Cybersecurity and Infrastructure

Detection, Response and Recovery

Assuming something will get through, and being ready to see it, stop it, and come back.

How We Work, Step by Step
  1. 1Collect logs
  2. 2Detect and alert
  3. 3Contain
  4. 4Eradicate and recover
  5. 5Learn and improve

What We Do for You

  • Centralise logging and write detection rules for your risks.
  • Write the incident response plan and the contact tree.
  • Build response playbooks for your top scenarios.
  • Design immutable backups and prove recovery by restoring.
  • Run a tabletop exercise with your team and report the findings.

How this is bought: Bought as a defined project to set it up, then a monthly managed service to run it. Build an estimate for your case.

Our Approaches Explained

Centralised logging and SIEM

Logs gathered in one place where patterns across systems become visible.

Detection engineering

Writing and tuning rules against real attacker behaviour, mapped to MITRE ATT&CK techniques.

SOAR and playbooks

Written response steps, partly automated, so the first hour does not depend on who is awake.

Incident response plan

Roles, thresholds, evidence handling and communication lines agreed in advance, following NIST SP 800-61.

Forensic readiness

Log retention and evidence preservation sufficient to reconstruct what happened.

Backup, restore and immutability

Copies that cannot be altered or deleted for a set period, tested by actually restoring.

Business continuity and disaster recovery

Recovery time and recovery point objectives (RTO / RPO) agreed with the business, not assumed by IT.

Tabletop exercises

Walking through a realistic incident with the people who would handle it, before it is real.

Breach notification readiness

Knowing who must be told, in what form, and inside what deadline.

The Standards We Work To

NIST SP 800-61 incident handlingMITRE ATT&CKNIST SP 800-34 contingency planningISO 22301 business continuity

We follow the structure and controls these standards describe. We do not claim to be certified against them - where you need a formal certificate, we prepare the evidence and an accredited body performs the audit.

What You Get

  • Logging and monitoring design
  • Incident response plan and contact tree
  • Response playbooks
  • Backup and restore test report
  • Tabletop exercise and findings
Where We Usually Focus
Critical systems logging centrally91%
Playbooks written for top scenarios80%
Restore drills completed76%

These are the areas clients most often ask us to improve. Your project sets its own targets, measured and agreed with you.

Ask AI what ARRIX does for Detection, Response and Recovery - ARRIX

Opens your assistant with the question ready. Gemini has no pre-filled link, so we copy the question to your clipboard first.