OneGuard IT // Incident Response

Incident Response // Ready

When Every Minute Matters,Regain Control.

Cyber incidents create confusion quickly. OneGuard IT helps organizations assess what happened, contain the threat, protect critical systems, and begin the path toward recovery.

Incident Status

Design visualization

State
Active
Priority
High
Current Phase
Detection
Environment
Under assessment
Response Workflow
Active
Service
Incident Response
Objective
Regain Control
Approach
Contain // Recover
Output
Documented Findings

IR-01 //First Response

Stop the SituationFrom Getting Worse.

During a cybersecurity incident, the first objective is understanding the scope of the event while limiting additional damage.
  1. 01

    01 // UNDERSTAND

    Determine what systems, users, identities, or infrastructure may be affected.

  2. 02

    02 // CONTAIN

    Take appropriate steps to limit the threat and reduce additional exposure.

  3. 03

    03 // STABILIZE

    Protect critical operations while preparing the environment for recovery.

IR-02 //Incident Types

When Something Goes Wrong,We Help Find the Path Forward.

10 incident classifications

  • ENDPOINTIR-01

    Ransomware

    Encrypted systems, ransom demands, and disrupted operations that call for calm, structured decisions.

  • ENDPOINTIR-02

    Malware

    Malicious software on workstations or servers that needs to be identified, contained, and removed.

  • IDENTITYIR-03

    Compromised Accounts

    Stolen credentials or unauthorized sign-ins that expose email, files, and connected systems.

  • EMAILIR-04

    Business Email Compromise

    Mailbox takeover, fraudulent payment requests, or impersonation aimed at your people and partners.

  • ACCESSIR-05

    Unauthorized Access

    Someone reached systems or data they shouldn't have, and the scope needs to be understood.

  • DATAIR-06

    Data Exposure

    Sensitive information that may have been accessed, copied, or made available without authorization.

  • NETWORKIR-07

    Network Intrusion

    Suspicious traffic or activity suggesting an unauthorized party is operating inside the network.

  • DEVICEIR-08

    Lost or Compromised Devices

    Missing laptops or phones, or devices that may have been tampered with or accessed.

  • SIGNALIR-09

    Suspicious Activity

    Unusual alerts, sign-ins, or behavior that should be investigated before it becomes something larger.

  • CONTROLSIR-10

    Security Control Failure

    Backups, firewalls, or other protections that didn't work as expected when they were needed.

Every incident is different. Response actions and outcomes depend on the environment, available evidence, and the nature of the event.

IR-03 //Response Sequence

From Incident to Recovery.

A structured response keeps decisions deliberate when pressure is high. Each stage builds on what the previous one established.
  1. 01 // TRIAGE

    Establish what is known, identify immediate risks, and determine the initial response priorities.

    Known facts // Immediate risks // Initial priorities

  2. 02 // ASSESS

    Evaluate affected systems, accounts, devices, infrastructure, and available evidence to understand the scope of the incident.

    Systems & accounts // Devices // Available evidence

  3. 03 // CONTAIN

    Take appropriate steps to isolate affected resources and limit additional damage while preserving business operations where possible.

    Isolation // Exposure reduction // Business continuity

  4. 04 // INVESTIGATE

    Analyze available evidence to understand what occurred, how the incident progressed, and what may have been affected.

    Evidence review // Progression // Potential impact

  5. 05 // ERADICATE

    Remove identified malicious artifacts, compromised access, or other persistent threats where appropriate.

    Malicious artifacts // Compromised access // Persistence

  6. 06 // RECOVER

    Restore systems and services carefully, validate functionality, and monitor for signs of continued compromise.

    Restoration // Validation // Monitoring

  7. 07 // STRENGTHEN

    Document lessons learned and prioritize improvements that can reduce the likelihood or impact of a similar incident.

    Lessons learned // Improvements // Documentation

IR-04 //Containment

Contain the Threat.Protect the Business.

Containment is a balance. Isolating too little can let a threat spread; isolating too much can stop the business. Response decisions weigh security against business continuity, so healthy systems keep running wherever it's safe to do so.

Stage 01 // DETECT

A compromised resource is identified and its connections to the rest of the environment are mapped.

