AnySec
All services
Response·varies (rapid response)

Incident Response

Active breach? We respond within 30 minutes.

Rapid-response cybersecurity engagement for active or suspected incidents. We contain, eradicate, and recover — then run a forensic post-mortem so it doesn't happen twice. 30-minute response SLA when retained in advance.

All sectors
From€3,500/ per incident

ROE signed before any work · 30 minutes response

30 min
Response SLA on retainer
24/7
Year-round availability
Regulator-ready
Reports drafted for EU + US frameworks

Scope of work

What's included

Everything below is delivered by senior engineers — no scanner-only reports, no junior hand-offs.

  • 30-minute response time when on retainer
  • Immediate triage and containment
  • Eradication of attacker presence
  • Forensic timeline reconstruction
  • Recovery validation and hardening recommendations
  • Post-incident report for regulators and stakeholders

Methodology

How we run it

  1. 01Triage: classify severity and contain spread
  2. 02Eradicate attacker presence and persistence
  3. 03Recover affected systems with hardened baselines
  4. 04Forensic analysis with full attacker timeline
  5. 05Post-incident hardening to prevent recurrence

Comparison

IR retainer vs cold call.

FeatureAnySecGeneric firmDIY
Response time30 min on retainer4–24 hours typicalHours to days
Pre-engagement contextWe know your stack alreadyStart from zeroYour team in firefight mode
Regulator-ready reportingIncludedAdd-onYour responsibility
AnySec was on a Zoom with our SOC 23 minutes after our pager fired. Within 90 minutes the attacker had no live foothold. Game-changing.

Director of Security · European fintech (Series C)

Deliverables

What you receive

  • Forensic timeline with attacker actions
  • Containment and recovery documentation
  • Hardening recommendations
  • Regulator-ready incident report

Our commitments

Skin in the game.

  • 30-minute SLA on retainer — refunded if missed
  • Direct senior engineer on every escalation, no triage queue
  • Regulator-ready report within 5 business days of containment

FAQ

Questions we get asked

Can we retain you in advance?+

Yes — and you should. Advance retainers get the 30-minute SLA. Cold engagements still get rapid response but no formal SLA.

Do you coordinate with law enforcement?+

If you direct us to. We never contact law enforcement without your authorization.

What counts as an incident worth calling you for?+

Ransomware or suspected ransomware, a confirmed intrusion, data exfiltration, suspicious privileged-account activity, or a DDoS beyond your provider's capacity. Call early — a false alarm costs far less than a foothold that spreads while you deliberate.

Do you help with GDPR or NIS2 breach notification?+

Yes. We produce a regulator-ready incident report and help you meet notification timelines, including the GDPR 72-hour window and NIS2 reporting obligations for in-scope entities.

What do you need from us to start?+

A point of contact, access to the affected systems, and a signed engagement. On a retainer we collect all of this in advance, which is what makes the 30-minute SLA real — a cold engagement spends its first hour just getting oriented.

Response · IR-RAPID

Ready to start Incident Response?

Buy the engagement to lock your slot, or book a free 30-minute call to scope it first. 30 minutes response either way.

ROE signed before any test fires · varies (rapid response)

Incident Response
€3,500 · per incident