Incident response
Incident response advisory from the customer side of the bridge, before, during, and after an incident.
What we deliver
- Incident response retainer
A named contact, an agreed customer-side response time, and a monthly cadence call between incidents.
- Tabletop exercises
Scenario-based dry runs for your leadership and IT team, with a written action list afterwards.
- Post-incident review
Root cause, which control stopped the incident, and what we change now.
- Board and regulator communications
NSM reporting, NIS2 notification obligations, and customer letters during an active incident.
- Coordination with CrowdStrike Falcon Complete
Local escalation contact in Norwegian during an active case, while Falcon Complete runs the bridge.
- Forensics support with external DFIR
We coordinate with an external DFIR firm when the case needs full investigation, and hold the customer side together.
How we deliver this service
- In a project
A tabletop exercise or a post-incident review with a defined deliverable and a final report.
- In a role at the customer
An incident response retainer with a named contact and an agreed response time over twelve months.
- As part of a service
Included in the Secured by FM CyberSecurity bundle for small and medium-sized businesses.
The platform we offer
Recent insights on Incident response
- What to check in a next-generation SIEM proposal
The next-gen label does not define one architecture or price model. Evaluate source coverage, detection, search, retention and the work behind the service.
- Incident response: preparation, containment and reporting in Norway
A response plan should identify who can act, how evidence is preserved and which notifications apply. The first decisions depend on the incident, not a fixed script.
- Data breaches and ransomware: different consequences, connected response
Ransomware can affect availability, confidentiality and recovery. Norwegian businesses need to assess operational harm and personal-data obligations together.