شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

Detect & respond

Incident responseStructured containment, documented analysis, evidence-based recovery

We lead the incident from detection to closure with a response team working to an approved plan, and leave you with preserved evidence and written lessons.

At a glance

Frameworks

  • NCA ECC
  • SAMA CSF
  • PDPL
  • ISO 27001
  • ISO 22301

Deliverables

  • Approved incident response plan
  • Playbooks for at least five scenarios
  • Regulator notification templates
  • Final incident report with timeline and root cause
  • Tabletop exercise report

The challenge

The NCA Essential Cybersecurity Controls (ECC) require a documented incident management and reporting plan, and the SAMA Cyber Security Framework (CSF) expects incidents to be classified and reported within defined windows. The Personal Data Protection Law (PDPL) adds a duty to notify the regulator and affected individuals when personal data is breached.

The first hours of an incident decide the damage: disconnect the server or watch it? Reboot and lose the evidence? Who briefs management and the regulator? Without a rehearsed plan these decisions are improvised.

We give you a ready response team with a written plan, procedures for each scenario and defined communication channels, so an incident is a managed event rather than a crisis.

How we work

  1. 1

    Preparation

    We review or write the response plan, define roles, contacts and notification templates for NCA, SAMA and SDAIA, and pre-stage evidence-collection tooling.

  2. 2

    Containment and analysis

    When an incident occurs we classify it, contain its spread, collect evidence from hosts, logs and SIEM such as Splunk, and establish the timeline, entry point and affected scope.

  3. 3

    Recovery and lessons

    We plan restoration with your teams, verify complete eradication, and hand over a final report with root causes, recommendations and a lessons-learned session.

What is included

  • Incident response plan

    An approved plan covering classification, escalation, roles and communication, aligned with ECC, SAMA CSF and ISO 27001.

  • Scenario playbooks

    Written procedures for ransomware, business email compromise, data exfiltration, compromised accounts and insider threats.

  • Digital forensics

    Memory and disk acquisition, chain-of-custody preservation and artefact analysis to establish what happened, when and how.

  • Malware analysis

    Sample analysis to extract indicators of compromise and push them to your detection tooling.

  • Regulatory notification

    Templates and paths for notifying NCA, SAMA and SDAIA according to the nature of the incident and the data affected.

  • Tabletop exercises

    Simulation sessions for management and technical teams on illustrative real-world scenarios, with a report on gaps found in the plan.

  • SOC coordination

    Direct integration with our managed SOC and MDR service, so an incident moves from detection to response without hand-off gaps.

  • Retainer option

    A standing arrangement that keeps the team ready and familiar with your environment before any incident occurs.

Frameworks and regulations

We align the service with the frameworks your organisation is subject to.

  • NCA ECC
  • SAMA CSF
  • PDPL
  • ISO 27001
  • ISO 22301

Frequently asked questions

Can we engage you during an active incident without a prior contract?

Yes. We start with an urgent scoping session and then agree the work plan. A retainer shortens contracting and environment familiarisation.

Do you notify regulators on our behalf?

Notification remains your legal responsibility. We prepare the content, evidence and timeline, and support you in the communication where needed.

Does this cover personal data incidents?

Yes. We establish whether personal data was affected and document it in a way that serves PDPL requirements.

What do we receive at the end of an incident?

A final report with timeline, root cause, impact and recommendations, the preserved evidence, and an update to the plan and playbooks based on lessons learned.

How quickly can your team respond to an incident?

Response terms, including how you reach the team, availability and escalation paths, are agreed in the contract, usually as part of a retainer, based on your environment and locations. We do not publish generic response times because they depend on what is agreed with each client. Without a prior agreement, we start with a scoping session and agree the engagement terms then.

What affects the cost of incident response?

For an active incident, the main drivers are the number of systems and locations affected, how deep the forensic work must go, whether malware analysis is needed, and how much recovery support you want from us. For a retainer, cost depends on the size of your environment, the response terms agreed and the readiness work included, such as plan reviews, playbooks and tabletop exercises. In both cases we agree the scope with you before work begins.

How is incident response different from MDR or a managed SOC?

A managed SOC and MDR monitor the environment continuously to detect threats and take initial response actions. Incident response is the deeper work once an incident is confirmed: forensic investigation, containment, eradication, recovery and lessons learned. Our managed SOC and MDR are delivered within the scope of our NCA Tier 2 licence and are not offered to government entities or to organisations that own, operate or host critical national infrastructure.

Contact

Let's talk about what you need

We answer enquiries through the form, WhatsApp, a call or email.