Home / Incident Response
24/7 IR Hotline · Active incident

Active incident?
Call now.

Direct line 208·557·1883

The line is answered by the founder or a designated principal. Initial call is free. If the matter is privileged, route through counsel — we'll work with them from the first sentence.

FIRST 60 MINUTESchecklist
  1. 01Don't power off. Volatile evidence lives in memory.
  2. 02Isolate, don't wipe. Network-isolate suspect hosts. Preserve disk.
  3. 03Loop in counsel. Privilege starts now, not at hour 12.
  4. 04Notify carrier. Cyber-insurance panel rules matter.
  5. 05Call CyberD20. We coordinate with counsel and carrier from there.
What we respond to

Common incident profiles.

·

Ransomware & extortion

Containment, recovery planning, threat-actor communications support, and decision support for executives and counsel.

·

Business email compromise

Wire fraud loss containment, mailbox forensics, downstream notification, and recovery coordination with banks.

·

Network intrusion

Triage, scoping, lateral-movement reconstruction, and root-cause documentation suitable for regulators.

·

Insider misuse

Discreet investigation of suspected exfiltration, abuse of access, or policy violation — with HR and legal in the loop.

·

Third-party / supply chain

Triage when a vendor or upstream provider is the entry point; impact scoping and mitigation guidance.

·

Executive & principal targeting

Response to harassment, doxxing, or coordinated targeting of executives, family, and high-visibility personnel.

Lifecycle

From the first call to the closeout report.

PHASE 01

Triage & coordination

Initial scoping call. Counsel and carrier looped in. Rules of engagement and chain-of-custody discipline established immediately.

First hour
PHASE 02

Containment

Network isolation, account lockdown, and propagation arrest — without destroying volatile evidence in the process.

Hours 1–24
PHASE 03

Forensic triage

Memory and disk acquisition, log centralization, scope determination, and preliminary attribution.

Days 1–5
PHASE 04

Eradication & recovery

Threat-actor removal, credential rotation, control hardening, and staged restoration of business operations.

Days 3–14
PHASE 05

Findings & closeout

Root-cause documentation, regulator-ready timeline, and executive briefing — with concrete control improvements.

Per matter
Retainers

Pre-arranged response,
at pre-arranged terms.

An IR retainer means the negotiation, conflict check, and onboarding happen in calm conditions — not at hour zero of an active incident. Retained organizations get priority response, a defined SLA, and a familiar team that already knows the environment.

Retained
  • — Priority response · defined SLA
  • — Pre-built playbooks & runbooks
  • — Annual tabletop included
  • — Familiar with your environment
Walk-up
  • — Best-effort response, hourly billing
  • — Conflict check at intake
  • — Ad-hoc onboarding
  • — Always answered. Never guaranteed.
Pricing — custom by environment. Retainers and incident response engagements are scoped to environment size, regulated-data exposure, and required response posture. No fixed packages. Written quote inside five business days of intake; emergency rates apply once an active incident is declared.
Geographic coverage

Drive-time response across Idaho. Mountain West on case-by-case.

Active incidents inside Idaho receive on-site response within drive-time from Eastern Idaho HQ — Idaho Falls, Pocatello, Rexburg, Twin Falls, Jerome, and the rest of the state. Remote response begins immediately while travel is in motion.

Idaho · primary
  • — On-site within drive-time, Eastern Idaho & Magic Valley
  • — Statewide on engagement (Boise, Coeur d'Alene, Lewiston)
  • — Remote response begins immediately at intake
  • — Established Idaho LE & prosecutor coordination
Mountain West · case-by-case
  • — MT · WY · UT · NV · OR · WA
  • — Counsel referrals & prior-relationship matters
  • — Remote-first; on-site at carrier or counsel discretion
  • — Conflict check at intake before any privileged review
If in doubt — call.

No initial-call fee. No sales process.
Just an operator on the line.