Cyber Incident Response
Under attack? Our UK incident response team is on standby.
When ransomware hits or you suspect a breach, every minute matters. Our UK SOC contains the threat, investigates the root cause and gets you back to business — with clear reporting for insurers and regulators.
Delivered by the cyber security specialists at Fresh Mango Technologies.

What it is
Cyber Incident Response, explained plainly.
Cyber incident response is the rapid, expert-led process of detecting, containing, investigating and recovering from an active cyber attack. We provide on-call response retainers and emergency engagement for SMEs across the UK, BVI and USA facing ransomware, account compromise, data exfiltration or active intrusions.
Why it matters
The business risk if you don't act.
Most SMEs are not equipped to handle a live cyber incident. The decisions made in the first hour — isolation, evidence preservation, communications — often determine whether you recover in days or weeks.
Average ransomware recovery for an unprepared SME exceeds 20 working days
Evidence destroyed in the first hour can invalidate insurance claims
ICO breach notification has a strict 72-hour window
Re-infection rates are high without proper root-cause remediation
What's included
Everything you need, in one service.
- 24/7 UK incident response hotline
- Rapid threat containment and isolation
- Forensic investigation and evidence preservation
- Ransomware negotiation guidance (where appropriate)
- Recovery, rebuild and environment hardening
- Insurer and ICO-ready incident report
How it works
A simple, proven process.
- 1
Triage
Call our 24/7 UK line. A senior responder is engaged within minutes to assess scope and impact.
- 2
Contain
We isolate affected systems, revoke compromised credentials and stop the attack spreading.
- 3
Investigate
Forensic analysis identifies the root cause, scope of compromise and any data exfiltration.
- 4
Recover
We rebuild and harden your environment, then deliver a full report for insurers and regulators.
Who it's for
Built for SMEs in the UK, BVI & USA.
Any SME across the UK, BVI and USA without an in-house security team — either on a proactive retainer or in an emergency. Particularly critical for businesses with cyber insurance or regulated data.
- Businesses currently experiencing a suspected breach
- SMEs that want a 24/7 retainer so someone answers if the worst happens
- Companies with cyber insurance requiring an IR provider
- Any business handling regulated or client-sensitive data
Investment
Retainer from £250 / month · Emergency response available
Proactive retainers guarantee 24/7 access to our UK incident response team at a known price. Emergency engagements are charged at our standard incident rate.
FAQ
Common questions about Cyber Incident Response.
What is cyber incident response?
+
Cyber incident response is the rapid, expert-led process of detecting, containing, investigating and recovering from an active cyber attack such as ransomware, account compromise or data exfiltration. We provide both on-call retainers and emergency engagement for SMEs across the UK, BVI and USA when something has already gone wrong. The priority order is always the same: stop the attacker’s access, preserve evidence, restore operations, then establish how they got in so it cannot happen again. We also handle the parts businesses forget under pressure, including ICO notification, insurer and legal liaison, and clear communication with staff and customers.
How does incident response work if we're hit right now?
+
Call our 24/7 UK line and a senior responder engages within minutes to assess scope and impact. We isolate affected systems and revoke compromised credentials to stop the attack spreading, run a forensic investigation to identify root cause and any data exfiltration, then rebuild and harden your environment and deliver a full report for insurers and regulators.
Why should we have an incident response provider in place before something happens?
+
The decisions made in the first hour of an incident — isolation, evidence preservation, communications — often determine whether you recover in days or weeks, and evidence destroyed early can invalidate insurance claims. A pre-agreed retainer means someone answers immediately and follows a proven playbook, rather than you scrambling to find help mid-crisis.
What does incident response cost?
+
Proactive retainers start from around £250 per month and guarantee 24/7 access to our UK team at a known, capped price. Emergency engagements without a retainer are charged at our standard incident rate, quoted transparently once we understand the scope of the incident. A retainer also includes an annual review of your environment and an agreed response plan, which materially shortens response time because we are not learning your systems during the incident. For most SMEs the retainer costs less than a day of emergency response.
How long does incident response take?
+
Initial triage begins within minutes of your call, containment is typically achieved within hours, and full investigation and recovery can range from a few days for a contained incident to several weeks for widespread ransomware, depending on backup quality and the scale of the environment affected. The single biggest factor in how long recovery takes is whether you have tested, offline backups. Businesses that do are usually operational within days; those relying on backups that turn out to be encrypted or incomplete face a far longer and more expensive recovery.
Is this only for large organisations, or do SMEs need it too?
+
SMEs need it more, in many ways, because they rarely have an in-house team able to respond to a live incident. Average ransomware recovery for an unprepared SME exceeds 20 working days without expert support, so having a response plan matters just as much for smaller businesses as for large ones.
