What is incident response?
Incident response is the set of actions to manage an attack or breach: detect, contain, notify, recover and learn.
The difference between a scare and a disaster is often decided in the first hours. Acting methodically —not in a panic— limits the damage, the cost and the legal exposure.
Mandatory notification: a formality you can't get wrong
When there's a breach or a significant incident, the law requires you to notify the authority on time: 72 hours to the data protection authority if personal data is at risk, and 24- and 72-hour alerts for operators covered by NIS2.
It isn't complicated, but it can't go wrong: late or badly drafted, the notification makes your situation worse instead of protecting you.
This is included in your Plan Tria. We manage the notification: we assess whether it applies, prepare the content and send it on time. It's a formality and we handle it, at no extra cost.
When you need to go further
Some incidents aren't solved with a notice. That's where the add-on services come in:
- Incident investigation (forensics): what happened, how they got in, how far they reached and what they took.
- Expert support during the attack: specialist technical support in the heat of the moment, through our technical partner.
- OSINT: what information about you is out there and what has leaked.
- Legal support: if the incident leads to proceedings, with lawyers who specialise in cybersecurity.
Before the incident: be prepared
The best time to prepare your response is before it happens. Without a plan, you improvise; and you improvise badly.
- Response plan with roles and decisions.
- Key contacts and an alert chain.
- Tested backups for restoration.
- A drill so the real day isn't the first time.
How we act
- Activation and triage. We confirm the scope.
- Containment. We stop the spread.
- Timely notification to whoever applies — included in your plan.
- Recovery. Back to normal.
- Forensic investigation and expert support, if the incident requires it (add-on).
- Post-incident report and improvements.
With Plan Tria, when it happens, you don't improvise. The plan is in place, roles are clear, backups are tested — and the mandatory notification is covered. Response starts in minutes, not in meetings.
Frequently asked questions
What do I do in the first hours of an incident?
Don't shut down or delete things in a panic: isolate what's affected, alert who needs to know and call us. Preserving the information is key for forensics.
Is notifying the authority included?
Yes. Managing the mandatory notification is part of Plan Tria: we assess whether it applies, prepare it and send it on time.
What about forensic investigation?
That's an add-on. When you need to know exactly what happened and how far they got, we run the investigation, with support from our technical partner if the attack demands it.
Should I pay a ransomware ransom?
Not advised: it guarantees neither getting your data back nor that they won't return. We help you weigh options and recover without giving in to extortion wherever possible.