Incident-Response Support When Something Has Already Gone Wrong
A written plan for what to do when a security incident happens, plus hands-on support during an active one, for businesses without an internal team. GullySystem prepares the plan and stands alongside you when it is needed.
What Incident-Response Support Covers
This covers two related things: preparing a written plan naming who does what before anything happens, and hands-on support during and after an actual incident — a suspicious login, a data leak, unusual activity that suggests something has been accessed it should not have.
What Happens Without a Plan
- A suspicious login is spotted and nobody knows who should be called or what should be shut down first
- Hours are lost deciding what to do while an incident is actively ongoing
- A data leak needs to be described to customers or a regulator, and nobody can yet say what was actually taken
- Different people take conflicting actions because no one was clearly in charge of the response
Preparation and Active Response
A Written Response Plan
Steps, roles and contacts defined in advance, so a response does not start from a blank page.
Containment
Help stopping ongoing access or spread once an incident is identified.
Investigation
Working out what happened, what was accessed, and how it occurred.
Recovery and Communication Support
Help restoring affected systems and drafting what needs to be communicated to customers, partners or a regulator.
What Support Looks Like in Practice
Support can be arranged as an on-call retainer for businesses that want a response plan and a number to call ready before anything happens, or engaged directly once an incident is already under way. Either way, the shape of the work is the same: contain, investigate, recover, and communicate what happened.
Who Needs This in Place
- Businesses without an internal security team who would otherwise have nobody to call
- Companies holding customer data that would need to be notified if it were exposed
- Any business currently in the middle of a suspected incident and needing support right now
Frequently asked questions
Can you help if something has already happened right now?
Yes. Incident-response support can be engaged directly once an incident is under way, without a pre-existing retainer, though a business that already has a plan and named contacts in place is able to move into containment faster than one starting cold.
How quickly can you respond?
Response depends on how the support is arranged and how serious the incident is — a retainer with an agreed escalation path moves faster into action than a one-off engagement set up after the fact. We do not promise a fixed response time up front; how urgency is handled is set out clearly during scoping.
What determines what this costs?
Whether the arrangement is an ongoing retainer or a one-off engagement, and the scale and severity of what is being handled. A single suspicious login investigated and closed costs far less than a multi-system incident needing containment, investigation and customer communication together.
Do we need a written plan before you can help us?
No. A plan makes any future response faster and clearer, but support can be provided during an active incident even where no plan exists yet — building one afterwards is often part of what follows.
Do you help with notifying customers or a regulator?
We help draft what needs to be communicated and work out what was actually affected, so your business can meet its own notification obligations with an accurate account. The decision of what to say and to whom remains yours.
Who owns the investigation findings and any records produced?
You do. Everything produced during an incident — findings, timelines, communication drafts — belongs to your business and stays available to you afterwards, including for any regulator or insurer that later asks for it.
What do you need from us to get started?
For preparation, a list of your key systems and the people who should be contacted during an incident. For an active incident, immediate access to the affected systems, a clear point of contact on your side, and whatever you already know about what triggered the concern.
Tell us what you need.
Send a short brief and one of our engineers will come back to you — usually the same day.
- No obligation
- We reply the same working day
- Your details stay private