Bristol, Gloucestershire, Wiltshire, Somerset, Dorset, Devon, Cornwall and the South West


MULTI AWARD WINNING IT SUPPORT, SOLUTIONS AND SERVICES

Cyber Incident.

Response.

"I would have no hesitation in recommending Soltech.”

Janie Tucker, Managing Director, Waste-Disposer Warehouse

SME

Cyber Incident Response

Corporate

Cyber Incident Response

Charity

Cyber Incident Response

Public Sector

Cyber Incident Response

When a Cyber Attack Happens, Every Minute Matters


A cyber attack can happen to any organisation.


It could begin with a phishing email, compromised Microsoft 365 account, stolen credentials, ransomware or an exploited vulnerability.


When something goes wrong, knowing who to call and what to do next can make a significant difference.


Soltech IT Ltd provides Cyber Incident Response to help businesses identify what has happened, contain the threat, investigate the incident and safely restore normal operations.


If you think you've been hacked, don't wait.

Contact Soltech IT as soon as possible.


What Is Cyber Incident Response?


Cyber Incident Response is the structured process of dealing with a cyber security incident.

Our approach can include:


Detect → Contain → Investigate → Remediate → Recover → Improve


The response depends on the nature, severity and potential impact of the incident.


The priority is to prevent the situation from getting worse while establishing what has happened.


What Types of Cyber Incidents Can We Help With?


Ransomware


Files or systems have been encrypted and your business can no longer access critical information.


We can help investigate the incident, contain the threat and establish the safest recovery options.


Microsoft 365 Account Compromise


An attacker has obtained an employee's or administrator's credentials.

What Information Can Be Exposed?


We can help:


  • Secure the account
  • Reset credentials
  • Revoke active sessions
  • Review MFA
  • Investigate sign-in activity
  • Check for malicious mailbox rules
  • Identify potential further compromise

Phishing Attacks


An employee has clicked a suspicious link or entered their credentials into a fake website.


We can assess the potential exposure and take appropriate steps to secure the affected account and wider environment.


Malware Infection


A computer or server is behaving suspiciously or has been identified as infected.


We can investigate the device, isolate it where appropriate and determine whether the threat has spread.


Business Email Compromise


A criminal has gained access to an email account and is using it to impersonate the business.


This can include attempts to:


  • Redirect payments
  • Change bank details
  • Intercept invoices
  • Impersonate directors
  • Target customers or suppliers


We can help secure the affected environment and investigate the technical aspects of the compromise.


Data Breach


A cyber incident may result in personal, financial or confidential information being accessed or disclosed.


We can help establish:


  • What happened
  • Which systems were affected
  • Which accounts were involved
  • What information may have been accessed
  • What technical evidence is available


Where specialist legal, regulatory or forensic advice is required, we can work alongside your chosen advisers.


What To Do If You Think You've Been Hacked


If you suspect an active cyber attack:


1. Don't Panic

Avoid making unnecessary changes that could destroy useful evidence.


2. Contact Your IT or Cyber Security Provider

The sooner the incident is assessed, the more opportunity there may be to contain it.


3. Don't Delete Evidence

Emails, logs, files and devices may contain important information about what happened.


4. Don't Assume It's Isolated

A compromised computer or account may be part of a wider attack.


5. Follow Your Incident Response Plan

If you have one, activate it immediately.


Our Cyber Incident Response Process


1. Immediate Assessment


We establish what is known and determine whether an active threat may still be present.


Questions can include:


  • What happened?
  • When did it start?
  • Which systems are affected?
  • Is the attacker still present?
  • Is data at risk?


2. Containment


The priority is to stop the attack spreading.


Depending on the circumstances, this may include:


  • Isolating devices
  • Disabling compromised accounts
  • Revoking sessions
  • Blocking malicious connections
  • Restricting access
  • Stopping suspicious processes


3. Investigation


We investigate available evidence to understand the incident.


This can include:


  • Security alerts
  • Microsoft 365 activity
  • Sign-in logs
  • Endpoint activity
  • Email
  • Network activity
  • System logs
  • Malware
  • Suspicious processes


4. Determine the Scope


An important question is:


How far has the attacker got?


We identify potentially affected:


  • Users
  • Computers
  • Servers
  • Microsoft 365 accounts
  • Cloud services
  • Applications
  • Data


5. Remediation


Once the source and scope of the incident are understood, remediation can begin.


This may include:


  • Removing malware
  • Resetting passwords
  • Revoking sessions
  • Removing malicious accounts
  • Removing persistence mechanisms
  • Patching vulnerabilities
  • Reconfiguring security controls


6. Recovery


We help restore normal business operations safely.


This may involve:


  • Restoring systems
  • Recovering data
  • Rebuilding devices
  • Restoring Microsoft 365 access
  • Recovering from backups
  • Validating systems before reconnecting them


7. Post-Incident Review


Once the immediate incident has been resolved, we can identify how the attack happened and what needs to change.


This could lead to recommendations around:


  • MFA
  • EDR
  • MDR
  • Email Security
  • Cyber Essentials
  • Vulnerability Management
  • Security Awareness Training
  • Microsoft 365 Security
  • Backup protection


The objective isn't simply to recover from today's incident.


It's to make the next attack harder to succeed.


Ransomware Incident Response


Ransomware can bring a business to a standstill.


An attack may prevent access to:


  • Files
  • Servers
  • Applications
  • Databases
  • Shared drives
  • Business systems


Our response focuses on containment, investigation and recovery.


Where secure backups are available, we can help assess whether systems can be restored without relying on the attacker.


Never assume that paying a ransom is the best option.