How does having a retainer compare with calling for help only in an emergency?
+
Retainer clients get guaranteed response SLAs, capped rates and pre-agreed playbooks, which matter enormously when minutes count. Emergency-only engagement still gets you expert help, but without the SLA guarantees, pre-agreed access, or the faster start that comes from us already knowing your environment. In practice, retained clients tend to contain incidents in hours rather than days, because access, contacts and escalation routes are already agreed. A retainer is also increasingly something cyber insurers look for, and can help at renewal.
Should we ever pay a ransom?
+
Almost always no. Paying doesn't guarantee data recovery or that stolen data won't be leaked anyway, and it can mark you as a target for repeat attacks. We focus on recovering from backups and hardening your environment so the same attack can't succeed twice. Payment may also carry legal and sanctions implications depending on who the attacker is. Our role is to give you an honest assessment of your recovery options, the realistic timescales for each, and the evidence you need for your insurer, so the decision is a commercial one made with the facts rather than under pure panic.
Before you buy
Costs, risks and misconceptions.
The questions buyers actually ask about Cyber Incident Response — what it costs to budget for, what happens if you do nothing, and the assumptions that most often turn out to be wrong.
How does the cost of a retainer compare with paying during an incident?
+
A retainer is a predictable annual fee that buys a guaranteed response time and an agreed team. Emergency engagement without one is charged at incident rates, and you also pay in delay: scoping, contracting and access provisioning while the attacker is still active. The dominant cost in either case is not the responder's fee, it is downtime, so the arrangement that gets containment started fastest is normally the cheaper one overall.
What actually goes wrong in the first hours if there is no plan?
+
Predictable, damaging things. Staff turn machines off, destroying the memory evidence needed to understand what happened. Nobody knows who is allowed to authorise disconnecting systems. Backup credentials turn out to be stored in the compromised environment. Clients and staff hear about it informally before there is a considered message. Most of the avoidable damage in an incident comes from these first-hour decisions, not from the malware itself.
Isn't incident response just restoring from backup?
+
Restoring is one step and often not the first. Before you restore you have to establish how the attacker entered and whether they still hold access, or you restore straight into a compromised environment and are encrypted again. You also need to know what data was taken, which drives your legal notification obligations, and that question cannot be answered from a backup. Response covers containment, investigation, recovery and the regulatory position.
Will our cyber insurance cover this, and can we use our own responder?
+
Most policies cover incident response costs, but many also require you to use a panel provider and to notify the insurer before engaging anyone, or the costs may not be reimbursed. Check that clause before an incident, not during one. We are happy to work alongside an insurer's appointed team, and if your policy restricts who can be engaged we will tell you rather than starting work you cannot claim for.
Do we have to report an incident, and who do we tell?
+
Under UK GDPR a personal-data breach that poses a risk to individuals must be reported to the ICO within 72 hours of becoming aware, and affected individuals told where the risk is high. Regulated sectors and BVI-based entities carry additional obligations, and contracts frequently require client notification within a stated period. We help you establish what happened factually so those decisions are made on evidence, but the reporting decision remains yours and we recommend legal input on it.
What do we need to have in place before an incident for this to work?
+
A short list, agreed in advance: who declares an incident, who can authorise systems being taken offline, an out-of-band way to communicate if email is compromised, and an offline copy of key contacts and account details. Add tested backups you have actually restored from. Setting this up takes a couple of hours in calm conditions and is the difference between a coordinated response and an improvised one.
Explore related cyber security services
Most SMEs combine cyber incident response with a wider set of managed controls. Here's where to look next.
Next step
Cyber Shield — ongoing protection
Monthly subscription that keeps your team cyber-aware all year. 14-day free trial, cancel anytime.
Cyber Essentials (CE Accreditation)
Get certified, win tenders and lower your insurance.
EDR / MDR
Endpoint detection and managed response that stops ransomware before it spreads.
Start here
Book a free cyber security review
30 minutes with a UK specialist — a plain-English view of your risks and next steps.
Related case studies
All case studiesUnderstand the concepts behind Cyber Incident Response
Plain-English reference pages in our Knowledge Centre that explain the terms used on this page.
Where we deliver Cyber Incident Response
We support SMEs across Yorkshire, the wider UK, the British Virgin Islands and the US. These pages cover the areas where we work on site.
Who delivers this work
Complete Cyber Security is part of Fresh Mango Technologies, with offices in the UK and BVI.
Two ways to get started
Not sure what you need? Speak to us. Want ongoing protection? Try it free.
Book a free 30-minute Cyber Security Review with our UK team, or start a 14-day free trial of Cyber Shield and see the difference for yourself.

