Description
Sophos Emergency Incident Response
Emergency Incident Response puts the Sophos digital forensics and incident response team on an active attack. It covers investigation, containment and the forensic work that follows, whether or not you run Sophos products.
If an attack is in progress, do not wait on a purchase order. Call us and we will engage Sophos DFIR directly. This listing exists so the service is visible and quotable, but an active incident is a phone call, not a checkout.
What the team does
- Captures digital evidence from affected endpoints and systems of interest.
- Analyzes it forensically to identify indicators of compromise and trace adversary activity.
- Reviews telemetry for ongoing or previous threats beyond the incident that triggered the call.
- Performs malware analysis, static and dynamic, on anything found.
- Delivers a written or verbal summary with a timeline of key events and the indicators identified.
Engagement types under DFIR
The wider DFIR service covers engagement management, incident response, digital forensics, business email compromise, compromise assessment, threat hunting, threat intelligence and research, and ransom negotiation. Which of those applies is established during the first call.
What Sophos needs from you
Administrative privileges, log and forensic data from the systems in scope, deployment of the service software where applicable, and up to three named people to support delivery. Response moves at the speed of that access, so agreeing it in advance is worth doing before you need it.
Frequently asked questions
Do I need to be a Sophos customer?
No. Emergency Incident Response is available whether or not you run Sophos products.
How quickly does it start?
The team operates 24/7 and works remotely. Response speed depends on how quickly access and evidence can be provided, which is why organizations with a retainer in place move faster.
Can I lock in response ahead of time?
Yes. The Sophos Security Services Retainer guarantees DFIR access with defined SLAs and pre-negotiated hourly rates, rather than negotiating under pressure mid-incident.
Does it cover ransom negotiation?
Ransom negotiation is one of the DFIR engagement types, alongside forensics, threat hunting and business email compromise investigation.
Arrange this through Nuformat
Nuformat is a Sophos partner serving Canada and the United States. Tell us your environment size and what prompted the enquiry, and we will scope the engagement and come back with a quote, usually in two to three business days.
Request a quoteService scope and delivery as published by Sophos. Pricing confirmed by Nuformat at the time of quotation.

