● ALL SYSTEMS OPERATIONAL* · Updated 09 Aug 2026 08:40 UTC* Emergency line limitations apply
Operational security portal / demonstration

Report early. Respond with context.

Use this desk to check service status, review current advisories and begin a secure incident-response conversation. Do not submit credentials, malware, personal data or confidential evidence through a public form.

INITIAL INCIDENT ROUTE Public intake
Expected illustrative acknowledgement: within 30 minutes for contracted critical incidents*. This form does not establish an SLA or emergency service.
Service status / sample Maintained data requires owner, timestamp and archive.
Incident intake ● Operational*
Advisory feed ● Operational*
Customer portal ● Operational*
Threat telemetry ● Operational*
Current notices / examples

Advisories with revision history.

Replace every illustrative identifier, status and date with verified maintained information before publication.

Credential replay observed against remote-access services

Action recommended Rev 2

Review internet-exposed administration interfaces

Monitoring Rev 1

Third-party email delivery degradation

Resolved Rev 4
Severity language

A score needs a method and context.

State the scoring system, vector, affected versions, exploit evidence, remediation and update date. A numeric score alone is not a response plan.

LOW

Limited impact under described conditions.

MEDIUM

Meaningful impact requiring planned review.

HIGH

Significant impact and prioritized remediation.

CRITICAL

Severe impact under verified applicable conditions.

Response sequence

Containment is not the whole incident.

Actual sequence changes with safety, scope, evidence and business continuity. Preserve records and involve qualified responders.

00–30* Acknowledge, authenticate the contact and establish a secure channel
TRIAGE Confirm observed facts, business impact, affected scope and immediate safety
CONTAIN Choose reversible actions with evidence and operational consequences in view
RECOVER Validate clean state, restore deliberately and monitor agreed indicators
LEARN Document chronology, decisions, root contributors and owned improvements
Preparation playbooks

Useful before an alert arrives.

01

Account compromise

Identity validation, session review, access revocation, evidence retention and communications.

Open overview →
02

Ransomware readiness

Authority, isolation decisions, backup evidence, legal routes and safe restoration.

Open overview →
03

Supplier incident

Dependencies, notification routes, shared evidence, contract scope and continuity options.

Open overview →
Trust information

Claims scoped to the right entity.

Certifications, audits and controls must identify the legal entity, covered services, period, auditor and exclusions.

Legal entity* Cobalt Security Desk Ltd / demonstration
Service scope* Managed detection and incident-response examples
Data region* Illustrative EU processing region
Last review* 09 August 2026 / replace with evidence
Urgent contact

An active incident needs a verified route.

For immediate danger or crime, contact the appropriate local emergency authority. Cobalt is not an emergency service.

CONTRACTED RESPONSE / SAMPLE +44 20 8000 9911* [email protected] Authenticate contacts before sharing sensitive information.