Skip to content
Home / Services / Incident Response
IR 24/7 · Every minute counts

Incident Response & Digital Forensics

When a breach occurs, every minute counts. 24/7 SOC under NIST SP 800-61 and digital forensics with chain of custody for court — integrated on a single page.

Overview

Berghem's response program covers the entire incident cycle — from preparation with playbooks and tabletops, to containment in hours via 24/7 SOC, to forensic investigation that reconstructs the kill chain and produces a signed expert report for court. All under NIST SP 800-61 and ISO/IEC 27037.

Every action is logged, every decision is documented, and every artifact preserves chain of custody. We close with post-incident review, playbook updates, and indicators of compromise ready to feed your SIEM, EDR, and internal threat intel — closing the cycle in a way that reduces detection and containment time for the next event.

Everything included

24/7 SOC with rotating on-call
NIST SP 800-61 cycle (6 phases)
Containment within 4 hours
Forensic disk and memory acquisition
Malware reverse engineering
Chain of custody ISO/IEC 27037
Expert report signed by judicial expert
Module 01 · NIST SP 800-61

Incident Response

Six phases executed by a 24/7 SOC — from preparation to post-incident. Every minute is logged, every decision is documented, and every action preserves chain of custody.

Phase 01 · Playbook

Preparation

Response plan, team training, and tabletop exercises to ensure readiness before the incident — scenario-specific and business-area playbooks.

Phase 02 · SIEM · EDR

Detection & Analysis

Rapid identification and classification via SIEM, EDR, and threat intel — multi-source correlation to separate noise from real compromise and prioritize response.

Phase 03 · Isolation

Containment

Host isolation, credential revocation, and blast radius limitation — all while preserving evidence for subsequent forensics and audit.

Phase 04 · Cleanup

Eradication

Complete threat removal from the environment and closure of exploited attack vectors — focused hardening and integrity validation of compromised systems.

Phase 05 · Restoration

Recovery

Assisted restoration with enhanced monitoring to detect adversary return attempts — point-to-point validation before resuming normal operations.

Phase 06 · Post-mortem

Lessons Learned

Post-incident report, root cause analysis, and corrective actions — closing the cycle with playbook, control, and indicator updates that reduce the time of the next event.

Module 02 · ISO/IEC 27037

Digital Forensics

Investigation that withstands cross-examination: forensic acquisition, timeline reconstruction, and expert report signed by judicial expert. Six capabilities with auditable chain of custody.

Image · RAM · Artifacts

Disk & Memory

Write-blocked bit-by-bit images, volatile RAM capture, NTFS/EXT4 artifact analysis, and process dumps — the technical foundation of any serious forensic investigation.

PCAP · NetFlow · C2

Network Traffic

PCAP capture, NetFlow, session reconstruction, IOC extraction, and command-and-control server identification — recovering the complete history of adversarial communication.

Sandbox · MITRE ATT&CK

Malware & Reverse Engineering

Static and dynamic analysis in sandbox, unpacking, deobfuscation, and TTP mapping against MITRE ATT&CK — deep understanding of what the adversary actually did in the environment.

SIEM · EDR · IdP · Cloud

Logs & Timeline

Log correlation from SIEM, EDR, IdP, and cloud to reconstruct the kill chain minute by minute — from initial access to exfiltration, with court-admissible evidence.

ISO/IEC 27037 · SHA-256

Chain of Custody

ISO/IEC 27037 procedures with SHA-256 hashing, digital seals, and auditable trail of every piece of evidence — from collection to court presentation.

Report · Expertise · Court

Judicial Expert & Report

Signed expert report, technical court assistance, and specialized testimony — investigation that withstands cross-examination and supports legal accountability.

Frequently Asked Questions

What is Berghem's incident response time?
Berghem offers tiered incident response with defined SLAs. Critical incidents receive initial response within 1 hour, with an analyst engaged within 4 hours. High-severity incidents receive response within 4 hours with analyst engagement within 8 hours. Response times apply 24/7 for critical tier subscribers and during business hours for standard tier. All engagements begin with rapid triage to determine scope, impact, and containment priorities.
Does Berghem provide digital forensics?
Yes. Berghem's digital forensics capabilities include disk and memory forensics, network traffic analysis, malware reverse engineering, timeline reconstruction, and evidence preservation following chain-of-custody procedures suitable for legal proceedings. Our forensic investigators use industry-standard tools and methodologies to ensure findings are defensible and actionable. Forensic analysis can be performed on-site or remotely depending on the incident requirements.
Can Berghem handle ransomware incidents?
Yes. Berghem provides comprehensive ransomware incident response including immediate containment to prevent lateral spread, forensic analysis to determine the attack vector and scope of encryption, negotiation advisory services, recovery planning, and post-incident hardening. We help organizations evaluate their options objectively — including backup restoration, decryption possibilities, and business continuity activation — while preserving evidence for potential law enforcement engagement.
What happens after an incident is resolved?
After containment and recovery, Berghem conducts a thorough post-incident review including root cause analysis, timeline documentation, detection gap assessment, and response effectiveness evaluation. We deliver a comprehensive incident report with lessons learned and a strategic remediation roadmap to prevent recurrence. This includes updated playbooks, improved detection rules, and recommendations for security architecture improvements identified during the incident investigation.

Active incident?

If you are facing a security incident right now, contact us immediately to activate 24/7 emergency response.

Contact emergency response