Overview
Whether it's ransomware, a business email compromise, a data leak or a suspicious alert you can't explain, the first hours of an incident shape the outcome. Decisions about containment, evidence and communication made under pressure are hard to undo.
Our responders guide containment, coordinate investigation across endpoints, servers, cloud and email, and support eradication, recovery and hardening so the same path can't be used again. Deep forensic investigation and malware analysis are delivered by our Digital Forensics team as part of the response.
We provide clear reporting for leadership, insurers, legal counsel and regulators — including support for time-bound obligations such as CERT-In incident reporting in India.
What's included
Our approach
- EngageInitial call, scoping and immediate containment advice.
- PreserveCollection of logs, images and artefacts with chain of custody.
- InvestigateTimeline reconstruction, root cause and data-impact assessment.
- Eradicate & recoverRemoval of attacker access and safe restoration.
- LearnPost-incident report and prioritised improvement plan.
What you receive
- Incident timeline and root cause
- Containment and recovery actions
- Retainer onboarding pack
- Tabletop exercise reports
- Executive, technical and regulatory reports
Standards & frameworks
- NIST SP 800-61
- ISO/IEC 27035
- CERT-In directions (2022)
- GDPR Art. 33 / DPDP Act breach obligations
Frequently asked questions
We think we've been breached — what should we do first?
Avoid powering off affected systems or wiping evidence, isolate them from the network where possible, preserve logs, and contact us immediately using the details on our contact page.
Can you work with our cyber insurer?
Yes. We can coordinate with insurers and legal counsel and produce reports suited to claims and legal review.
Do you offer incident response retainers?
Yes. A retainer pre-agrees terms and onboarding so responders can start immediately when you need them.