Cybersecurity for complex IT and OT environments
Senior specialists, supported by AI
Incident response and digital forensics serve two immediate objectives during a cyber incident: stop further compromise and establish what happened. The response must reduce operational impact without destroying evidence or obscuring the attack path. Every action therefore requires technical control, clear authority and an understanding of the systems, identities and business processes involved.
Incident response focuses on containment, eradication and controlled recovery. Digital forensics reconstructs the sequence of events through logs, endpoints, cloud platforms, identity systems, network data and other digital evidence. Together, these disciplines determine how access was obtained, which accounts and systems were affected, whether persistence remains and whether data was accessed, altered or exfiltrated.
Senior specialists bring structure to incidents involving ransomware, business email compromise, account takeover, data theft, insider activity and disruption within IT or OT environments. Critical actions are prioritised, evidence is preserved and technical findings are translated into decisions for management, legal teams and operational stakeholders.
The result is more than restored availability. It is a defensible timeline, a validated assessment of impact and a clear recovery plan. This provides the operational picture required to contain the incident, support reporting obligations and prevent the same attack path from being used again.

DeepBlue is a member of Cyberveilig Nederland
During a cyber incident, speed and evidence preservation must remain in balance. Immediate action may be required to stop further compromise, but uncontrolled changes can destroy logs, alter timestamps or remove traces needed to reconstruct the attack. The first phase therefore establishes command, identifies critical systems and determines which containment measures can be executed without compromising the investigation.
The response follows three objectives: contain the threat, establish the facts and prevent further impact. Incident response and digital forensics operate as one coordinated process. Containment limits attacker access and lateral movement. Forensic analysis reconstructs the timeline, identifies the initial access vector and determines which systems, accounts and data were affected. Recovery decisions are based on validated findings rather than assumptions.
The investigation produces a factual timeline, a documented attack path and a substantiated assessment of impact. This evidence supports technical recovery, executive decision-making, legal review and regulatory reporting where required. The final outcome includes concrete measures to remove persistence, close the exploited weaknesses and strengthen detection and response against recurrence.
An Incident Response Retainer establishes access to forensic and incident response specialists before an incident occurs. Escalation routes, responsibilities, communication channels and technical access requirements are agreed in advance. This removes delays during the first critical hours and allows the response team to begin triage with an existing understanding of the organisation and its environment.
The retainer can provide guaranteed response capacity, initial triage, remote or on-site support and access to specialists in incident coordination, digital forensics and technical containment. The exact operating model depends on the risk profile, infrastructure and required response time. Coverage can include IT, cloud, identity, email and OT environments.
Preparation is part of the service. Contact details, evidence sources, logging coverage, access procedures, network designs and key dependencies are reviewed before activation. Tabletop exercises, playbook reviews and forensic readiness activities can be included to identify gaps before they affect a live response. Retained hours can be used for incident response, forensic investigation and agreed preparation activities. This keeps the arrangement operational throughout the contract period and provides a defined route to specialist support when an incident is confirmed or suspected.
The required response depends on the type of incident, the affected environment and the decisions that must be supported. A ransomware attack, business email compromise, insider case or OT disruption requires a different investigation plan, evidence strategy and command structure. The engagement is therefore organised around defined workstreams. These can run independently or as part of a coordinated response. Scope and priorities are adjusted as new evidence becomes available. Critical systems, legal constraints, reporting obligations and operational dependencies remain visible throughout the investigation.
Senior specialists work directly with technical teams, management, legal counsel, insurers and external suppliers where required. Responsibilities, escalation paths and decision authority are established early. This prevents parallel actions from interfering with evidence, containment or recovery.

A clear command structure is established for technical decisions, escalation and communication. Actions, owners and dependencies are tracked throughout the incident. Management receives verified information for decisions, while technical teams work from a controlled action plan.

Relevant evidence is collected from endpoints, servers, cloud platforms, identity systems, email environments, network devices and security tooling. Collection methods are selected to preserve integrity, metadata and chain of custody without creating unnecessary operational impact.

The investigation determines whether attacker access extends beyond the initially identified systems. Accounts, tokens, persistence mechanisms, remote access, administrative changes and lateral movement are examined across the environment. This defines the actual scope of compromise before recovery begins.

Restored systems are reviewed before they return to normal operation. Access paths, identities, configurations, monitoring and critical controls are validated against the findings from the investigation. Recovery is completed only when the known attack path has been removed and residual risks are documented.
Specialist support should be engaged when compromise is suspected but not yet confirmed, or when internal teams cannot establish the full scope of an incident. Common triggers include unusual account activity, ransomware indicators, unexplained data transfers, mailbox manipulation, persistence mechanisms or disruption of critical systems. Early involvement reduces the risk of evidence loss and uncontrolled remediation.
Emergency incident response is activated after an incident has occurred and may require commercial, legal and technical arrangements before work can begin. An Incident Response Retainer establishes these arrangements in advance. Response expectations, escalation routes, access requirements and available capacity are already defined when support is needed.
Many incidents can initially be investigated remotely through secure access to relevant logs, endpoints, cloud platforms, identity systems and security tooling. On-site deployment may be required when systems are isolated, physical evidence must be acquired, OT environments are involved or remote access cannot be trusted. The response model is determined during initial triage.
The investigation can assess whether evidence supports access to, collection of or exfiltration of data. Relevant sources may include endpoint artefacts, cloud audit logs, proxy data, firewall logs, email activity and attacker tooling. A definitive conclusion depends on the quality and retention of available telemetry. Uncertainty is documented where the evidence does not support a conclusive finding.
Coverage depends on the policy, applicable conditions and insurer approval process. Many cyber insurance policies include access to approved incident response, forensic, legal and recovery providers. The insurer or broker should be contacted early, but urgent evidence-preservation and containment decisions should not be delayed unnecessarily.
Preparation starts with clear escalation routes, current contact details, tested backups, adequate logging and documented authority for containment decisions. Critical systems, suppliers and evidence sources should be known in advance. Tabletop exercises and forensic readiness reviews help identify gaps before an incident places the organisation under operational pressure.
Discuss a security requirement, active risk or complex IT or OT environment with one of our senior specialists. The initial conversation focuses on the technical context, operational constraints and the most appropriate course of action.
Urgent assistance required?
Call +31 (0) 70 290 6 290
or email info@deepbluesecurity.nl
Technical analysis, field observations and sector-specific perspectives across IT, OT and cyber resilience.