Do you offer an incident response retainer?
Yes — retainers guarantee 1-hour response SLAs, with pre-agreed rates and pre-authorised investigators on standby 24×7.
Extended answers to the questions buyers, boards and procurement teams ask before commissioning Digital Forensics & Incident Response (DFIR).
Delivered by an ISO/IEC 27001, 27701 & 9001 certified organisation
Yes — retainers guarantee 1-hour response SLAs, with pre-agreed rates and pre-authorised investigators on standby 24×7.
Yes. We follow ACPO and NIST SP 800-86 guidelines with full chain-of-custody documentation.
Ransomware, business email compromise (BEC), insider threat, data breach, financial fraud, intellectual property theft, cloud account takeover and nation-state intrusion.
We coordinate with specialist ransom-negotiation partners and OFAC-screened payment facilitators where leadership decides negotiation is necessary. Our default position is recovery, not payment.
Yes — we are on the panels of major regional and global cyber insurers and align scope, rates and reporting to their incident-response requirements.
Yes — we coordinate with UAE Cyber Crime Centre, SAMA-CERT, CERT-IN, CBUAE and law enforcement as required, with evidence packs prepared to a court-admissible standard.
We can typically have a triage call inside 4 hours and forensic responders onsite or remote within 24 hours. Retainer clients get a 1-hour SLA.
Yes — every engagement closes with a written report covering scope, timeline, root cause, remediation and lessons learned, signed by the lead investigator.
Every engagement is led by a partner or principal with at least 12 years in cybersecurity and supported by certified consultants (CISA, CISM, CISSP, CIPP/E, ISO 27001 Lead Auditor, ISO 42001 Lead Implementer, OSCP, CREST). You meet the actual delivery team before contracts are signed.
All client data stays within the regions you authorise. NDAs are signed before scoping calls, and we offer fully on-premise delivery for sensitive engagements. For UAE and KSA clients, evidence remains in-country by default.
Yes. We routinely collaborate with EY, Deloitte, KPMG, PwC, BDO and Grant Thornton as your implementation partner while they retain audit independence. Roles are agreed upfront in writing to preserve auditor independence rules.
Yes — our Managed Compliance Service operates the programme on a monthly subscription, covering control monitoring, evidence collection, internal audit and recertification across every framework in scope.
Success criteria are agreed in the engagement charter — typically a passed certification or regulator submission, an audit-ready evidence repository, trained control owners and a 12-month continuous-improvement plan.