An agent emails the wrong list. An assistant leaks a file. An automation is hijacked. Most small firms have no plan for any of it, and no way to tell whether a person or the AI did it. We give you the plan, the kill switches and the evidence trail. Then we're on the end of the phone when it happens.
Your IT or cyber plan was written before AI agents could act on their own.
Nobody knows every place an agent is connected, or how to revoke its keys.
Logs don't separate human actions from AI actions.
Serious personal data breaches must be reported to the ICO within 72 hours. Could you work out what happened in time?
Cyber insurers increasingly ask about AI use and controls. “We don't know” is a bad answer.
If an AI sent something it shouldn't, who tells customers, and what do they say?
Incident response is a known discipline in security. The AI twist is that your “employee” may have acted thousands of times before anyone noticed. Speed and evidence matter more than ever.
Who does what, written down before it's needed.
| When | Who | Does |
|---|---|---|
| 0:00 | Anyone | Spots it · calls the owner |
| 0:05 | Owner | Runs the kill switch for that agent |
| 0:10 | Owner | Calls Eutaxis · opens the incident log |
| 0:20 | Eutaxis | Confirms the agent is stopped everywhere |
| 0:30 | Eutaxis + IT | Pulls the logs · AI actions vs human |
| 1:00 | Owner | Decides: ICO assessment? customers? |
Then the first day and the first week, on one page.
Set-up for a small firm takes two to three weeks. The drill is a two-hour session. The retainer runs from the day the plan is signed off.
Agent register, kill switches, logging and templates put in place. Roles agreed.
A tabletop exercise: we walk your team through a realistic AI incident and fix the gaps it shows.
When it happens, you call us. We help contain it, work out what happened, and support the reporting.
After the incident, a short review: what to change so it doesn't happen twice.
A recruitment agency's automation sent 400 candidates an email meant for one client, including a salary. With a plan, the owner stopped the flow in four minutes, we traced which records were touched within the hour, and the ICO assessment and the candidate notice went out the same day. Without a plan, that's a week of panic.
Illustrative example, drawn from typical findings. Not a named client.
“Access control is the part most AI suppliers wave at. It's the part we came from.”
Any time an AI agent or automation does something it shouldn't: sends the wrong thing, leaks or deletes data, takes an action nobody approved, or is taken over by someone outside. Also, a person using an AI tool in a way that exposes data.
Insurance pays some of the costs afterwards. It doesn't stop the agent, find the cause or write the ICO report, and most policies expect you to have reasonable controls in place. This gives you the controls and the evidence that you had them.
Being on call during agreed hours, a set number of response hours a year, the annual drill, and keeping your plan and register current as your AI use changes. Anything beyond that is quoted before we start.
Yes, and we'd rather. They know your systems; we know AI agents and identity. The plan says who does what.
No. Only personal data breaches likely to risk people's rights and freedoms must be reported, within 72 hours of becoming aware. Our template walks you through that assessment so you make the decision properly and record it.
The set-up is a fixed price after a free discovery call. The retainer is a monthly figure based on your size and the hours of cover you want.