When it's real, the clock is already running. So are we.

The difference between a contained event and a reportable breach is measured in minutes. When something's wrong, you need a responder who already knows your environment and can move through containment, eradication and recovery without relearning your network from scratch, not a ticket dropped into a queue. Here's what you can hold us to.

Three numbers, put in writing SLA
A responder is already moving through the timeline
15 min
Triage Response & Acknowledgement
A responder is on the line, assessing scope.
1 hr
Active engagement
Containment underway, isolating what's affected and protecting what isn't.
4 hr
Full team mobilized
Investigation, recovery and evidence capture running in parallel.
Our SLA for active IR retainer clients
Our incident response commitment

Three numbers, put in writing.

How fast does Cyberwall actually respond to an incident?

Cyberwall commits to a 15-minute triage response and acknowledgement, active engagement and containment within 1 hour, and a fully mobilized response team within 4 hours of any confirmed incident. These aren't targets we aim for: they're the commitment behind every engagement.

15 min
Triage Response & Acknowledgement
A responder is on the line, assessing scope.
1 hr
Active engagement
Containment underway, isolating what's affected and protecting what isn't.
4 hr
Full team mobilized
Investigation, recovery and evidence capture running in parallel.

Every action is logged to a chain of custody standard your carrier and counsel can rely on, so recovery and the insurance claim move forward together, not one after the other.

What's included

From "something's wrong" to "we're back", covered end to end.

01Phase 01

Containment & eradication

We isolate what's affected, cut off attacker access, and remove the threat from your environment, stopping the bleeding before anything else. That includes segmenting or quarantining affected hosts, disabling compromised accounts, and rotating credentials and access keys an attacker may have touched, so the door is actually shut, not just the alarm silenced. Where it helps scope the intrusion, we map observed attacker behavior against the MITRE ATT&CK framework's known tactics and techniques rather than treating each indicator in isolation.

02Phase 02

Forensic investigation

We determine how the incident happened, what was accessed, and how far it spread: the answers your board, your carrier and your counsel will all ask for. That means capturing volatile memory, log, and disk evidence before it's overwritten, preserving it under a documented chain of custody, and reconstructing the timeline from initial access through to whatever it touched last. From there we draw a clear line between what was actually exposed and what was merely at risk, a distinction that matters for both your breach notification obligations and your claim.

03Phase 03

Recovery & documentation

We support getting systems back online safely, and every action taken is documented to a standard your insurance claim and post incident report can rely on. Systems are rebuilt or restored from known-clean backups and validated before they're reconnected, rather than assumed clean because the alert stopped firing, and the written report we leave behind is built to stand on its own, in front of your board, your regulator, or your insurer, without needing us in the room to explain it.

What SOC 2 expects from incident response

A SOC 2 Type II report doesn't just ask if you have a plan. It asks if you can prove it holds up.

SOC 2 Type II is an evaluation of how your controls actually perform over an audit period, not a one-time checklist, which is what separates it from a Type I report and why it carries more weight with clients, auditors and carriers alike. Under the security-related Trust Services Criteria, an auditor isn't satisfied by a policy document sitting in a shared drive. They're looking for evidence, sampled across the audit window, that when something goes wrong, your organization can identify it, respond to it, and recover from it in a way that's consistent, timely, and defensible after the fact.

In plain terms, that generally means an organization needs to show:

01A documented incident response plan that's actually been reviewed and exercised, not written once and shelved.
02Defined roles and escalation paths, so it's clear who owns a decision the moment an incident is declared, not sorted out mid-crisis.
03Logging and monitoring sufficient to detect an incident in a reasonable timeframe, and evidence retention long enough to support a later review.
04A response that happens on a timeline, not whenever someone gets to it, since "eventually" isn't an acceptable answer to an auditor or a regulator.
05A post-incident review that feeds back into the control environment, so the same gap doesn't reopen the next time.

This is exactly what our engagement is built around, not a separate compliance exercise bolted onto the response. The 15-minute triage / 1-hour active engagement / 4-hour full mobilization commitment above is that "response on a timeline" requirement, in writing. The chain-of-custody standard behind every action we log is the evidence retention requirement. And direct coordination with your carrier and counsel during the response, not after, means the post-incident report is already built to the standard your own auditor, your board, and your insurer will each independently expect to see. If your organization is already SOC 2 certified, or working toward it, an engagement built this way is one less gap for your next audit to find.

"An auditor isn't asking whether you'll have an incident. They're asking whether you can prove, with evidence, that someone owned it, the clock started, and the response holds up under review."
  • A documented, exercised plan with clear ownership and escalation
  • Detection and response measured against a stated timeline
  • Evidence retained to a standard your own auditor can rely on
Working with your cyber insurance

Built to support the claim, not just survive the incident.

Our documentation and chain of custody standards, covering how evidence is captured, hashed, and handled from the moment it's collected, are designed so that when your carrier and counsel review a claim, the evidence is already there and defensible.

"During the response itself, we're already talking to your carrier and counsel, not waiting for a claim to be filed before the documentation exists."
  • Incident evidence captured to a claim ready standard
  • Direct coordination with broker, carrier and breach counsel
  • A written report your board can actually read
From the blog
Works with

Pairs naturally with these.

Already in an incident? Don't wait for the form.

Call us and a responder picks up. Not in one right now? Book a preparedness call so a containment plan already exists before you need it.

Under attack? · 24/7
1-888-471-5400

Call us and a responder picks up.