AI incident response

We respond to incidents involving AI systems: stolen or tampered models, poisoned training data, prompt injection exploits and deepfake-enabled fraud. We contain the damage, run the forensics, and help you restore the system hardened.

When AI fails, it fails differently.

A poisoned model or a prompt injection exploit leaves different evidence from a typical breach, and the usual incident playbook doesn't say where to look. We know which logs, model artifacts and data pipelines to examine, and we work through them while the incident is still live.

Incidents we handle

Model compromise

Containment and investigation when a model is stolen, tampered with or quietly manipulated.

Data poisoning

Find the poisoned training data that changed the model's behavior, remove it, and confirm the fix.

Deepfake incidents

Response to deepfake-enabled fraud, executive impersonation and disinformation aimed at your organization.

AI system forensics

Forensic analysis of models, prompts, logs and pipelines to establish what the attacker reached and, where the evidence allows, who they were.

Adversarial attacks

Investigation of evasion attacks, prompt injection exploits and other attacks on model inputs.

Recovery and hardening

Put the system back into service with the changes needed to stop the same attack working twice.

How we respond

From the first call to the post-incident review.

01

Triage

Establish the scope and severity of the incident and what needs containing first.

02

Containment

Isolate the affected AI systems to stop further damage or data exposure.

03

Forensic analysis

Examine model artifacts, logs and model behavior to work out what happened.

04

Impact assessment

Determine how far the compromise reached, including downstream systems that consume the model's output.

05

Remediation

Remove the attacker's access, restore clean models and data, and make the first security fixes.

06

Post-incident review

A written account of the incident, what it taught you, and what to change next.

Dealing with a compromised AI system right now?

Tell us what the model or application is doing and what it has access to. Our team is available 24/7.