What's covered/04 · Incident response

Your breach panic button.

Something's wrong and you need help now - not a support ticket, not a sales call. Hit the button and a real responder is paged immediately. We get on the line, scope the damage, and start locking it down. The first 30 minutes are free. After that it's $400 an hour, billed by the hour - no retainer, no surprises.

sythe://incident/responseStanding by
First 30 minutes free · then $400 / hour, billed by the hour
[ 01 ] When it's on fire

The number you call when it matters.

An incident is the worst time to discover your vendor responds in business hours. We built this to be the opposite - a button that puts a real, capable human on the problem the moment you press it.

Real humans, in minutes

You hit the button and a named responder is paged - not routed into a queue. A person is usually on the line in under 15 minutes, any hour, any day.

- paged instantly · <15 min to a human

The people who break in, defending you

The same offensive operators who run our pentests work your incident. They think like the attacker because they are one - so they find the foothold faster.

- offensive team · attacker mindset

Contain first, explain later

We isolate the blast radius, revoke what's compromised, and stop the bleeding before we write a single word of report. Action now; the write-up follows.

- stop the bleeding, then document

Transparent, even mid-crisis

No emergency surcharge, no minimum, no retainer to pre-buy. The first call is free and every hour after is billed at one honest rate you can see coming.

- free triage · $400/hr · no surprises
[ 02 ] How response works

From the button to back to normal.

Every incident runs the same disciplined path - starting the minute you press the button. The gated steps (triage and verification) are where a human draws the line, so "contained" means contained and "closed" means closed.

T + 0 · gated

Page & triage

You hit the button. A responder is paged and on the line in minutes for a free 30-minute call to scope what's happening and what's at stake.

Human on the line · scope set
Phase 02

Contain

We isolate affected systems, revoke compromised credentials and sessions, and cut the attacker's access - fast, to stop the incident from spreading.

Blast radius contained
Phase 03

Eradicate

We find and remove the root cause - the foothold, the backdoor, the misconfiguration - and confirm the attacker no longer has a way back in.

Threat removed · access closed
Phase 04

Recover

We bring systems back safely and in the right order, validate they're clean, and watch closely for any sign the attacker tries to return.

Service restored · monitored
Phase 05 · gated

Verify & evidence

We confirm the incident is closed and capture the timeline, the indicators, and what we did - evidence you can hand to leadership, customers, or an auditor.

Closed · evidence in-platform
Phase 06

Post-incident review

Once the fire is out, we walk the root cause with your team and harden the gaps that let it happen - so the same door doesn't open twice.

Root cause · hardening plan
[ 03 ] What it costs

Honest pricing, even in a crisis.

The worst time to be nickel-and-dimed is mid-breach. So incident response is priced the same way the rest of Sythe is - out in the open, one rate, no games. It stands on its own: you don't need a plan with us to call.

First 30 minutes
Free
A real responder, on the line, scoping the incident with you. No card, no commitment. If we can point you in the right direction in 30 minutes, that's on us.
After that
$400/ hour
Billed by the hour, only for time we actually spend. No retainer, no minimum, and no emergency multiplier because the building's on fire.
Already on a Sythe plan? Incident response is included - the hotline is for everyone else, mid-incident, right now.
[ → ] Don't wait it out

If something feels wrong, it probably is.

You won't be charged to find out. Hit the hotline, get a human in minutes, and let us tell you whether it's an incident or a false alarm - before it becomes the former.