IR-01 //First Response
Stop the SituationFrom Getting Worse.
- 01
01 // UNDERSTAND
Determine what systems, users, identities, or infrastructure may be affected.
- 02
02 // CONTAIN
Take appropriate steps to limit the threat and reduce additional exposure.
- 03
03 // STABILIZE
Protect critical operations while preparing the environment for recovery.
IR-02 //Incident Types
When Something Goes Wrong,We Help Find the Path Forward.
10 incident classifications
- ENDPOINTIR-01
Ransomware
Encrypted systems, ransom demands, and disrupted operations that call for calm, structured decisions.
- ENDPOINTIR-02
Malware
Malicious software on workstations or servers that needs to be identified, contained, and removed.
- IDENTITYIR-03
Compromised Accounts
Stolen credentials or unauthorized sign-ins that expose email, files, and connected systems.
- EMAILIR-04
Business Email Compromise
Mailbox takeover, fraudulent payment requests, or impersonation aimed at your people and partners.
- ACCESSIR-05
Unauthorized Access
Someone reached systems or data they shouldn't have, and the scope needs to be understood.
- DATAIR-06
Data Exposure
Sensitive information that may have been accessed, copied, or made available without authorization.
- NETWORKIR-07
Network Intrusion
Suspicious traffic or activity suggesting an unauthorized party is operating inside the network.
- DEVICEIR-08
Lost or Compromised Devices
Missing laptops or phones, or devices that may have been tampered with or accessed.
- SIGNALIR-09
Suspicious Activity
Unusual alerts, sign-ins, or behavior that should be investigated before it becomes something larger.
- CONTROLSIR-10
Security Control Failure
Backups, firewalls, or other protections that didn't work as expected when they were needed.
Every incident is different. Response actions and outcomes depend on the environment, available evidence, and the nature of the event.
IR-04 //Containment
Contain the Threat.Protect the Business.
Stage 01 // DETECT
A compromised resource is identified and its connections to the rest of the environment are mapped.
Isolation isn't automatic. Each containment action is a deliberate decision based on the environment, the potential business impact, and the evidence available at the time.
Containment Map
Illustrative
- INTERNETOperational
- FIREWALLOperational
- CORE NETWORKOperational
- IDENTITYOperational
- SERVERSOperational
- ENDPOINTSCOMPROMISED
- CLOUDOperational
IR-05 //Incident Analysis
Understand What Happened.
Case Workspace // Analysis View
Illustrative incident data
Evidence sources
- TIMELINE
- IDENTITIES
- ENDPOINTS
- NETWORK ACTIVITY
- SECURITY EVENTS
- AFFECTED SYSTEMS
- INDICATORS
Event timeline
Sample case
Suspicious authentication activity identified
IDENTITYLogged
Endpoint behavior correlated
ENDPOINTLogged
Affected resource isolated
CONTAINMENTLogged
Containment validation underway
VALIDATIONIn progress
Signals
IDENTITIES
2 accounts under review
ENDPOINTS
1 device isolated
NETWORK ACTIVITY
Outbound traffic reviewed
SECURITY EVENTS
Alerts correlated to one case
AFFECTED SYSTEMS
Scope: 1 segment
INDICATORS
3 indicators documented
Fictional example for illustration only. Not customer data and not a live system.
IR-06 //Recovery
Getting Back Online Is OnlyPart of the Job.
STABILIZE
Confirm the threat is contained and the environment is steady.
VALIDATE
Verify systems, accounts, and backups are trustworthy before restoring.
RESTORE
Bring services back carefully, in business-priority order.
MONITOR
Watch for signs of continued or renewed compromise.
IMPROVE
Apply what was learned to reduce future risk.
What recovery may include
Every recovery plan is shaped by the incident and the environment. Work is prioritized around the systems your business depends on most.
What can be restored depends on factors such as the condition of backups and the nature of the incident. Not every system or piece of data can always be recovered, which is why recovery options are evaluated early and communicated plainly.
- System restoration
- Credential resets
- Access-control changes
- Security configuration changes
- Endpoint validation
- Network validation
- Monitoring
- Documentation
- Remediation planning
IR-07 //After the Incident
Turn an Incident Intoa Stronger Environment.
- Output // 01
Root Cause & Timeline
Help establish what happened and how the incident developed based on available evidence.
- Output // 02
Remediation Roadmap
Prioritize weaknesses and corrective actions discovered during response.
