Cybersecurity

Incident response when the alert goes red.

Uzado's IR team supports your CIRT with containment, eradication, forensics, and post-incident hardening for businesses across North America. Retainer or on-demand.

What's covered

The work Uzado IR runs alongside your team

Incidents are won by the team that prepared. Uzado's IR engagement covers the full lifecycle so the technical response is decisive while business decisions stay with leadership.

Triage & containment

Rapid scoping of severity, blast radius, and active attacker presence. Containment actions executed immediately on in-scope systems.

Eradication & recovery

Attacker access removed, backdoors cleaned, systems restored to a known-good state. Recovery runs alongside containment, not after it.

Forensics

Disk and memory forensics, log analysis, and timeline reconstruction. Evidence preserved for regulator, law-enforcement, or insurance review.

Regulatory notification support

Drafts, timelines, and runbook for breach notification to Canadian and EU supervisory authorities. The 72-hour clock under GDPR Article 33 is met deliberately.

Post-incident hardening

Root-cause-driven remediation: identity, segmentation, monitoring, and process gaps closed. The same incident does not happen twice.

Service modes

Retainer or on-demand

The retainer model includes a defined response SLA, priority routing, and a reduced hourly rate during active incidents. On-demand engagements activate at the time of incident and run on standard rates. For businesses across North America with cyber insurance, retainer also satisfies most carrier preparedness expectations.

How we deliver

A five-step engagement model

01
Activation

Phone or chat activation triggers a senior responder. Initial bridge and triage call within minutes for retainer clients.

02
Triage & scope

Severity assessment, scope determination, and stakeholder notification path agreed in the first hour.

03
Containment & eradication

Active threat removed from the environment. Communication runs on a defined cadence with leadership.

04
Recovery & validation

Systems restored, integrity validated, monitoring re-baselined. Hand-off back to operations with documented next steps.

05
Lessons learned

Written incident report, contributing factors, and remediation roadmap delivered within agreed SLA.

Operating with

Tooling we typically run during IR

SentinelOne endpoint detection and response partnerHuntress managed detection and response partner
FAQ

Common incident response questions

Retainer vs on-demand: what's the difference?+

Retainer engagements include guaranteed response SLAs (typically 30 minutes to first responder), pre-approved blanket authorisations, and reduced hourly rates during incidents. On-demand engagements activate when an incident occurs but without pre-negotiated SLAs or pricing. Retainer is the right model for most businesses with material brand or revenue at risk; on-demand fits where insurer panel coverage is already in place.

Do you work alongside our IT team?+

Yes. Uzado's IR team plugs into your existing CIRT, IT, and leadership structure. We bring tradecraft and 24x7 coverage; you keep operational ownership of the environment. Hand-offs are explicit and documented.

Do you support cyber insurance claims?+

Yes. Uzado IR engagements are structured to support insurance carrier requirements: documentation, evidence preservation, and reporting timelines. We work alongside breach counsel and forensic firms named on your panel.

What about regulator notification timing?+

GDPR Article 33 requires notification of personal data breaches within 72 hours of becoming aware. PIPEDA mandates notification of breaches with real risk of significant harm without unreasonable delay. Uzado runs the breach decision tree, drafts the notifications, and supports the engagement with breach counsel.

Will you preserve evidence?+

Yes, by default. Disk images, memory captures, and logs are preserved with chain-of-custody documentation. Even when the immediate goal is recovery, evidence preservation is built into the runbook so options remain open later.

What tooling do you use during IR?+

Uzado typically operates SentinelOne for endpoint forensics and containment, Huntress for identity and Microsoft 365 telemetry, plus open-source forensic tooling for memory and disk analysis. We can also operate against your existing tooling if that is the faster path during an active incident.

Related: MDR, Managed Backups, and vCISO.

Set the retainer up before you need it.

Talk to Uzado. We will scope a retainer that matches your environment, your insurance posture, and your risk tolerance.