Recover from an attack

Network intrusion and breach response

An alert you can't explain, an admin account nobody created, sign-ins in the middle of the night, or a warning from someone outside the business. Find out whether someone is inside, and get them out properly.

If you think someone is inside
  1. Don't tip them off. Talk about it by phone rather than email or chat, which the attacker may be able to read.
  2. Don't wipe or rebuild anything yet. It destroys the evidence of how they got in, and they may have other ways back.
  3. Note what made you suspicious: times, account names, alerts and which machines.
  4. Call for help. Contact us, or if you can't reach us, Sophos's UK emergency line on +44 1235 635329. Tell your cyber insurer too.
The risk

Attackers who get into a network rarely act straight away. They look around, collect passwords and find the valuable systems first; ransomware or data theft usually comes at the end of that.

Removing the one machine you know about is rarely enough. If they have created accounts, stolen passwords or installed remote access tools, they can come back another way.

What it does
  • Confirms whether an attacker is present, with a compromise assessment across your systems
  • Threat hunting to find the accounts, tools and footholds they left behind
  • Traces how they got in: phishing, a stolen password or an unpatched system facing the internet
  • Removes them in one coordinated step, so they can't switch to another route as soon as one is closed
  • Watches for signs they come back
  • Works alongside the security tools you already have, so you don't need to be a Sophos customer

Once they're out, network detection and 24/7 managed detection and response watch for the next attempt, including on devices that can't run security software.

Who it's for

Businesses that have seen signs of an intruder, or have been told by a supplier, the police or the NCSC that they may have been breached.

How we supply it

Intrusion response is carried out by Sophos's incident response team and arranged through us. Contact us and we'll get it started. If you can't reach us, you can call Sophos's UK emergency line directly on +44 1235 635329.

What's under the hood

Sophos Incident Response Services — Sophos's digital forensics and incident response team, which gained NCSC-assured Cyber Incident Response (Level 2) status in 2024.

Questions
Common signs include admin accounts nobody created, sign-ins at odd hours or from abroad, security tools being switched off, unusual traffic leaving the network, and files being gathered in one place. One sign on its own may be innocent; a compromise assessment gives you a clear answer.
Usually not. Most of the work is done remotely, using a sensor installed on your systems. On-site support is available if the case needs it.
The report sets out what to fix. Intrusions are often found late because nobody is watching overnight or at weekends, which is the gap 24/7 managed detection and response closes.
It depends on the size of the incident, and the cost is agreed with you before work starts.

Not sure what you need?

Tell us a little about your business and we'll recommend the controls that matter most for it — no obligation, and no jargon.

Talk to us → or see every security area →