Platform

HexaCore, The unified resilience core HexaSOC, AI agentic SOC & MDR HexaInt, Cyber & dark-web intelligence HexaOT, OT & ICS security HexaComply, Compliance & TPRM HexaAI, AI security & governance HexaCustody, Digital content custody HexaStrike, Agentic offensive security HexaMatrix, ATT&CK coverage & mapping HexaView, Multi-tenant customer portal

Solutions

Managed Detection & Response, 24/7 AI-agentic detection & response Co-Managed SOC, Your team and ours, one operation Detection Engineering, Coverage you can measure Incident Response Retainer, A hand on the wheel before you need it Penetration Testing, See your estate the way attackers do Red & Purple Teaming, Offence that hardens your defence Continuous Security Validation, Validate continuously, not annually Cyber Crisis Tabletop & War-Gaming, Rehearse the bad day Continuous Threat Exposure Management, From a list of vulns to a plan Cyber Risk Quantification, Risk as a number the board can use Managed Threat Intelligence, Signal, not noise Digital Risk & Brand Protection, Protect your name where you cannot see Managed OT & IoT Monitoring, Security for systems that cannot go down OT/ICS Assessment, Know your OT before an attacker does Compliance as a Service, Gap assessment to certification Third-Party & Supply-Chain Risk Management, Risk does not stop at your perimeter Virtual CISO & Governance Advisory, Executive security leadership, on tap AI Security & Governance, Govern the AI you are adopting Managed Content Custody, Custody for your crown jewels

Industries

Maritime, Fleets, ports and shore-side IT Media & Entertainment, Pre-release content and production Casino & Gaming, Platform integrity and player trust Financial Services, DORA, resilience and fraud Critical National Infrastructure, Converged IT and OT estates Manufacturing, Plants, PLCs and supply chain Healthcare, Clinical systems and patient data Pharmaceutical & Life Sciences, Research IP, GxP and data integrity Energy & Utilities, Generation, grid and SCADA Government, Sovereign data and assurance

Partners

Partner programme, Refer, resell or white-label Cyber Dockside AI, Maritime, exclusive partner TeamLogic IT, US channel partner Walking Comet, Australia, casino & gaming Copla, GRC technology partner Nexovern, Runtime AI sensor partner

Learning

Learning Hub: explainers, guides and briefings

Company

About HexaShield Contact Book a meeting Client Login Book a demo
Managed SOC / MDR

Incident Response Retainer

When the SOC escalates, we take the wheel.

An L4 incident-response capability that activates the moment your SOC declares a major incident. Response hours are agreed and purchased upfront, then drawn down when you need them — coordinated, communications-led, and run in a dedicated Microsoft Teams war room. Available only as an add-on for HexaShield managed SOC (IT & OT) customers.

Hours banked upfrontSOC add-on only
HexaSOC™ Seen through HexaView™
L1Triage L2Investigate L3Hunt L4 Incident Response DFIR · external ESCALATE

An add-on for managed SOC customers only

This retainer extends HexaSOC for IT and OT estates. It is not sold separately — your environment must already be monitored by our managed SOC, so responders arrive with full context and telemetry, never a cold start.

Powered by HexaSOC™. Every action and update is one truth in HexaView™.

Where the SOC hands over

From SOC L3 to L4 incident response

Your SOC runs continuously across three tiers. When an event becomes a major incident that exceeds day-to-day operations, it crosses a line into L4 — the incident-response retainer. Beyond IR sits digital forensics, a specialist discipline we deliberately leave to a dedicated DFIR provider.

HexaSOC · 24/7 · included
L1TriageAlerts sorted and prioritised
L2InvestigateConfirmed and enriched
L3Hunt & advanced analysisWhere a major incident is called
Major incident declared escalate
L4 · The retainer

Incident Response

Named responders activate and take the wheel — drawing on your banked hours.

The line to DFIR

Digital Forensics

Specialist · not HexaShield

You retain a dedicated DFIR firm; we coordinate a clean handoff.
How the retainer works

Response time, banked in advance

You buy a block of incident-response time upfront — a set number of hours or days. When an incident is declared, responders draw from that block. It is topped up on renewal, and time you do not spend on incidents is never wasted.

Retained response hours40h purchased
24h drawn down16h available
  • Predictable, agreed costNo emergency day-rates negotiated mid-crisis — the commercials are settled before anything happens.
  • No cold startBecause we already run your SOC, the clock starts on response, not on onboarding and access.
  • Unused hours build readinessQuiet quarter? Spend the block on tabletop exercises, playbook development and IR readiness reviews.
Inside an incident

A calm, coordinated response — communication at every step

A walk-through of how we run an incident. The phases move fast, but the constant throughout is communication: everyone who needs to know, knows, at every stage.

