SXGuard — Swiss Security
...
Incident Response
Services 2

Incident Response

When it happens, you don't start from zero.

  • 24/7 hotline
  • NDA before any technical detail
  • You don't have to be a client already
Incident Response

When It Happens, You Don't Start From Zero.

Our responders work on the same platform already watching your estate. The case opens with the timeline, the IOCs, the affected hosts and accounts, and the investigation tasks already in it. No scramble to pull logs out of six teams first.

Not a monitoring client? We still take the call. The first job then is standing up emergency collection, so there's something to investigate.

  1. On contact

    We pick up and steady the situation.

    One technical lead is assigned to you. NDA signed. We tell you what to do now — and what not to do, so the evidence survives.

  2. Stage 1

    We classify it and draw the first boundary.

    Ransomware, BEC, data theft, insider misuse. Which systems are in scope.

  3. Stage 2

    We reconstruct the timeline.

    How they got in. How they moved. What they touched. Whether data left.

  4. Stage 3

    We contain it.

    You approve the containment plan before we run it. We don't cut production systems on our own authority.

  5. Close

    We report and hand over.

    Findings, prioritised remediation, and new detections deployed into monitoring so the next attempt surfaces sooner.

SXGuard alert management console

What You'll Receive

  • An incident report your board can read

    What happened, how far it went, what evidence backs that. Technical detail goes in the appendix, not the summary.

  • The attack timeline and the IOC list

    Ready to sweep the rest of your estate, and ready to hand to a partner or a regulator if it comes to that.

  • A prioritised remediation plan

    Including the new detections already live in monitoring, so you can show the gap is closed, not just logged.

Incident Types We Handle

Ransomware

Data encrypted, usually with a threat to leak it.

Business email compromise (BEC)

A mailbox taken over to redirect payments or read quietly.

Data breach

Customer or internal data taken out of the estate.

Web application compromise

A vulnerability exploited to plant a backdoor.

Insider risk

Legitimate access used for something it wasn't granted for.

Third-party breach

A supplier is compromised and it reaches you.

Targeted Intrusions And APT

The alert is not the intrusion. It's the first thing that happened to be visible — and it's late.

  • Months of history, queryable

    Every hunt re-runs across retained data — which is how an exfiltration spread thinly over a fortnight gets found at all.

  • Related alerts become one case

    Alerts sharing an entity fold into a single campaign instead of forty tickets that each look minor.

  • Every case opens with its neighbourhood

    One hop of the entity graph comes attached, so lateral movement is visible rather than reconstructed.

  • Severity follows the asset

    Malware on a payment host means segmentation, jump host and application auth were already crossed. The case says which — and that says where to look next.

Analyst inspecting a correlated case in the SXGuard console

What The AI Does In An Investigation

It performs the steps an analyst repeats identically every time:

  1. Pulls the context around the alert — that user, that host, either side of it
  2. Expands entities one hop and attaches the neighbourhood
  3. Enriches every indicator against reputation and intelligence
  4. Drafts the timeline, the IOC list and the affected assets into the case
  5. Seeds the standard investigative tasks, so the process holds at 4am
  6. Proposes a verdict with its reasoning and a confidence level

An analyst decides. The AI does not contain, isolate, disable or block.

Every step it took is recorded in order and can be replayed — you audit its work, not just its conclusion.

Where We Respond

Cloud & SaaS

Control-plane and audit trails normalised like any endpoint log, so a cloud step and a host step land on one timeline.

Containers & Kubernetes

Cluster audit, workload events, runtime security, and the virtualisation layer under them. A pod that is gone cannot be imaged — collection is continuous, not reactive.

On-premise

Windows, Linux, macOS, firewalls, proxies, VPN, directory, network sensors. No central logging? We collect with the free forensic toolkit and replay it into the same pipeline.

OT, ICS & IoT

The limits matter more than the claim — see below.

OT, ICS and IoT. We work where OT incidents are actually investigated: the IT side of the boundary.

  • Scope: Engineering workstations, HMIs, historians, jump hosts.
  • Hard limit: We do not install agents on PLCs or RTUs, and we do not touch controllers on a running process.
  • Why severity is elevated: OT assets are recognised by host naming and vendor stack and weighted at the top of the criticality scale — an alert there means the IT/OT boundary, the DMZ historian relay, and engineering-workstation access were already crossed.

What we don't claim. ICS protocol content — Modbus, DNP3, S7comm, IEC-104 — is not parsed into detections. ICS network visibility reaches us through the IDS feed; safety-instrumented systems are out of scope.

In An Incident, Or Trying To Avoid One?

In one. Call the hotline. We take the call first and do the paperwork after.

Not in one. Start with a log coverage assessment. Fixed scope, fixed duration. The findings will tell you what to do next — including when the answer is "you don't need a managed SOC yet."