Isolation isn't automatic. Each containment action is a deliberate decision based on the environment, the potential business impact, and the evidence available at the time.

Containment Map

Illustrative

  • INTERNETOperational
  • FIREWALLOperational
  • CORE NETWORKOperational
  • IDENTITYOperational
  • SERVERSOperational
  • ENDPOINTSCOMPROMISED
  • CLOUDOperational

IR-05 //Incident Analysis

Understand What Happened.

Clear decisions depend on clear information. Evidence from identities, endpoints, network activity, and security tools is correlated into a single, reviewable picture of the incident.

Case Workspace // Analysis View

Illustrative incident data

Evidence sources

  • TIMELINE
  • IDENTITIES
  • ENDPOINTS
  • NETWORK ACTIVITY
  • SECURITY EVENTS
  • AFFECTED SYSTEMS
  • INDICATORS

Event timeline

Sample case

  1. Suspicious authentication activity identified

    IDENTITYLogged

  2. Endpoint behavior correlated

    ENDPOINTLogged

  3. Affected resource isolated

    CONTAINMENTLogged

  4. Containment validation underway

    VALIDATIONIn progress

Signals

  • IDENTITIES

    2 accounts under review

  • ENDPOINTS

    1 device isolated

  • NETWORK ACTIVITY

    Outbound traffic reviewed

  • SECURITY EVENTS

    Alerts correlated to one case

  • AFFECTED SYSTEMS

    Scope: 1 segment

  • INDICATORS

    3 indicators documented

Fictional example for illustration only. Not customer data and not a live system.

IR-06 //Recovery

Getting Back Online Is OnlyPart of the Job.

Recovery is deliberate. Systems are restored carefully, validated, and watched closely, because returning too quickly to a still-compromised environment can restart the incident.
  1. STABILIZE

    Confirm the threat is contained and the environment is steady.

  2. VALIDATE

    Verify systems, accounts, and backups are trustworthy before restoring.

  3. RESTORE

    Bring services back carefully, in business-priority order.

  4. MONITOR

    Watch for signs of continued or renewed compromise.

  5. IMPROVE

    Apply what was learned to reduce future risk.

What recovery may include

Every recovery plan is shaped by the incident and the environment. Work is prioritized around the systems your business depends on most.

What can be restored depends on factors such as the condition of backups and the nature of the incident. Not every system or piece of data can always be recovered, which is why recovery options are evaluated early and communicated plainly.

  • System restoration
  • Credential resets
  • Access-control changes
  • Security configuration changes
  • Endpoint validation
  • Network validation
  • Monitoring
  • Documentation
  • Remediation planning

IR-07 //After the Incident

Turn an Incident Intoa Stronger Environment.

The end of the emergency is the start of the improvement work. What was learned during response becomes a practical plan.
  • Output // 01

    Root Cause & Timeline

    Help establish what happened and how the incident developed based on available evidence.

  • Output // 02

    Remediation Roadmap

    Prioritize weaknesses and corrective actions discovered during response.

  • Output // 03

    Security Improvements

    Identify opportunities to strengthen identity, endpoint, network, backup, monitoring, and other defensive controls.

  • Output // 04

    Documentation

    Provide useful documentation of findings, actions, and recommended next steps.

From Response to Resilience

What Happens After the Emergency?

Once the immediate incident has been addressed, organizations may choose to validate the broader environment and identify additional weaknesses. Alpha Group, OneGuard IT's offensive security division, offers authorized post-incident security assessments as an optional next step.

Explore Alpha Group

Separate, optional engagement // Authorized scope only

IR-08 //Before the Incident

The Best Time to PrepareIs Before Something Happens.

Preparation shortens confusion when it matters most. Not dealing with an incident right now? This is the best time to strengthen the foundations a response depends on.
  • Incident Response Planning

    Define roles, contacts, decision points, and communication steps before they're needed.

  • Backup & Recovery Review

    Confirm backups are protected, current, and can actually be restored.

  • Identity Security

    Strengthen multi-factor authentication, privileged access, and account hygiene.

  • Endpoint Protection

    Make sure devices are protected, managed, and monitored consistently.

  • Network Segmentation

    Limit how far a threat can move if a single system is compromised.