  1. 01

    Declare & mobilise

    The SOC escalates the major incident; an Incident Commander is assigned and a Teams war room is opened within minutes.

  2. 02

    Triage & scope

    Confirm, classify severity and scope the blast radius across IT and OT, using full context from your managed SOC.

  3. 03

    Contain

    Isolate affected systems with guard-railed, OT-safe actions to stop the spread without breaking operations.

  4. 04

    Eradicate

    Remove attacker access and close the entry vector, verifying nothing is left behind.

  5. 05

    Recover

    Restore services safely, validate integrity and watch closely for any sign of reinfection.

  6. 06

    Review & harden

    A clear post-incident report, lessons learned, and new detections fed straight back into your SOC.

Communications — continuous, from declaration to closure.

A steady cadence of updates to executives, legal, insurers and regulators, plus your technical team — owned by a dedicated Communications Lead so responders can stay on the response.

Communication is the response

Your incident war room, in Microsoft Teams

The moment an incident is declared, we open a dedicated Microsoft Teams war room — the single source of truth for the whole response. Everyone who needs to be in the room is in the room.

#incident-war-roomINC-2043 · Sev 1 · IT + OT Live
IC
Incident Commander 09:02War room open. Sev 1 declared. Drawing from the retainer. Roles assigned — updates every 30 min.
LR
Lead Responder 09:07Scoped to 3 hosts + one OT segment. Containment staged, OT specialist looped in before we isolate.
CL
Comms Lead 09:12Exec brief sent. Holding statement drafted for legal. Regulator clock noted.
You
Your Liaison 09:15Approved isolation of the three hosts. Standing by on the OT call.
  • A dedicated channel per incident — opened automatically on declaration.
  • Clear roles and a single line of authority, agreed in advance.
  • A live decision and action log — who decided what, and when.
  • Exec, legal and regulator updates from one place, on cadence.
  • Actions and evidence linked back to HexaView™ for the record.
  • Secure and access-controlled — only the room, in the room.
Who’s in the room

The response team

An incident is run by people, not tickets. These are the roles we bring — and the ones we agree on your side — so authority and communication are never in doubt.

Incident Commander

Owns the incident end to end: decisions, priorities, cadence and the single line of authority.

Lead Responder

Runs the technical response — triage, containment, eradication and recovery on the ground.

SOC L3 Analysts

The same analysts already watching your estate, now surging on the incident with full context.

OT Response Specialist

Brought in for OT incidents to keep containment safe for systems that cannot simply be switched off.

Communications Lead

Keeps executives, legal and regulators informed with the right message at the right moment.

Your Named Liaison

Your side of the bridge — the people we agree in advance who can authorise and unblock.

Key features & benefits

What the retainer gives you

  • Priority access with agreed response SLAs
  • A named Incident Commander for every incident
  • Response hours banked upfront, drawn down on demand
  • OT-safe containment across IT and OT estates
  • A Microsoft Teams war room, opened on declaration
  • Communications managed across execs, legal and regulators
  • Full context from minute one — no cold start
  • Post-incident report with lessons fed back to your SOC
  • Unused hours convert to proactive IR readiness
Clear boundaries

Where our IR ends and DFIR begins

We are deliberately clear about scope. We run incident response; we do not provide digital forensics. Knowing the line in advance is what keeps a real incident clean.

HexaShield Incident ResponseIn scope · L4
  • Escalation from your managed SOC (L3 to L4)
  • Triage, severity classification and scoping
  • OT-safe containment and eradication
  • Safe recovery and reinfection watch
  • Incident coordination and the Teams war room
  • Executive, legal and regulator communications
  • Post-incident report and hardening actions
Digital Forensics (DFIR)Specialist · external
  • Court-admissible forensic acquisition & imaging
  • Formal chain of custody for litigation or law enforcement
  • Expert-witness testimony and legal reporting
  • Deep malware reverse-engineering as legal evidence
  • Long-term evidence preservation and disclosure

We don’t provide digital forensics. If an incident needs it, you engage a specialist DFIR retainer and we coordinate a clean handoff — preserving what we can along the way.

Ready before you need it

Add a retainer to your managed SOC

Already a HexaSOC customer? Let’s size the right block of response hours and put the war room, roles and playbooks in place — before the bad day.