Ransomware containment
Support isolation decisions, account protection, network restrictions, recovery-source protection and critical-service priorities.
Incident Response
Cyber incidents create pressure before the full picture is available. We help structure the response, contain confirmed activity, preserve evidence and make recovery decisions against clear technical criteria.
When to engage
Support may be appropriate when systems are encrypted, accounts appear compromised, critical services are unavailable, persistent malicious activity is detected or restored systems have not been validated.
Request Incident AssistanceResponse lifecycle
Containment should not erase the evidence needed to understand scope. Recovery should not restore the same access paths that enabled the incident.
Response workstreams
The exact work depends on business impact, available evidence and the condition of affected systems.
Support isolation decisions, account protection, network restrictions, recovery-source protection and critical-service priorities.
Examine artifacts and telemetry for execution, persistence, remote access, account use and movement between systems.
Review privileged access, authentication activity, Active Directory, Microsoft 365 and administrative changes.
Identify relevant sources, record collection details, calculate integrity hashes where appropriate and maintain an evidence register.
Define dependencies, clean-build expectations, credential rotation priorities, validation checks and reconnect criteria.
Provide situation updates, decision-ready technical briefings, documented limitations and executive reporting.
Identify control failures, response gaps and recovery constraints that require accountable follow-up.
Convert findings into sequenced action with owners, dependencies and measurable validation steps.
Starting inputs
Sensitive material is transferred only after an appropriate secure exchange method has been agreed.
Typical deliverables
Incident FAQ
Not in every case. Powering off may stop activity, but it can remove volatile evidence and affect critical services. Isolate where feasible, record the action and obtain incident-specific guidance before broad changes.
Yes, when the workstreams are coordinated. Recovery priorities, evidence needs, trusted administration and reconnect criteria should be agreed before systems return to production.
The investigation uses the evidence available and documents the resulting limitations. Conclusions are stated according to the strength and consistency of supporting sources.
Provide a short description, when it began, current operational impact and a safe callback method. Do not submit credentials, suspicious files or confidential evidence through the website.
Next step
Share the minimum operational details through the incident assistance form. Secure evidence exchange is arranged separately.