Cybersecurity

Intrusion Detection & Response

The part after the alert.

Intrusion detection and response means noticing that something is wrong across your systems and then doing something about it: identify, contain, remove, restore, report. Detection is the half that is easy to buy. happier IT provides both, from our own security operations centre in Canada, with the authority to contain a problem agreed with you before anything happens.

Who it's for

The gap is almost always between the alert and the action.

Four situations, and each one is really the same question wearing different clothes: when something fires, what happens next, and who is allowed to do it?

Alerts arrive in an inbox. A rule sends them to a shared mailbox, or to one person who also has a day job. They are read in the morning, which is fine for most of them and not fine for the one that matters.

Nobody has agreed who may disconnect what. The technical ability exists. The authority does not. At 2am that difference is the whole story, because the machine stays online while somebody looks for a phone number.

Your logs do not go anywhere. The firewall keeps a few days, the server overwrites its own, and the cloud tenancy keeps whatever window your licence includes. You cannot investigate what was never recorded, and that gets discovered at the worst moment.

A contract asks for 24/7 monitoring. Ask any provider, us included, for staffed hours rather than monitoring hours. Software runs continuously nearly everywhere. People do not.

The question that decides everything

"At 2am, who is permitted to take a machine off the network without phoning me first, and at what severity?"

Agreed in daylight, containment takes minutes. Left undefined, it takes however long it takes to wake somebody who can decide, and that is the interval that determines how much of this you have to clean up.

What's included

Detection, and the response attached to it.

The first three items are what most services sell. The other five are what makes the first three worth having.

  • Log collection into one place (SIEM)

    A SIEM, security information and event management platform, gathers logs from identity, endpoints, email, firewalls and servers so they can be compared. An odd sign-in and an odd process on a laptop are one story when they sit side by side and two unrelated notes when they do not.

  • Detection tuned to your normal

    An alert only means something relative to what is usual for you. Overnight work in a different province is unremarkable for a construction company and worth a look for a single-office clinic. Tuning is a few weeks of work at the start and a standing item afterwards.

  • Human triage on a rota

    Analysts decide which detections matter and which are noise, so your team never sees the noise. A rota is what makes this possible; no individual can be the answer.

  • Containment authority, written and graded

    A short table: at this severity we isolate the device and tell you afterwards; at this one we disable the account first; at this one we always phone before acting. You approve it, and it is reviewed each quarter as your business changes.

  • Evidence preserved before anything is cleaned

    Isolating a machine rather than wiping it keeps what answers "how far did this reach". Insurers, regulators and clients all ask that question afterwards, and a rebuilt machine cannot answer it.

  • An incident response plan naming real people

    Who declares an incident, who speaks to staff, who calls the insurer and the lawyer, what clients are told and when. Contact details for all of them, kept somewhere reachable when your systems are not.

  • A report written for non-technical readers

    A timeline of what happened, what we did and when, what was affected, and what we recommend changing. Suitable to hand to a board, an insurer or a client without being rewritten first.

  • A review afterwards that changes something

    Every incident, including the small ones, produces one or two concrete changes: a rule, a permission, a process. A review that produces only a document has not finished.

How it works

Agree the rules, connect the sources, then rehearse.

The rehearsal is the part organizations skip, and it is the part that makes the first real incident calm.

  1. Decide what would count as an incident

    Before any technology, a short conversation about your business: which systems stopping would matter within an hour, which data would trigger a regulatory obligation, and who has authority to make decisions when the owner is on a plane. That shapes every severity below it.

  2. Connect the sources and set the authority

    Identity, endpoints, email, firewall and server logs into one place, retention set to a period you chose. Then the severity table and the containment authority, signed by you rather than assumed by us.

  3. Rehearse it once, on a quiet afternoon

    A tabletop exercise: we describe a scenario and your team talks through who does what, out loud, in order. It takes about ninety minutes, it reliably surfaces broken assumptions, two people who each assume the other calls the insurer, a plan stored on the server the scenario just took offline, and it is the cheapest item on this page.

What it costs

This is the managed security service, priced accordingly.

Detection without response is software. We price the combination, because separating them is how the useful half gets dropped from a budget.

Intrusion detection and response is delivered as part of happier IT’s managed security service

It is materially cheaper alongside managed IT, because the team responding already knows your environment and does not have to be briefed during an incident.

We do not price monitoring per alert or per gigabyte of logs. That model charges you more for having better visibility, which produces exactly the wrong decisions at budget time.

Ask what happens in hour one

Some providers sell detection and then quote hourly incident response when something happens, at rates set after you already have a problem.

Ask any provider whether response is inside the monthly fee, whether there is a cap on hours, and what the rate is beyond it.

Why us for this

The five stages, and who does each one.

Identify. Work out what actually happened and how far it reached, from the logs rather than from a guess. This is where retention decisions made a year earlier either help or hurt.

Contain. Stop it moving, isolate devices, disable accounts, block a sender, inside the authority you agreed, so the clock is not spent finding permission.

Remove. Take out what should not be there, including the quiet parts: an added second-factor method, a forwarding rule, a new account, a scheduled task.

Restore. Bring systems back in an order you set in advance, from backups verified to be clean rather than the most recent ones by default.

Report. To you first, in plain English, and where required to a regulator, insurer or client. Written by the people who did the work.

happier IT runs all five from its own security operations centre in Canada, staffed by our own employees, with Certified Ethical Hacker credentials on the team. Staffed hours: 24/7, with the Surrey office on Monday to Friday, 8:00 am to 5:00 pm Pacific. Time from detection to a person looking: minutes, not hours.

Go deeper

Questions

What people ask before they sign anything.

What is intrusion detection and response?

It is the practice of collecting activity data from across your systems, recognising the patterns that suggest something is wrong, and then acting on them under an agreed authority. The detection half is largely technology. The response half is people, a written process and permission granted in advance, which is why two services with identical software can differ enormously in what they are actually worth.

What is a SIEM?

A SIEM is a security information and event management platform: a system that collects logs from many sources into one place, keeps them for an agreed period, and applies rules that look for patterns across them. Its value is correlation. A failed sign-in means little; forty failed sign-ins followed by one success and a new mailbox rule is a sequence, and only a system holding all three can see it. More in our glossary entry.

How fast would you respond?

Faster inside staffed hours than outside them, and we will state both rather than implying a single number. Our target from detection to a human assessment is minutes, not hours, with staffed hours of 24/7, with the Surrey office on Monday to Friday, 8:00 am to 5:00 pm Pacific. Where automated containment is authorised, isolation happens in seconds regardless, because it does not wait for a person.

What happens in the first hour of an incident?

Containment comes before diagnosis. We isolate what needs isolating under the agreed authority, preserve the evidence rather than cleaning up, and call your named contact with what we know and what we do not. Then we work out scope. The order matters: organizations that investigate first and contain second spend the following week dealing with what spread during the investigation.

Do we need this if we already have EDR?

They cover different ground. Endpoint detection and response sees the device it is installed on, which is a lot but not everything: it cannot see a sign-in to your cloud tenancy from an unmanaged laptop, a mail forwarding rule, or unusual traffic through the firewall. Intrusion detection joins those sources together. If you have EDR and nothing else, adding log collection from identity and email is the highest-value next step.

What does intrusion detection and response cost?

When comparing quotes, the questions that explain most of the price difference are how many log sources are included, whether response is inside the fee or billed hourly when it happens, and whether the analysts are the provider’s own employees.

Want to know what this would look like for you?

A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.