Emergency
In an active attack, the first minutes are decisive.
Ransomware, data breach, account takeover or suspicious activity. You can reach us even if you are not sure what is happening; we assess the situation with you and clarify the first steps.
Immediate response during business hours, within 2 hours outside them.
The first 60 minutes
The steps that matter until our team takes over
Isolation from the network
Affected systems are best disconnected from the network but left powered on; evidence in memory is lost on shutdown.
Preserving the records
Logs and backups are best left untouched, with no cleanup tools run. Timestamps are the map of the incident.
Narrowing access
Suspending suspicious accounts, temporarily restricting access to critical systems and changing passwords from a clean device are the right moves.
A single clean channel
Incident communication is best run over a known-clean channel instead of email. Once you reach us, we plan the rest together.