- Output // 03
Security Improvements
Identify opportunities to strengthen identity, endpoint, network, backup, monitoring, and other defensive controls.
- Output // 04
Documentation
Provide useful documentation of findings, actions, and recommended next steps.
From Response to Resilience
What Happens After the Emergency?
Once the immediate incident has been addressed, organizations may choose to validate the broader environment and identify additional weaknesses. Alpha Group, OneGuard IT's offensive security division, offers authorized post-incident security assessments as an optional next step.
Separate, optional engagement // Authorized scope only
01What should we do first if we suspect a cyber incident?
Avoid making large changes before the situation is understood. Write down what was observed and when, don't delete suspicious emails, files, or logs, and limit use of systems that appear affected. Contact your IT or security provider as early as possible and notify internal leadership according to your policies. If you carry cyber insurance, review your policy early, since many insurers have specific notification requirements. The right first steps depend on what is happening in your environment, so it helps to talk through the situation before taking broad action.
02Should we disconnect affected computers from the network?
Isolating an affected device can help limit spread, but how it's done matters. Disconnecting network access, such as unplugging the network cable or turning off Wi-Fi, is generally preferable to powering a device off, because shutting down can erase information in memory that may help an investigation. In some environments, isolating a system can also disrupt critical operations. If you're unsure, contact OneGuard IT to discuss the situation before disconnecting systems broadly.
03Can OneGuard IT respond to ransomware?
Yes. OneGuard IT helps organizations respond to ransomware by assessing the scope of the event, helping contain further spread, and evaluating recovery options such as restoring from available backups. Outcomes depend on factors like the condition of backups, the extent of the encryption, and the environment itself, so we can't guarantee that every system or file can be recovered. Decisions about ransom demands involve legal, insurance, and regulatory considerations and should be made with your legal counsel and insurance provider.
04Can you determine how an attacker got in?
We work to identify how an incident likely began and progressed by reviewing available evidence such as logs, endpoint data, account activity, and system configurations. How conclusive that analysis can be depends on what evidence exists and how well it was preserved. Sometimes the initial access point can be identified with confidence; other times findings are limited to the most likely explanation. When specialized digital forensics is needed, additional forensic specialists may need to be involved.
05Can you help recover our systems?
Yes. Recovery support may include restoring systems from available backups, rebuilding affected devices, resetting credentials, validating that restored systems work correctly, and monitoring for signs of continued compromise. What can be recovered depends on the condition of backups and the nature of the incident, so recovery is planned carefully and prioritized around your most critical operations.
06Should we contact law enforcement?
It may be appropriate, depending on the nature of the incident. In the United States, organizations often report cyber incidents to agencies such as the FBI, including through its Internet Crime Complaint Center (IC3), or to CISA. Whether and when to contact law enforcement is a decision best made with your legal counsel. OneGuard IT does not provide legal advice, but we can help document technical information that may be useful to your counsel and to investigators.
07Will you work with our cyber insurance provider?
We can coordinate with your insurance provider and the parties they involve, and help supply technical information about the incident when requested. Policies vary, and some require specific vendors, notification steps, or approvals before response work begins. We recommend contacting your insurer early and reviewing your policy with your broker or legal counsel. OneGuard IT can't interpret your coverage or guarantee that any cost will be covered.
08What information should we preserve during an incident?
When possible, preserve anything that could help explain what happened: suspicious emails, ransom notes or on-screen messages (photos are helpful), system and security logs, a list of affected devices and accounts, and notes on what was observed, when, and by whom. Avoid wiping, reimaging, or restoring affected systems until evidence preservation has been discussed with your response team. Your legal counsel can advise whether specific preservation or notification obligations apply to your organization.
09Can you help prevent another incident?
Yes. After an incident, OneGuard IT can help prioritize improvements based on what was learned, such as strengthening identity and access controls, endpoint protection, network segmentation, backups, logging, and monitoring. Organizations that want a deeper evaluation can also engage Alpha Group, OneGuard IT's offensive security division, for an authorized security assessment. No set of controls eliminates risk entirely, but targeted improvements can reduce the likelihood and impact of future incidents.
Incident Response
Something Happened.Let's Get Control Back.
If your organization is dealing with a suspected cybersecurity incident, contact OneGuard IT to discuss the situation and determine the appropriate next steps.
A OneGuard IT specialist will follow up to discuss the situation