Threat Intelligence and Incident Response

Know who is targeting you, and be ready when something happens.

Intelligence tells you which threats matter to an organisation like yours. Incident response makes sure that, when one gets through, an experienced team is ready to contain it, recover your systems and establish what happened.

Why it matters

The problems we solve

01

Generic threat feeds create noise

Global indicator feeds rarely reflect the actors actually targeting Qatar and the GCC.

02

Your brand is abused outside your network

Phishing sites, fake social accounts and leaked credentials appear where your security tools cannot see them.

03

No plan when an incident starts

Without a retainer, the first hours of an incident are spent finding and contracting a response team.

04

Evidence has to stand up

Investigations for regulators, insurers or courts need forensically sound evidence.

Services

What we deliver

Each service can be engaged on its own or combined into a single programme.

01

Cyber Threat Intelligence

Actionable intelligence on threat actors, campaigns and vulnerabilities relevant to Qatar and the GCC.

  • Actor and campaign profiles for your sector
  • Indicators integrated with your SIEM
  • Periodic threat landscape briefings
02

Digital Risk Protection

Monitoring of the open, deep and dark web for brand impersonation, leaked data and exposed credentials.

  • Phishing domain and fake account detection
  • Dark web and paste-site monitoring
  • Takedown support
03

Incident Response Retainer

Pre-agreed response times and an on-call team, so you are not negotiating contracts during an incident.

  • Agreed response times and named contacts
  • Incident response plan and playbook review
  • Tabletop exercises with your team
04

Emergency Incident Response

Containment, eradication and recovery for active incidents, including ransomware.

  • Triage and scoping
  • Containment, eradication and recovery
  • Ransomware response support
05

Digital Forensics

Evidence collection and analysis with chain of custody, for breaches, insider cases and fraud.

  • Disk, memory, log and cloud evidence
  • Chain of custody documentation
  • Reports for regulators and legal counsel
06

Compromise Assessment

A focused hunt to confirm whether an attacker is already inside your environment.

  • Hunting across endpoints, logs and identity
  • Checks for persistence and lateral movement
  • A clear answer on whether you are compromised
Outcomes

What you get

Agreed response times under retainer
Root cause and impact clearly documented
Lessons learned fed back into detection
How it works

Our approach

01

Prepare

Plans, playbooks, retainer terms and tabletop exercises.

02

Triage

Scope the incident and decide the first containment steps.

03

Contain and recover

Remove the attacker and restore operations safely.

04

Learn

Root cause, lessons learned and new detections.

Standards we work to

Standards we work to

NIST SP 800-61ISO/IEC 27035MITRE ATT&CKNCSA National Information Assurance
Questions

Frequently asked

Do we need a retainer to call you?

No. We respond to emergencies without one, but a retainer gives you agreed response times and a team that already knows your environment.

Can you handle ransomware?

Yes. We help contain the attack, preserve evidence, recover systems and support your communication with stakeholders.

Is the intelligence specific to Qatar?

We prioritise intelligence on actors and campaigns targeting Qatar, the GCC and your sector.

Get in touch

Tell us what your regulator, auditor or board is asking for.

We will come back to you with how we would approach it, who would work on it and what it would take.