Skip to main content
Incident response & red teaming, Cyber (Cyber & Critical Infrastructure), Unstrat

Incident response & red teaming

Breach response and adversary simulation

Overview

Incident-response engagements that contain and eradicate live breaches, and red-team operations that rehearse the adversary before one arrives. Delivered by researchers with responsibly disclosed vulnerabilities across maritime, rail and industrial control systems.

When the breach is live, the team that arrives has broken into ships, rail systems and payment networks legally, and knows exactly how the adversary thinks.

Unstrat represents this capability to a market only once classification and the end-user-certificate chain are confirmed. Full specifications are shared under briefing.

Capabilities

  • Incident-response engagements: containment, eradication, recovery
  • Red-team operations rehearsing realistic adversaries
  • Forensics and after-action hardening
  • Retainer and rapid-deployment options
  • Reduces the dwell time of a live intrusion: the team contains and eradicates before an attacker can pivot deeper into critical systems
  • Every engagement leaves the estate more defensible, feeding findings straight into hardening so the same breach cannot recur

Specifications

TypeIncident response & red teaming
ModesLive response / adversary simulation
BasisDisclosed research across maritime / rail / ICS
OriginIndependent / non-aligned

In depth

Containment comes before certainty

A live breach creates a practical order of work. The incident-response engagement covers containment, eradication and recovery, with forensics and after-action hardening recorded as part of the offer. The first task is to limit the intrusion and prevent an attacker from pivoting deeper into critical systems. Eradication removes the foothold, while recovery restores the affected environment and the confidence to operate it again. Forensics preserves the account of what happened so the response is not reduced to a hurried reset. The catalogue also records retainer and rapid-deployment options, reflecting the difference between arranging help after a compromise and having a response path ready when the event is live.

An incident-response team containing a live breach from a coordinated operations room.
An incident-response team containing a live breach from a coordinated operations room.

Rehearse the route an attacker takes

Red-team operations provide the other mode of the capability. They rehearse realistic adversaries against the buyer's environment before an actual breach, using the same attention to objectives and attack paths that makes response useful under pressure. The team is associated in the product record with responsibly disclosed vulnerabilities across maritime, rail and industrial control systems. Its work has also included legally conducted attacks against ships, rail systems and payment networks. Those references establish the research and operating domains without turning a simulation into a claim of access to every environment. The purpose is specific: expose weaknesses, exercise response plans and learn where an attacker could move before the organisation is dealing with the real event.

The breach should change the defence

After-action hardening is the connection between response and prevention. Findings from a live engagement feed into hardening so the same weakness is not simply documented and forgotten. Offensive cybersecurity supplies authorised adversary testing, while defensive cybersecurity supplies continuous detection and response. The incident-response capability joins them around the event itself, with an independent and non-aligned origin and a basis in disclosed research across maritime, rail and industrial control systems. Its role is not to claim that an incident can be made impossible. It is to reduce dwell time, contain the compromise before it travels further, recover the affected systems and leave the estate more defensible than it was when the response began.

Response has a defined handoff

The response sequence is deliberately wider than finding a compromised machine. Containment limits the incident, eradication removes the foothold, recovery returns the affected systems to operation, and forensics records what can be established about the intrusion. After-action hardening then turns that record into changes to the estate. The catalogue lists retainer and rapid-deployment options because those modes address different procurement decisions without changing the work itself. A buyer may need a standing path for a live breach, or a rapid engagement when no retainer exists. The red-team side provides a controlled way to rehearse the same sequence before the next event. It uses realistic adversaries and a defined objective, with the work bounded by authorisation. Research across maritime, rail and industrial control systems keeps the assessment grounded in environments where a breach can affect more than an office endpoint. The capability therefore links response, forensics, simulation and hardening, while leaving the buyer with the findings needed to make the defensive estate stronger.

The research boundary is part of the response

The record does not describe incident response as a generic help desk. Its basis is responsibly disclosed research across maritime, rail and industrial control systems, and its related offensive work has legally tested ships, rail systems and payment networks. That operating background matters when the responder has to understand how an adversary could move through a specialised environment, not just how to reset an office account. The response still follows the defined modes in the catalogue: containment, eradication and recovery for a live breach; red-team adversary simulation before one; forensics and after-action hardening after the work. Retainer and rapid-deployment options provide the available engagement paths without changing those responsibilities or making a claim that every incident has the same cause.

