Incident and ransomware response
Bring structure to disruptive events while containment, evidence preservation, investigation and business recovery move in parallel.
When to engage
Systems are encrypted or unavailable, privileged accounts appear compromised, critical services are disrupted, or the extent of an incident remains unclear.
What we assess
Affected assets, identity activity, available logs, current attacker access, containment options, recovery sources and operational dependencies.
How it works
We establish an incident structure, confirm priorities, preserve relevant evidence, support containment and coordinate investigation with recovery.
What you receive
- Incident action plan
- Situation updates
- Evidence register
- Recovery criteria
- Technical and executive reports
Expected outcome: A controlled incident, a defensible understanding of what occurred and clear criteria for returning systems to service.