  • Logging & Monitoring

    Keep the visibility needed to detect incidents and understand them later.

  • Security Assessments

    Identify and prioritize weaknesses before someone else finds them.

IR-09 //FAQ

Incident Response Questions.

Every incident is different. These answers are general guidance, not legal advice; your legal counsel and insurance provider may need to be involved depending on the circumstances.
01What should we do first if we suspect a cyber incident?

Avoid making large changes before the situation is understood. Write down what was observed and when, don't delete suspicious emails, files, or logs, and limit use of systems that appear affected. Contact your IT or security provider as early as possible and notify internal leadership according to your policies. If you carry cyber insurance, review your policy early, since many insurers have specific notification requirements. The right first steps depend on what is happening in your environment, so it helps to talk through the situation before taking broad action.

02Should we disconnect affected computers from the network?

Isolating an affected device can help limit spread, but how it's done matters. Disconnecting network access, such as unplugging the network cable or turning off Wi-Fi, is generally preferable to powering a device off, because shutting down can erase information in memory that may help an investigation. In some environments, isolating a system can also disrupt critical operations. If you're unsure, contact OneGuard IT to discuss the situation before disconnecting systems broadly.

03Can OneGuard IT respond to ransomware?

Yes. OneGuard IT helps organizations respond to ransomware by assessing the scope of the event, helping contain further spread, and evaluating recovery options such as restoring from available backups. Outcomes depend on factors like the condition of backups, the extent of the encryption, and the environment itself, so we can't guarantee that every system or file can be recovered. Decisions about ransom demands involve legal, insurance, and regulatory considerations and should be made with your legal counsel and insurance provider.

04Can you determine how an attacker got in?

We work to identify how an incident likely began and progressed by reviewing available evidence such as logs, endpoint data, account activity, and system configurations. How conclusive that analysis can be depends on what evidence exists and how well it was preserved. Sometimes the initial access point can be identified with confidence; other times findings are limited to the most likely explanation. When specialized digital forensics is needed, additional forensic specialists may need to be involved.

05Can you help recover our systems?

Yes. Recovery support may include restoring systems from available backups, rebuilding affected devices, resetting credentials, validating that restored systems work correctly, and monitoring for signs of continued compromise. What can be recovered depends on the condition of backups and the nature of the incident, so recovery is planned carefully and prioritized around your most critical operations.

06Should we contact law enforcement?

It may be appropriate, depending on the nature of the incident. In the United States, organizations often report cyber incidents to agencies such as the FBI, including through its Internet Crime Complaint Center (IC3), or to CISA. Whether and when to contact law enforcement is a decision best made with your legal counsel. OneGuard IT does not provide legal advice, but we can help document technical information that may be useful to your counsel and to investigators.

07Will you work with our cyber insurance provider?

We can coordinate with your insurance provider and the parties they involve, and help supply technical information about the incident when requested. Policies vary, and some require specific vendors, notification steps, or approvals before response work begins. We recommend contacting your insurer early and reviewing your policy with your broker or legal counsel. OneGuard IT can't interpret your coverage or guarantee that any cost will be covered.

08What information should we preserve during an incident?

When possible, preserve anything that could help explain what happened: suspicious emails, ransom notes or on-screen messages (photos are helpful), system and security logs, a list of affected devices and accounts, and notes on what was observed, when, and by whom. Avoid wiping, reimaging, or restoring affected systems until evidence preservation has been discussed with your response team. Your legal counsel can advise whether specific preservation or notification obligations apply to your organization.

09Can you help prevent another incident?

Yes. After an incident, OneGuard IT can help prioritize improvements based on what was learned, such as strengthening identity and access controls, endpoint protection, network segmentation, backups, logging, and monitoring. Organizations that want a deeper evaluation can also engage Alpha Group, OneGuard IT's offensive security division, for an authorized security assessment. No set of controls eliminates risk entirely, but targeted improvements can reduce the likelihood and impact of future incidents.

Incident Response

Something Happened.Let's Get Control Back.

If your organization is dealing with a suspected cybersecurity incident, contact OneGuard IT to discuss the situation and determine the appropriate next steps.

A OneGuard IT specialist will follow up to discuss the situation