Experiencing a security incident? Emergency Response

Emergency

In an active attack, the first minutes are decisive.

Ransomware, data breach, account takeover or suspicious activity. You can reach us even if you are not sure what is happening; we assess the situation with you and clarify the first steps.

Immediate response during business hours, within 2 hours outside them.

The first 60 minutes

The steps that matter until our team takes over

01

Isolation from the network

Affected systems are best disconnected from the network but left powered on; evidence in memory is lost on shutdown.

02

Preserving the records

Logs and backups are best left untouched, with no cleanup tools run. Timestamps are the map of the incident.

03

Narrowing access

Suspending suspicious accounts, temporarily restricting access to critical systems and changing passwords from a clean device are the right moves.

04

A single clean channel

Incident communication is best run over a known-clean channel instead of email. Once you reach us, we plan the rest together.

Our incident response team runs the full process of detection, scoping, root cause analysis and forensic evidence collection, and guides you through regulatory notification duties when needed. Details are available on the Incident Response & DFIR service page.

Let's build your defense together.

Whether a single penetration test or an end-to-end security program, let's clarify your needs in a 30-minute introductory call.