Incident Response
When the breach happens, the worst time to find a security team is that morning.
Our incident response retainer means that when ransomware, a data leak or an account takeover hits, a team that already knows your environment answers within a guaranteed SLA — with forensics, containment, and regulator-reporting support ready to go.
What's covered
Before, during, and after the incident.
Before — Readiness
Environment onboarding, contact tree, response playbook tailored to your stack, and an annual tabletop drill so the first real incident isn't the first rehearsal.
During — Response
Guaranteed-SLA engagement, containment and eradication, digital forensics with chain-of-custody, ransomware assessment, and communication support for management.
After — Recovery
Root-cause analysis, CERT-In and sector-regulator reporting support, hardening of the exploited path, and a board-ready post-incident report.
Retainer structure
Pay a little for the guarantee, not a lot in the panic.
Retainers start at ₹60,000/year for business-hours SLA coverage, with extended-hours tiers for regulated and high-availability businesses. The annual fee covers onboarding, the playbook, the drill and the guarantee; incident hours are billed at pre-agreed rates — typically well below the emergency rates non-retainer clients pay. Unused readiness hours can be applied to security reviews.
We deliberately cap the number of retainer clients per coverage tier so the SLA we sign is an SLA we can honour. If a tier is full, we'll tell you and waitlist you honestly.
The 6-hour clock is real
CERT-In directions require reporting covered cyber incidents within six hours of noticing them, and sector regulators add their own timelines. Most organisations discover these clocks during their first incident — with a retainer, the reporting formats, facts and evidence flow are prepared in advance.
Talk through coverage →Related
Fraud involving crypto?
Ransom payments, drained wallets and crypto-routed fraud leave a public trail. Our blockchain forensics team traces it and builds the evidence your case needs.
Crypto Fraud Investigation →