Security Managed Service: Incident Response — Incident Investigation & Recovery Guidance
Security Managed Service: Incident Response is a monthly subscription service for companies that have experienced or suspect an information security incident, including unauthorized employee access, disclosure of confidential information, viral activity, suspected crypto miner activity, employee-account spamming, or malicious software on the company website. IT Partner specialists analyze the company infrastructure and event logs, interview users if necessary, and provide a report on the incident with recommendations to help prevent recurrence.
What this engagement is
This service helps a company investigate a defined information security incident. IT Partner specialists analyze the client infrastructure, including servers, workstations, and network hardware, review logs for suspicious activity, interview users if necessary, and provide a report with information obtained about the incident and recommendations to improve safety and prevent recurrence. The service can be ordered after incidents such as unauthorized employee access to information, disclosure of confidential information to third parties, viral activity such as data encryption or blocked system functions or data, crypto miner detection or suspicion of its existence, spamming on behalf of employees, or malicious software on the company website. This service is provided as a monthly subscription.
Success criteria
What you receive
How the work unfolds
Kickoff meeting.
Client provides the necessary information about the incident(s).
Data analysis by IT Partner specialists.
Making a report and providing it to the client.
Prerequisites
Who does what
IT Partner
- Client infrastructure analysis (servers, workstations, network hardware) to detect vulnerabilities
- Server, workstation, and network hardware log analysis to detect traces of suspicious activity
- Providing a report based on the results of work and giving recommendations to improve safety and prevent the same incidents from recurring
Your team
- Provide necessary information about existing hardware, servers, and workstations
- Provide a dedicated point of contact responsible for working with IT Partner
- Coordinate any outside vendor resources and schedules
What's not included
Limitations & technical notes
Frequently asked questions
What is Security Managed Service: Incident Response?
Security Managed Service: Incident Response is an IT Partner monthly subscription service for companies that have experienced or suspect an information security incident. IT Partner specialists analyze the company infrastructure and event logs, interview users if necessary, and provide a report with findings and recommendations to help prevent recurrence.
What types of security incidents can this service investigate?
This service can be ordered for incidents such as unauthorized employee access to information, disclosure of confidential information to third parties, viral activity, suspected data encryption or blocked systems, suspected crypto miner activity, spamming from employee accounts, or malicious software on the company website. It is designed for a defined incident or suspected incident, because the deliverable is a report about what was found in that case.
What is included in the Incident Response service?
The service includes analysis of the client infrastructure, including servers, workstations, and network hardware, to identify vulnerabilities or suspicious activity related to the incident. IT Partner also reviews relevant logs, may interview users if necessary, and prepares a report with incident information and safety recommendations. The included outcome is investigation and guidance, not full implementation of all recommended changes.
What is not included in this Incident Response service?
This service does not include purchasing licenses for products, setting up products or services that are not required for incident investigation, or implementing products and solutions proposed in the final report. Those activities are outside the stated scope because the service is focused on analyzing the incident and delivering findings and recommendations.
How long does the Incident Response service take?
The plan may vary depending on the client’s needs and the information available, so any scheduling details should be confirmed with IT Partner during kickoff.
How much does the Incident Response service cost?
It is described as a monthly subscription service, so buyers should confirm billing details and any renewal terms with IT Partner before ordering.
What deliverables will we receive at the end of the service?
The deliverable is a report based on the results of IT Partner’s work. The report contains information obtained about the incident and recommendations to improve safety and reduce the chance of the same type of incident recurring.
What are the success criteria for this service?
The service is considered successful when the client receives a report containing information obtained about the incident and recommendations on how to prevent it from recurring. The success criteria focus on investigation findings and recommendations, not on guaranteed eradication, remediation, or legal conclusions.
What happens during the engagement?
The engagement starts with a kickoff meeting, followed by the client providing necessary information about the incident or incidents. IT Partner specialists then analyze the data, infrastructure, and logs, and finally prepare and provide the report to the client.
Does IT Partner analyze our servers, workstations, and network hardware?
Yes. IT Partner’s responsibilities include analyzing client infrastructure such as servers, workstations, and network hardware to detect vulnerabilities, as well as reviewing logs from those systems to identify traces of suspicious activity.
Will IT Partner review security logs as part of the incident response?
Yes. Log analysis for servers, workstations, and network hardware is part of IT Partner’s stated responsibility, because suspicious activity often leaves traces in system and infrastructure logs. The value of the review depends on the logs and incident information the client can provide.
Will IT Partner interview our users or employees?
IT Partner may interview users if necessary as part of understanding the incident. Interviews are not described as mandatory for every case, because the service scope says they are performed when needed.
What does the client need to provide before or during the service?
There are no formal prerequisites listed for this service. However, the client is responsible for providing necessary information about existing hardware, servers, and workstations, assigning a dedicated point of contact, and coordinating any outside vendor resources and schedules.
Who is responsible for coordinating third-party vendors during the investigation?
The client is responsible for coordinating outside vendor resources and schedules. This matters because IT Partner can analyze the client environment and logs, but access to third-party systems or vendor-managed infrastructure may require the client’s coordination.
Will this service cause downtime or interrupt business operations?
The service description does not specify planned downtime, and the stated work is investigative analysis of infrastructure, logs, and incident information. Any possible business impact depends on the environment, access method, and incident conditions, so downtime or operational constraints should be confirmed with IT Partner during kickoff.
Does the service include removing malware, stopping a crypto miner, or restoring encrypted data?
The stated scope is incident investigation, analysis, reporting, and recommendations. Malware removal, crypto miner eradication, data restoration, or implementation of proposed solutions is not explicitly included, so those activities should be treated as separate unless IT Partner confirms they are required for investigation and within scope.
Can this service help if an employee account is sending spam?
Yes. Spamming on behalf of employees is one of the incident examples listed for this service. IT Partner can investigate relevant infrastructure and logs and provide findings and recommendations to help prevent recurrence.
Can this service help if our website has malicious software?
Yes. Malicious software on the company website is one of the listed situations where the service can be ordered. The engagement focuses on analyzing the incident and providing a report with recommendations, not necessarily implementing website cleanup or new security products.
What happens after we receive the incident report?
After completion, the client receives the report with incident information and recommendations to improve safety and prevent similar incidents. Implementing products, services, or solutions proposed in the report is not included in this service, so follow-up remediation should be planned separately if needed.