Daniel-led operational intake
Cyber incident intake and escalation
This noindex page is the limited-capacity route to reach Daniel about urgent coordination. Any accepted engagement is contracted through Dead Simple Computing Ltd and delivered within its applicable insurance and governance controls. It does not promise continuous monitoring, guaranteed response or an NCSC-assured Cyber Incident Response service.
If an incident is happening now
The dedicated incident line is not currently accepting enquiries.
Do not use the ordinary contact form, general number or email for an active incident. Use the NCSC assured-provider directory for response support and the government reporting service where reporting is required.
Assurance boundary: Support reached through this route is not currently assured under the NCSC Cyber Incident Response scheme. The NCSC recommends assured providers for organisations seeking an independently assessed incident-response service.
Find an NCSC-assured incident response provider · Report a cyber incident
Scope of Daniel-led coordination
Within an agreed DSC remit I can help establish what is known, coordinate internal IT and external providers, maintain the incident timeline and decision record, support containment and recovery decisions, and identify what specialist help is required.
This is a single-adviser route. It is not presented as a 24-hour security operations centre, forensic laboratory, malware-analysis team or source of legal advice. Where specialist forensics, legal advice, insurer-appointed response or an NCSC-assured provider is needed, that requirement should be identified and the appropriate organisation engaged.
Dead Simple Computing's company incident-response service remains the service page for generic company incident-response enquiries. This page is a noindex intake route for work led personally by Daniel, not a separate provider or duplicate sales page.
Immediate actions
Every incident is different. Follow your incident plan and insurer requirements where they exist, and seek appropriate response support. The NCSC publishes current guidance on recovering from a highly disruptive cyber attack.
- Use a known-clean device and communication route if normal email, chat or identity systems may be compromised.
- Start a factual timeline of what was observed, when it was seen and every action authorised since.
- Preserve available logs, alerts and evidence. Avoid wiping or rebuilding systems until the response and evidence requirements are understood.
- Decisions to isolate or power down systems should balance containment, safety, business impact and evidence, with specialist advice where available.
- Consider insurer, legal, regulator and law-enforcement notification requirements without assuming that one report satisfies another.
Planning and post-incident work
The ordinary enquiry form can be used for incident planning, exercises, an independent review after an incident, or non-urgent follow-up. It must not be used to seek an urgent response or to send credentials, evidence or detailed incident information.
Discuss planning or a completed incident
For non-urgent work, give only a short outline and a safe way to reply. A suitable channel can be agreed before substantive incident material is shared.