Responders reconstructing an attack timeline across forensic analysis screens.
Responders reconstructing an attack timeline across forensic analysis screens.

Why Unstrat: the difference

Unstrat is the authorised global representative and distributor for this capability. It is already in service with a track record behind it, so you are buying something that has done the job elsewhere, not funding a first attempt. You are not the test bed.

01

Independent, non-aligned origin, with no political exposure to any major-power ecosystem.

02

One accountable team from first briefing through delivery and in-region sustainment.

03

Responders with responsibly disclosed vulnerabilities across maritime, rail and industrial control systems.

How it reaches you

Independent maker
Non-aligned manufacturer
Unstrat
Single accountable channel
End user
Government or enterprise buyer
In-region sustainment · training · classification & end-use governance

Related capability

View all

Procurement & sustainment

Classification & EUC

Classification and the end-user-certificate chain are confirmed before this capability is represented to your market.

Non-aligned origin

Sourced from an independent manufacturer: no major-power disclosure rules or political conditions.

One accountable channel

A single team responsible from first briefing through delivery: not a chain of foreign primes to integrate yourself.

In-region sustainment

Lifecycle support and operator training delivered in-region, building capability that outlasts the initial deployment.

Questions buyers ask

What is an incident response retainer?

A contract signed before the breach, so that the NDA, the data-handling terms and the commercial arrangement are already agreed when the phone rings. The strongest practical argument for one is procurement speed rather than raw response time. We offer retainer and rapid-deployment options, and the responders are the same people who legally break into ships, rail systems and payment networks.

See: Incident response and red teamingAgainst Unit 42 and Mandiant

What response time should an IR retainer guarantee?

The market benchmark is now two hours to first human contact: Mandiant guarantees it on any retainer, and Unit 42 offers it on its top tier with 4, 8 and 24 hours below that. We do not publish an SLA, which is a genuine gap and we say so on our comparison page. Note also that time to first contact and time to containment are different numbers, and only the second one changes the outcome.

See: Published response commitments

Best incident response firms

Unit 42 and Mandiant publish the clearest commitments in the industry, and on paper we do not match them: Unit 42 cites more than 1,000 investigations a year and Mandiant frontline work since 2004. What neither publishes is a track record inside vessels, rail signalling and industrial control systems. Choose on the estate you actually need defended.

See: Domain experience compared

Who can respond to a cyber incident on a ship at sea?

Very few teams. Most IR practices are built for enterprise IT and will not know what can safely be isolated on a vessel under way. Our responders come from the research that produced responsible disclosures across maritime, rail and industrial control systems, so the first hour is spent containing rather than learning the environment. Neither the Unit 42 nor the Mandiant retainer datasheet publishes sector experience of that kind.

See: Incident responseMaritime cybersecurity

Incident response for industrial control systems and rail signalling

Containment in an OT estate is a safety decision as much as a security one, because isolating the wrong segment stops the process. Our incident work covers containment, eradication and recovery on systems in service, followed by hardening that feeds back into the defences. The disclosures behind the team span maritime, rail and industrial control systems.

See: IT and OT security comparedOT security capability

Is an IR retainer worth it if we are never breached?

The good ones are designed so the money converts into readiness. Mandiant allows unused prepaid hours to be repurposed across other consulting within the term, and Unit 42 credits can be spent on readiness assessments, tabletop exercises, penetration testing and IR plan development. If a supplier cannot tell you what happens to unused capacity, negotiate harder before signing.

See: Commercial structures compared

Should the same firm do our red teaming and our incident response?

A reasonable argument exists both ways. Separation preserves independence in the report; combination gives you responders who already know where the estate is weak because they broke it last quarter. We offer both from one team deliberately, and Unit 42 does something similar through retainer credits. Mandiant keeps its Red Team Assessment as a separate engagement.

See: Adversary simulation in the retainerOffensive cybersecurity

How do you reduce attacker dwell time once a breach is found?

By containing before the intruder pivots, which needs prior knowledge of what can be isolated in your estate without stopping operations. Our engagements are built around exactly that: containment, eradication and recovery, then forensics and after-action hardening so the same breach cannot recur. On the defensive side, our published example is a fleet-wide ransomware event contained and fully recovered inside a week.

See: Incident responseDefensive operations

We have a live intrusion in a national payment switch right now. What matters in the first hour?

