About Expertise Work Managed Apps
Business Website Online Store Sales CRM Team Drive Online Academy Newsletter System Booking System Shared Inbox Knowledge Base Short Links Business Manager Photo Gallery Survey Platform Community Forum Project Boards Estate Agency Car Workshop Restaurant Clinic Photography Studio
AWS
Assess & advise Build & migrate Automate & operate Secure & comply Urgent & go-live
Projects
Hosted Monitoring & Dashboards Self-Hosted Observability Stack Bulk Document Data Extraction Email Deliverability Diagnosis & Repair SEO Migration Recovery AWS Security Review VPS Hardening & ModSecurity Cloud Architecture & Resilience Review SSL & Server Configuration Container Security Review DNS & Email Troubleshooting DevOps Deployment & Rollback Review WordPress Hardening Retainer Data Pipeline Rerun Review Metric Reconciliation
Free Tools
Website Health Check Email Domain Health Check DNS Health Check SSL Certificate Checker Redirect Chain Checker Robots.txt Checker XML Sitemap Validator Docker Compose Checker WordPress Security Check AWS IAM / S3 Policy Checker Domain Registration Lookup Uptime Monitoring Trial Downtime Cost Calculator AWS Cost Estimator Cloud Architecture Self-Assessment DevOps Engagement Builder Self-Managed VPS vs Managed AWS
Blog Certifications Hire Me

Emergency AWS Incident Response

Something is down, burning money or possibly compromised. A flat triage fee, then hourly.

Price and scope

$249

Same day–2 days
Working days, counted from the moment I have access — not from the day you agree.

What moves it up

  • Nothing changes the triage fee — it is flat, and it covers the first two hours
  • Beyond that it is hourly, at a rate stated before the work continues
  • Outside the coverage window it is a higher hourly rate, and it is best effort rather than a promise

Some of this you can check yourself, right now, for free: Website Health Check →

The first hour of an incidentA timeline from an outage starting. Four repair attempts are made in quick succession with no record kept, so when the symptoms change nobody can say which change caused it. A written change log, kept from the first minute, preserves the diagnosis.it goes downhelp arrivesrestarted itrolled backresized the DBcleared the cachenone of it written downa written change log, from minute onethe fix is quick. reconstructing what you already tried is not.
Emergency AWS Incident Response

What actually goes wrong

The expensive part of an incident is almost never the fix. It is the first hour, spent changing things — restarting instances, rolling back a deploy, resizing a database — in an order nobody is recording, so that when something does help, nobody can say which change it was. By the time an experienced pair of hands arrives, the evidence of what actually happened has been overwritten by the attempts to repair it, and a fifteen-minute diagnosis has become an afternoon.

How I find it

  • CloudTrail for the last few hours first, before touching anything — what changed, and when
  • The alarm history, to establish when it actually started rather than when it was noticed
  • A written change log from the moment I join, so the repair does not destroy the diagnosis
  • Read-only access to look, and write access only when there is something specific to do with it

What you get

  • A stated cause, or a stated best hypothesis with what would confirm it — never a vague reassurance
  • The immediate mitigation, and whether it is a fix or something holding until Monday
  • A written timeline of what happened and what was changed, including by you before I arrived
  • The two or three things that would stop it recurring, quoted separately and not sold in the moment

Questions

What are your actual response hours?

Sunday to Thursday, 09:00 to 18:00 EET. Outside that I will look if I see the message and the rate is higher, but it is best effort and I will not pretend it is anything else. If you need guaranteed cover at 3am, you need a team, and I would rather say so now than during your outage.

What does the triage fee actually get me?

The first two hours: access, orientation, and a stated cause or a hypothesis with a way to test it. Most incidents are diagnosed inside that. Anything beyond continues hourly, agreed with you at the point it becomes necessary rather than added to an invoice afterwards.

I think we have been compromised. Can you help?

For the AWS side — containing access, rotating credentials, reading the trail, establishing what was reached — yes. Formal forensics and anything that has to stand up legally is a specialist discipline and I will tell you to get one rather than improvise. Do not delete anything before we talk.

Is it cheaper if I already have a plan with you?

Yes. On the Business and Advanced plans, incident assistance inside the coverage window is included rather than charged, because by then I already know the environment — which is most of what the triage fee is buying here.

AWS Monitoring & Alerting

Alerts that fire when customers are affected, and stay quiet the rest of the time.

From $299 2–4 days

Want this done?

Tell me what you are running and I will come back with a fixed price and a date. If it turns out you do not need this, I will say that instead.

Prefer to talk? Book a free call ↗  ·  Or hire me on Upwork ↗  ·  Typical reply within one business day.

When I answer

Sunday to Thursday, 09:00–18:00 EET. Outside that I will still look, but I will not promise a time.

No 24/7 desk, and I will not pretend otherwise

One person, one time zone. If round-the-clock cover is what you need, you need a team, and I will say so rather than sell you a plan that cannot deliver it.

Your AWS bill stays yours

You pay Amazon directly and you keep control of the account. Nothing here resells your infrastructure or sits between you and your own billing.

A price that starts with "from" is a starting price

Every service page lists exactly what pushes a quote above it, before you ask. You get a fixed number in writing before any work begins.