Build & Respond

Incident response services

Contain the breach, remove the cause, and deliver the report your customers, regulator and insurer are waiting for. Available as a retainer or on demand.

Ali Aleali

Ali Aleali, CISSP, CCSP

Co-Founder & Principal Consultant

Former security architect for Bank of Canada and Payments Canada. CISSP, CCSP, more than twenty years in enterprise security. Leads every engagement.

Connect on LinkedIn

What the engagement covers

Built on a SANS-based incident response framework, with vulnerability assessment and penetration testing in parallel.

icon-2

Identify and contain

Read-only access to cloud log sources and application security logs, malicious sources blocked, exploited endpoints disabled, every affected system and compromise wave identified. A dedicated Slack channel and status calls every few hours from the first hour.

icon-9

Eradicate and recover

Malicious code and unauthorized changes removed, fixes verified for every vulnerability identified, evidence assembled proving each way in is closed.

icon-7

Vulnerability assessment and penetration test

Across the attack surface, alongside recovery, so reinstatement and hardening move together.

icon-5

Forensics and kill-chain reconstruction

Reconnaissance through impact, with an indicators-of-compromise appendix.

icon-6

Reports built for the reader

Structured for the platform review, the regulator, the customer or the insurer who will read them, as well as your leadership.

icon-3

Root-cause remediation roadmap

Prioritized recommendations mapped to root cause, handed to your team or carried by ours.

Before the incident

Response is faster when the team already knows the environment.

icon-8

Incident response retainer

Pre-agreed terms, a named team that has already mapped your environment and log sources, and response hours reserved. The first call is a status call, not an onboarding call.

icon-1

Tabletop exercises

Leadership and engineering walk through a realistic incident together. Gaps in decisions, contacts and evidence show up before a real one.

icon-4

Incident response for Shopify apps

Containment, VAPT and a forensic report structured for Shopify's app-reinstatement review, from a team that works inside the Shopify app architecture.

Assess, Build, Operate, applied to an incident

Three goals in sequence, each ending with evidence. A documented methodology, led by a senior architect with more than ten years of enterprise security experience and a CISSP.

01

Assess

Log access, containment, affected systems identified. Dedicated channel open from the first hour.

02

Build

Malicious code removed, vulnerability assessment and penetration test across the attack surface, fixes verified, closure evidence assembled.

03

Operate

Kill-chain reconstruction, forensic report, VAPT report, remediation roadmap. Structured for the review process between you and normal operations.

What you hold at the end

Reports written for the people who decide whether you are back in business, and the evidence behind every line.

  • Forensic incident report

  • Kill-chain and indicators-of-compromise appendix

  • Vulnerability assessment and penetration test report

  • Closure evidence per vulnerability

  • Root-cause remediation roadmap

  • Customer and regulator notification support

Why the response holds up

Field-tested on national payment infrastructure and on live platform incidents, not rehearsed on paper.

When to call, and what this is not

If you are in an active incident, use the contact form and mark it urgent. A responder replies directly.

Frequently asked questions

Emergency incident response is available around the clock. The first working step is read-only access to your cloud log sources and application security logs, and a dedicated Slack channel opens the same day. Retainer clients skip the onboarding, because the team has already mapped the environment.

We respond. Readiness work such as tabletops and retainers exists so that the response is faster, and Truvo never scopes an incident response engagement down to a readiness document alone.

Pre-agreed commercial terms, a named team that has already mapped your environment and log sources, and reserved response hours. When something happens, the first call is a status call, with scoping already done. Unused hours can typically be applied to tabletop exercises or testing.

Because the people who will read the report, a platform review team, a regulator, an insurer or an enterprise customer, want proof that the way in is closed and that adjacent weaknesses were checked. Running the vulnerability assessment and penetration test alongside recovery means the report and the fix arrive together rather than months apart.

Yes. Truvo is not a law firm and does not act as breach coach. We work beside your counsel and, where an insurer is involved, within the terms they set. Where an insurer mandates a specific panel firm, we say so on the first call.

A forensic incident report with a kill-chain reconstruction and indicators-of-compromise appendix, a vulnerability assessment and penetration test report documenting closed vulnerabilities, closure evidence per finding, and a remediation roadmap mapped to root cause.

Talk to the architect who would do the work

A 30-minute call. We look at your environment and say plainly whether we can help and what it would take.

From the blog: incident response

SOC 2 CC7.4: Responding to Security Incidents

SOC 2 CC7.4 requires a company to respond to security incidents through a defined incident-response program that understands, contains, remediates, ...

The Canadian Ransomware Paradox: Why Two Surveys Disagree on Payment

Two of the most-cited Canadian ransomware statistics flatly contradict each other.

SOC 2 Incident Response for On-Premise Environments

TL;DR IR maps to CC7.3 (security event evaluation, the triage discipline) and CC7.4 (defined response program with containment, mitigation, ...