Knowing which segments can be isolated without failing settlement, and having someone on the call who has seen a payment network mid-incident before. Our responders work on live production systems including payment networks, and the containment options are worked out from experience of those estates rather than from a generic playbook. After containment, forensics and hardening feed straight back into the defences.

See: Incident response and red teamingFinancial infrastructure defence

How should we score IR bidders when one publishes an SLA and another does not?

Score the two clocks separately and ask everyone for both: time to first human contact and time to containment by severity, written into the contract. Mandiant and Unit 42 both publish two-hour contact commitments and we do not, which we will not dress up. Then ask what happens after the callback, because a fast call from someone who has never seen your kind of system is not a response.

See: Where each supplier stands

Who keeps the forensic images and credentials collected during a response?

By the end of an engagement the response team holds forensic images, credential material, network maps and an accurate account of how a national system was defeated. Neither competitor datasheet addresses onward disclosure, because product literature rarely does, so get the answer into the contract. Our answer is that there is no third government with standing to ask us for a copy.

See: Origin and disclosure

Our cyber insurer has a panel of approved responders. Does that limit who we can call?

It can shape claims handling, and it is worth checking before an incident rather than during one. Unit 42 publishes recognition on the approved vendor panels of more than 70 major cyber-insurance carriers, honouring applicable panel rates. We do not publish insurance-panel recognition. If your policy makes panel membership decisive, raise it at scoping so the arrangement is clear.

See: Insurance panel recognition

What preparedness work should we do before we ever need a responder?

Test whether you can detect, decide and isolate. Mandiant's preparedness service reviews monitoring, logging and detection, checks containment capability and runs collaborative scenario planning, which is a good model of the scope. We deliver readiness through range exercises and after-action hardening from the same team that would respond, so the plan is rehearsed by the people who will execute it.

See: Cyber ranges and trainingPreparedness compared

How does an incident response engagement leave us better off afterwards?

Only if the findings turn into work. Every engagement we run ends in after-action hardening, with findings fed straight into the defensive platforms so the same breach cannot recur. Ask any bidder what their report obliges them to do next, and whether the same team is accountable for the remediation.

See: Incident responseInfrastructure hardening

Can a responder reach a remote site or a vessel when the network is down?

That is the case worth testing at contract stage, since most retainers assume remote access to a live estate. Our response work sits alongside off-grid assurance for isolated and remote systems, so the disconnected case is part of the same practice rather than an exception. Unit 42 publishes remote response SLAs by tier and regional emergency numbers, which is a different model and a useful comparison.

See: Off-grid cybersecurityResponse models compared

Incident response & red teaming: questions

What is Incident response & red teaming?

Incident response & red teaming is Unstrat's Cyber (Cyber & Critical Infrastructure) capability: Incident-response engagements that contain and eradicate live breaches, and red-team operations that rehearse the adversary before one arrives. Delivered by researchers with responsibly disclosed vulnerabilities across maritime, rail and industrial control systems.

How does Incident response & red teaming work?

Incident response & red teaming delivers its effect through Incident-response engagements: containment, eradication, recovery, Red-team operations rehearsing realistic adversaries and Forensics and after-action hardening, capabilities matched to the requirement and confirmed under briefing rather than published.

Who provides Incident response & red teaming?

Incident response & red teaming is delivered by The Cybersecurity Group, whose focus is cyber & critical-infrastructure security. Unstrat represents The Cybersecurity Group to government and enterprise buyers worldwide as an independent, non-aligned prime vendor.

Why choose Incident response & red teaming over a major-power alternative?

Incident response & red teaming is sourced from an independent, non-aligned provider, so it carries no major-power disclosure rules, upgrade-locks or political ramifications. Concretely: responders with responsibly disclosed vulnerabilities across maritime, rail and industrial control systems. The capability is accountable to you, not to a foreign vendor's government and its release schedule.

How is Incident response & red teaming procured, and where can it be delivered?

When the breach is live, the team that arrives has broken into ships, rail systems and payment networks legally, and knows exactly how the adversary thinks. Every engagement begins with a briefing, and export eligibility is confirmed per market under briefing rather than published. Where controlled capabilities are involved, the classification and end-user-certificate chain is confirmed first. Incident response & red teaming is then sustained in-region by one accountable team from briefing through long-term operation.

Contact us

Tell us the requirement. Specifications and the export position are confirmed in briefing, not published here.