate affected systems if it is safe to do so, avoid mass password resets from compromised devices, preserve evidence where practical, and contact support quickly. Quietly rebooting everything can destroy useful signal and spread the problem.

For teams that need an escalation path before a crisis

Businesses that want a known escalation path before a crisis, and organisations already dealing with ransomware, account takeover, or suspicious outbound activity.

Recovery should leave the business harder to hit twice

Incident response is the seatbelt. Managed security foundations—MFA, backups, patching, email defence—reduce how often you need it and how painful recovery becomes.

Frequently asked questions

Do you offer incident drills?

Yes. Tabletop exercises help leaders practise decisions before a real event—who communicates, who approves shutdowns, and how recovery is sequenced.

Are you available after hours for emergencies?

Emergency and 24/7 on-call cover options are available. Confirm the escalation path in your agreement before you need it.

Will you work with our insurer or legal advisors?

Where appropriate we can coordinate technically with the parties you engage. Legal and insurance decisions remain yours.

Can you help if we are not yet a managed client?

Contact us and we will be upfront about the fastest safe help we can offer in the moment, including whether immediate specialist escalation is wiser.

What happens after recovery?

A post-incident review should produce concrete hardening actions—identity, backups, email, endpoints—so you are not only “back online,” but harder to repeat-compromise.

Someone posing as our bank got access to a staff computer. What do we do first?

Ring the bank to freeze accounts, then ring us—in that order. We identify what remote access tool was used and whether it is still installed, scan the machine, and change what was exposed along with anywhere that password was reused. Do not wipe or reinstall before we have looked; how they got in is worth knowing.

Does it matter whether they controlled the computer or only watched the screen?

It matters a great deal, and it is the first thing we establish. View-only means they saw what the user saw—serious if someone signed into online banking while they watched, but nothing was installed. Full control means they could install software, change settings, or reach other systems, and the clean-up is far larger.

A caller asked our staff member to unplug their second monitor. Is that a red flag?

Yes, and a strong one. A remote session shows the other party one screen at a time, so a single small display puts everything the user does in front of them with nothing kept out of view. It is a control tactic. On its own it is reason enough to end the call and ring us.

How do you tell whether they installed anything?

We scan the machine, then check installed programs and running services for anything added recently or that nobody recognises. Remote access tools are legitimate software, so antivirus frequently will not flag them—they have to be found and removed deliberately rather than left to a scanner.

Our bank told a staff member to factory reset their phone. Is that right?

Usually yes, if the phone was the compromised device. Let us check what was actually used to reach them first—often a screen-share inside an app they already had—because removing that and changing the linked passwords is sometimes enough, and a reset costs anything not backed up.

After a scam, what needs changing and in what order?

Anything that could be used to contact people as the victim comes first—email, then social media—because the immediate risk is someone approaching their contacts asking for money. Then banking, then IRD, then anywhere the same password was reused. Expect the address to be sold on and attempts to continue, so this is also the moment to move to a password manager.