Bristol, Gloucestershire, Wiltshire, Somerset, Dorset, Devon, Cornwall and the South West
MULTI AWARD WINNING IT SUPPORT, SOLUTIONS AND SERVICES
Cyber Incident.
Response.
"I would have no hesitation in recommending Soltech.”
Janie Tucker, Managing Director, Waste-Disposer Warehouse
SME
Cyber Incident Response
Corporate
Cyber Incident Response
Charity
Cyber Incident Response
Public Sector
Cyber Incident Response
When a Cyber Attack Happens, Every Minute Matters
A cyber attack can happen to any organisation.
It could begin with a phishing email, compromised Microsoft 365 account, stolen credentials, ransomware or an exploited vulnerability.
When something goes wrong, knowing who to call and what to do next can make a significant difference.
Soltech IT Ltd provides Cyber Incident Response to help businesses identify what has happened, contain the threat, investigate the incident and safely restore normal operations.
If you think you've been hacked, don't wait.
Contact Soltech IT as soon as possible.
What Is Cyber Incident Response?
Cyber Incident Response is the structured process of dealing with a cyber security incident.
Our approach can include:
Detect → Contain → Investigate → Remediate → Recover → Improve
The response depends on the nature, severity and potential impact of the incident.
The priority is to prevent the situation from getting worse while establishing what has happened.
What Types of Cyber Incidents Can We Help With?
Ransomware
Files or systems have been encrypted and your business can no longer access critical information.
We can help investigate the incident, contain the threat and establish the safest recovery options.
Microsoft 365 Account Compromise
An attacker has obtained an employee's or administrator's credentials.
Phishing Attacks
An employee has clicked a suspicious link or entered their credentials into a fake website.
We can assess the potential exposure and take appropriate steps to secure the affected account and wider environment.
Malware Infection
A computer or server is behaving suspiciously or has been identified as infected.
We can investigate the device, isolate it where appropriate and determine whether the threat has spread.
Business Email Compromise
A criminal has gained access to an email account and is using it to impersonate the business.
This can include attempts to:
- Redirect payments
- Change bank details
- Intercept invoices
- Impersonate directors
- Target customers or suppliers
We can help secure the affected environment and investigate the technical aspects of the compromise.
Data Breach
A cyber incident may result in personal, financial or confidential information being accessed or disclosed.
We can help establish:
- What happened
- Which systems were affected
- Which accounts were involved
- What information may have been accessed
- What technical evidence is available
Where specialist legal, regulatory or forensic advice is required, we can work alongside your chosen advisers.
What To Do If You Think You've Been Hacked
If you suspect an active cyber attack:
1. Don't Panic
Avoid making unnecessary changes that could destroy useful evidence.
2. Contact Your IT or Cyber Security Provider
The sooner the incident is assessed, the more opportunity there may be to contain it.
3. Don't Delete Evidence
Emails, logs, files and devices may contain important information about what happened.
4. Don't Assume It's Isolated
A compromised computer or account may be part of a wider attack.
5. Follow Your Incident Response Plan
If you have one, activate it immediately.
Our Cyber Incident Response Process
1. Immediate Assessment
We establish what is known and determine whether an active threat may still be present.
Questions can include:
- What happened?
- When did it start?
- Which systems are affected?
- Is the attacker still present?
- Is data at risk?
2. Containment
The priority is to stop the attack spreading.
Depending on the circumstances, this may include:
- Isolating devices
- Disabling compromised accounts
- Revoking sessions
- Blocking malicious connections
- Restricting access
- Stopping suspicious processes
3. Investigation
We investigate available evidence to understand the incident.
This can include:
- Security alerts
- Microsoft 365 activity
- Sign-in logs
- Endpoint activity
- Network activity
- System logs
- Malware
- Suspicious processes
4. Determine the Scope
An important question is:
How far has the attacker got?
We identify potentially affected:
- Users
- Computers
- Servers
- Microsoft 365 accounts
- Cloud services
- Applications
- Data
5. Remediation
Once the source and scope of the incident are understood, remediation can begin.
This may include:
- Removing malware
- Resetting passwords
- Revoking sessions
- Removing malicious accounts
- Removing persistence mechanisms
- Patching vulnerabilities
- Reconfiguring security controls
6. Recovery
We help restore normal business operations safely.
This may involve:
- Restoring systems
- Recovering data
- Rebuilding devices
- Restoring Microsoft 365 access
- Recovering from backups
- Validating systems before reconnecting them
7. Post-Incident Review
Once the immediate incident has been resolved, we can identify how the attack happened and what needs to change.
This could lead to recommendations around:
- MFA
- EDR
- MDR
- Email Security
- Cyber Essentials
- Vulnerability Management
- Security Awareness Training
- Microsoft 365 Security
- Backup protection
The objective isn't simply to recover from today's incident.
It's to make the next attack harder to succeed.
Ransomware Incident Response
Ransomware can bring a business to a standstill.
An attack may prevent access to:
- Files
- Servers
- Applications
- Databases
- Shared drives
- Business systems
Our response focuses on containment, investigation and recovery.
Where secure backups are available, we can help assess whether systems can be restored without relying on the attacker.
Never assume that paying a ransom is the best option.
The appropriate response depends on the circumstances, available recovery options, legal considerations and other factors.