The appropriate response depends on the circumstances, available recovery options, legal considerations and other factors.


Microsoft 365 Incident Response


Cloud account compromise is increasingly common.


If an attacker gains access to a Microsoft 365 account, we can investigate areas such as:


  • Suspicious sign-ins
  • Impossible or unusual travel indicators
  • MFA activity
  • Mailbox rules
  • Email forwarding
  • Application permissions
  • Administrator changes
  • SharePoint and OneDrive access


We can then help secure the environment and determine whether the compromise has spread.


Business Email Compromise & Payment Fraud


A compromised mailbox can allow criminals to monitor conversations and identify upcoming payments.


For example:


Account compromised → Attacker monitors emails → Payment identified → Supplier impersonated → Bank details changed → Payment redirected


If you suspect this has happened, speed matters.


We can help secure the affected IT environment while you take the appropriate financial, legal and regulatory steps.


Digital Forensics


Some incidents require a deeper technical investigation.


Digital forensic analysis can help establish:


  • How the attacker gained access
  • What they did
  • Which accounts were compromised
  • Which systems were accessed
  • Whether malware was installed
  • Whether data may have been stolen
  • Whether the attacker may still have access


The appropriate level of forensic investigation depends on the circumstances and potential impact.


Data Breach Support


A cyber incident may involve personal data.


Depending on the circumstances, your organisation may have obligations under data protection legislation and potentially other regulatory requirements.


We can help establish the technical facts required to support your assessment, including:


  • What happened
  • Which systems were affected
  • Which accounts were compromised
  • What information may have been accessed
  • What evidence is available


Where legal or regulatory advice is required, we recommend involving your appropriate specialist advisers.


Incident Response Planning


The best time to prepare for a cyber attack is before it happens.


Soltech IT can help you develop an Incident Response Plan covering:


  • Who should be contacted
  • Who makes decisions
  • How systems should be isolated
  • Internal communications
  • Customer communications
  • Cyber insurance requirements
  • Backup recovery
  • External specialists
  • Legal and regulatory contacts
  • Recovery procedures


When an incident occurs, you don't want to be working out what to do for the first time.



Discover the right certification for your business.

Explore Cyber Essentials and Cyber Essentials Plus.


Cyber Essentials Cyber Essentials Plus

Test Your Incident Response Plan


A plan that has never been tested may not work as expected.


We can help test your response to scenarios such as:


  • Ransomware
  • Microsoft 365 compromise
  • Data breach
  • Server failure
  • Phishing attack
  • Lost or compromised credentials


Testing can identify gaps in:


  • Decision-making
  • Communication
  • Technical recovery
  • Backups
  • Staff awareness


Cyber Incident Response & MDR


Incident response works particularly well alongside Managed Detection & Response.


MDR helps detect suspicious activity.


Incident Response helps deal with the incident when a significant threat is identified.


Together:


Detect → Investigate → Contain → Remediate → Recover


Cyber Incident Response & Backup


Secure backups can be critical during a ransomware incident.


However, attackers increasingly target backup systems themselves.


That's why backup security should include:


  • Appropriate access controls
  • MFA
  • Separation
  • Retention
  • Monitoring
  • Immutable or isolated copies where appropriate
  • Regular recovery testing



Soltech IT can help assess your backup and recovery strategy.

Speak to Soltech IT about your businesses Cyber Security needs


Contact Us

Why Choose Soltech IT?


When your business is under attack, you need people who understand both technology and your business environment.


Soltech IT combines IT infrastructure expertise with cyber security services including:


  • Cyber Incident Response
  • Managed Detection & Response
  • Managed Security Operations
  • Managed Security Risk
  • Endpoint Detection & Response
  • Microsoft 365 Security
  • Email Security
  • Cyber Essentials
  • Cyber Essentials Plus
  • Penetration Testing
  • Cyber Security Auditing
  • Vulnerability Management
  • Phishing Simulation
  • Security Awareness Training
  • Dark Web Monitoring
  • Backup & Disaster Recovery


This means we can help move from containment through to recovery, rather than simply identifying the problem.


Frequently Asked Questions


What should I do if I think we've been hacked?

Contact your IT or cyber security provider immediately. Avoid deleting evidence or making unnecessary changes before the incident has been assessed.


Can Soltech IT help with ransomware?

Yes. We can assist with containment, investigation and recovery, including assessing available backups and helping restore affected systems.


Can you recover a compromised Microsoft 365 account?

Yes. We can help secure compromised accounts, revoke sessions, investigate suspicious activity and review the wider Microsoft 365 environment.


Do you provide forensic investigation?

Depending on the incident and the investigation required, we can provide technical investigation and work with specialist forensic partners where a deeper forensic investigation is appropriate.


Do you provide 24/7 incident response?

Response arrangements depend on the service agreement and level of support required. We can discuss appropriate out-of-hours arrangements for your organisation.


If You've Been Hacked, Act Quickly

A cyber attack is stressful, but the wrong response can make the situation worse.


The priority is to:


Contain the threat. Understand what happened. Protect your business. Recover safely.


Think you've been hacked?


Contact Soltech IT Ltd as soon as possible.



Our Cyber Incident Response team can help you understand what has happened and determine the appropriate next steps.

Speak to Soltech IT about your businesses Cyber Security needs

Our IT Consultants and Account Managers are always happy to help

Meet the team

Gareth Jones

Sales Director


Gareth has worked within the IT industry for most of his working life., with serval years experience managing SME, educational and corporate client accounts.


Drawing on his wide-ranging experience, Gareth leads the sales, marketing and account management aspect of the business with a primary focus upon meeting the required customer service and customer expectations.