Stop the breach. Limit the damage. Get back to business.
AMATAS helps you take control from the first critical hours – identifying the attack, containing the threat, determining its impact, and guiding your business through recovery.
Experiencing an incident right now?
Service options
Retainer or on-demand - be ready either way
Always-ready response
A standing agreement that guarantees priority access to AMATAS incident responders – with defined SLAs, pre-agreed scope, and a team that already knows your environment.
- Guaranteed response SLA – hours, not days
- Pre-authorized rules of engagement
- Environment onboarding & documentation upfront
- Annual tabletop exercise included
When an incident strikes
No retainer required – contact us when you need us. Our team responds as rapidly as possible, triages the situation, and deploys the right expertise for the incident type.
- Emergency contact line
- Rapid remote triage within hours
- On-site deployment where required
- Incident-scoped engagement
- Post-incident review included
How we respond
Full incident lifecycle - from first call to lessons learned
Initiation
Incident reported. Preliminary assessment completed and response objectives defined – with recommendations delivered within one hour of notification.
Triage
Incident classified by severity and business impact. IR team assigned and immediate response actions confirmed with your team.
Containment
Affected systems isolated and attacker access cut off – stopping the spread before eradication begins, with daily status reports throughout.
Eradication
Attacker tools, persistence mechanisms, and backdoors fully removed – ensuring the threat is eliminated before recovery begins.
Investigation
Forensic data acquisition and deep-dive analysis to determine root cause, full scope of compromise, and attacker timeline – with a final forensic report delivered.
Improvement
IR Playbook updated, lessons learned documented, awareness training and tabletop exercise delivered – and a remediation roadmap to prevent recurrence.
Who it's for
Incident response is essential for
Financial institutions
DORA requires documented incident response capability and rapid notification to regulators – a retainer satisfies both.
Critical infrastructure
NIS2 mandates incident reporting within 24 hours – a retainer ensures you have the expertise to respond and report in time.
Any organization without a dedicated IR team
Most organizations don’t have the in-house expertise to handle a serious incident alone – AMATAS fills that gap immediately.
Compliance support
Incident response aligned to regulatory requirements
DORA, NIS2, and GDPR all impose strict incident notification timelines. Our IR process produces the forensic evidence and documentation your legal and compliance teams need to meet those deadlines.
- DORA
- NIS2
- ISO 27001
- GDPR Art. 33
- PCI DSS
- HIPAA
FAQ
Incident response - common questions
Retainer clients have guaranteed response SLAs with remote triage beginning within hours. On-demand clients receive priority response as quickly as available capacity allows – typically within hours for remote triage. On-site deployment timelines depend on location and logistics, and are agreed as part of the initial triage call.
A retainer gives you guaranteed priority access, pre-agreed rules of engagement, and a team that has already been onboarded to your environment – dramatically reducing response time and friction during an incident. On-demand response is available without a prior agreement but comes without guaranteed SLAs or pre-onboarding. For organizations in regulated sectors or those with critical operational dependencies, a retainer is strongly recommended.
Our IR process provides the forensic evidence and scope determination your legal and compliance teams need to assess notification requirements and meet deadlines under GDPR (72 hours), NIS2 (24/72 hours), and DORA. We work alongside your legal counsel throughout the incident, providing the technical facts needed to support notification decisions, but not legal advice directly. Incident documentation can also be provided if agreed upon additionally as part of the engagement.
IR retainer clients receive proactive support including environment onboarding, incident response plan review, and an annual tabletop exercise. For organizations that want to build readiness without a full retainer, our Adversary Simulation services – particularly purple teaming – are the most effective way to test and improve your detection and response capability before a real incident occurs.
Don't wait for an incident to find out you're unprepared.
Talk to our team about an IR retainer – or ask about on-demand response availability.
Services that work alongside incident response

Managed XDR (MXDR)
24/7 threat detection and response that identifies incidents earlier – reducing the scope and cost of response.

Red Teaming
Test your detection and response capability before a real incident – so your team is ready when it matters.
Virtual CISO (vCISO)
Strategic security leadership to build and govern your incident response program over the long term.
Subscribe to our insights
Sign up to receive cyber news and updates