Overview
Whether it's ransomware, a business email compromise, a data leak or a suspicious alert you can't explain, the first hours of an incident shape the outcome. Decisions about containment, evidence and communication made under pressure are hard to undo.
Our responders guide containment, preserve and analyse evidence across endpoints, servers, cloud and email, analyse malware samples to understand capability and indicators of compromise, and reconstruct the attacker's timeline. We then support eradication, recovery and hardening so the same path can't be used again.
We provide clear reporting for leadership, insurers, legal counsel and regulators — including support for time-bound obligations such as CERT-In incident reporting in India.
What's included
Our approach
- EngageInitial call, scoping and immediate containment advice.
- PreserveCollection of logs, images and artefacts with chain of custody.
- InvestigateTimeline reconstruction, root cause and data-impact assessment.
- Eradicate & recoverRemoval of attacker access and safe restoration.
- LearnPost-incident report and prioritised improvement plan.
What you receive
- Incident timeline and root cause
- Indicators of compromise (IOCs)
- Data-impact assessment
- Executive and technical reports
- Post-incident improvement roadmap
Standards & frameworks
- NIST SP 800-61
- ISO/IEC 27035
- CERT-In directions (2022)
- GDPR Art. 33 / DPDP Act breach obligations
Frequently asked questions
We think we've been breached — what should we do first?
Avoid powering off affected systems or wiping evidence, isolate them from the network where possible, preserve logs, and contact us immediately using the details on our contact page.
Can you work with our cyber insurer?
Yes. We can coordinate with insurers and legal counsel and produce reports suited to claims and legal review.
Do you offer incident response retainers?
Yes. A retainer pre-agrees terms and onboarding so responders can start immediately when you need them.