Microsoft 365 Incident Response
Cloud account compromise is increasingly common.
If an attacker gains access to a Microsoft 365 account, we can investigate areas such as:
- Suspicious sign-ins
- Impossible or unusual travel indicators
- MFA activity
- Mailbox rules
- Email forwarding
- Application permissions
- Administrator changes
- SharePoint and OneDrive access
We can then help secure the environment and determine whether the compromise has spread.
Business Email Compromise & Payment Fraud
A compromised mailbox can allow criminals to monitor conversations and identify upcoming payments.
For example:
Account compromised → Attacker monitors emails → Payment identified → Supplier impersonated → Bank details changed → Payment redirected
If you suspect this has happened, speed matters.
We can help secure the affected IT environment while you take the appropriate financial, legal and regulatory steps.
Digital Forensics
Some incidents require a deeper technical investigation.
Digital forensic analysis can help establish:
- How the attacker gained access
- What they did
- Which accounts were compromised
- Which systems were accessed
- Whether malware was installed
- Whether data may have been stolen
- Whether the attacker may still have access
The appropriate level of forensic investigation depends on the circumstances and potential impact.
Data Breach Support
A cyber incident may involve personal data.
Depending on the circumstances, your organisation may have obligations under data protection legislation and potentially other regulatory requirements.
We can help establish the technical facts required to support your assessment, including:
- What happened
- Which systems were affected
- Which accounts were compromised
- What information may have been accessed
- What evidence is available
Where legal or regulatory advice is required, we recommend involving your appropriate specialist advisers.
Incident Response Planning
The best time to prepare for a cyber attack is before it happens.
Soltech IT can help you develop an Incident Response Plan covering:
- Who should be contacted
- Who makes decisions
- How systems should be isolated
- Internal communications
- Customer communications
- Cyber insurance requirements
- Backup recovery
- External specialists
- Legal and regulatory contacts
- Recovery procedures
When an incident occurs, you don't want to be working out what to do for the first time.
Discover the right certification for your business.
Explore Cyber Essentials and Cyber Essentials Plus.
Test Your Incident Response Plan
A plan that has never been tested may not work as expected.
We can help test your response to scenarios such as:
- Ransomware
- Microsoft 365 compromise
- Data breach
- Server failure
- Phishing attack
- Lost or compromised credentials
Testing can identify gaps in:
- Decision-making
- Communication
- Technical recovery
- Backups
- Staff awareness
Cyber Incident Response & MDR
Incident response works particularly well alongside Managed Detection & Response.
MDR helps detect suspicious activity.
Incident Response helps deal with the incident when a significant threat is identified.
Together:
Detect → Investigate → Contain → Remediate → Recover
Cyber Incident Response & Backup
Secure backups can be critical during a ransomware incident.
However, attackers increasingly target backup systems themselves.
That's why backup security should include:
- Appropriate access controls
- MFA
- Separation
- Retention
- Monitoring
- Immutable or isolated copies where appropriate
- Regular recovery testing
Soltech IT can help assess your backup and recovery strategy.
Speak to Soltech IT about your businesses Cyber Security needs
Contact Us
Why Choose Soltech IT?
When your business is under attack, you need people who understand both technology and your business environment.
Soltech IT combines IT infrastructure expertise with cyber security services including:
- Cyber Incident Response
- Managed Detection & Response
- Managed Security Operations
- Managed Security Risk
- Endpoint Detection & Response
- Microsoft 365 Security
- Email Security
- Cyber Essentials
- Cyber Essentials Plus
- Penetration Testing
- Cyber Security Auditing
- Vulnerability Management
- Phishing Simulation
- Security Awareness Training
- Dark Web Monitoring
- Backup & Disaster Recovery
This means we can help move from containment through to recovery, rather than simply identifying the problem.
Frequently Asked Questions
What should I do if I think we've been hacked?
Contact your IT or cyber security provider immediately. Avoid deleting evidence or making unnecessary changes before the incident has been assessed.
Can Soltech IT help with ransomware?
Yes. We can assist with containment, investigation and recovery, including assessing available backups and helping restore affected systems.
Can you recover a compromised Microsoft 365 account?
Yes. We can help secure compromised accounts, revoke sessions, investigate suspicious activity and review the wider Microsoft 365 environment.
Do you provide forensic investigation?
Depending on the incident and the investigation required, we can provide technical investigation and work with specialist forensic partners where a deeper forensic investigation is appropriate.
Do you provide 24/7 incident response?
Response arrangements depend on the service agreement and level of support required. We can discuss appropriate out-of-hours arrangements for your organisation.
If You've Been Hacked, Act Quickly
A cyber attack is stressful, but the wrong response can make the situation worse.
The priority is to:
Contain the threat. Understand what happened. Protect your business. Recover safely.
Think you've been hacked?
Contact Soltech IT Ltd as soon as possible.
Our Cyber Incident Response team can help you understand what has happened and determine the appropriate next steps.

Meet the team
Gareth Jones
Sales Director
Gareth has worked within the IT industry for most of his working life., with serval years experience managing SME, educational and corporate client accounts.
Drawing on his wide-ranging experience, Gareth leads the sales, marketing and account management aspect of the business with a primary focus upon meeting the required customer service and customer expectations.

































