03 / AFTER THE BREACH
Move forward.
Recover with confidence: close the root cause, verify the attacker is gone, and give leadership, insurers and regulators a clear account.

AT A GLANCE
What this covers
Who it serves
Organizations recovering from an incident — handled by IGH or someone else — and those whose leadership needs assurance it won’t repeat.
Typical trigger
Containment is done but confidence isn’t. Insurers, auditors or the board want evidence of remediation.
The work
- Post-incident compromise assessment to confirm eviction
- Hardening & remediation of the root cause and related weaknesses
- Lessons-learned review and updated IR plan
- Move into ongoing monitoring with OnWatch if wanted
Deliverables
- Post-incident report and root-cause summary
- Remediation verification checklist
- Updated playbooks and responsibility matrix
- Board-ready briefing
Not included
- Rebuilding business applications or data restoration beyond agreed scope
- Legal or PR services (coordinated via IR Concierge, delivered by your advisers)
Talk it through
Tell us where you are. We’ll recommend a sensible first step.