Choosing an Incident Response Company for Email Compromise
September 16, 2026
What to ask a provider before you need one: response time, identity expertise, forensic depth, insurer relationships, and who actually does the work.
The worst time to choose an incident response provider is during an incident. Ten minutes of evaluation now saves a very bad day later.
Questions worth asking
How fast does a human answer, and who is it? Ask for the acknowledgement target and who picks up at 3am on a Sunday. Our commitment is a live answer 24/7 and acknowledgement within 15 minutes.
Do they actually work in identity and cloud? BEC is an identity incident. The team needs day-to-day fluency in Entra ID, conditional access, unified audit logs, Google Workspace admin forensics, and OAuth abuse — not just endpoint malware.
Can they prove what was accessed? Answering the notification question requires mailbox-level forensics, not just "we reset the password". Ask what evidence they produce and in what form.
Who employs the responders? Subcontracted labour introduces markup, scheduling gaps, and inconsistency. Our technicians are direct W-2 employees across more than 5,000 engineers, which is why we can put certified people on-site or remote quickly and keep the hard work in-house.
Do they work with carriers and counsel? Claims go badly when the vendor has never spoken to an adjuster. We are engaged both directly and through carriers, brokers, and breach counsel.
Can they cover restoration, not just investigation? Many incidents need mail flow rebuilt, endpoints reimaged, or infrastructure restored. A single accountable owner beats coordinating three firms.
What happens on day 30? Investigation without hardening guarantees a repeat. Look for a provider who can also run managed detection and response afterwards.
Retainer or not
A retainer buys pre-negotiated terms, a known escalation path, and often a faster start. Even without one, get the number into your phone and your playbook — not into the mailbox that may be compromised.
Ours is 1-844-LYRA-REC. Put it somewhere you can reach without email. Then see our business email compromise page for what the first call covers.
Business email compromised right now? Call 1-844-LYRA-REC — our incident commanders answer live 24/7 and start containment on the first call. See our business email compromise response page for the first-hour checklist.