Home/IT Security/Incident forensics

03 · IT Security

Incident forensics

Has your organization been hit by an attack? We secure the evidence, establish how it happened and how far it went, support containment and recovery, and deliver a report you can give to your board, your regulator and your insurer.

24/7incident hotline
1 hto first decisions
72 hGDPR / NIS2 reporting deadline

Service details

Find out what happened — and make sure it cannot happen again

If you have landed here after a security incident wondering what to do next, that is exactly the question our experts answer every day. Incident forensics finds the root cause, shows which parts of your infrastructure were compromised and secures the evidence — before the traces disappear.

Time matters. Logs rotate, memory is lost at shutdown and attackers clean up after themselves. The earlier the analysis starts, the more we can prove — and the sooner you know whether the intruder is still inside.

  • 24/7 incident hotline and triage within the hour
  • Evidence secured with a documented chain of custody
  • Technical facts ready for GDPR, NIS2 and DORA notifications
IT Security
Incident in progress? Call us before you reinstall anything.

Every hour matters, and the most common mistake is destroying the evidence while trying to clean up. Our incident hotline is open 24/7 — we start with triage, tell you what to secure first and take over the technical side of the response.

Report an incident

What to do in the first hour

Do

  • Disconnect affected machines from the network — but leave them powered on, so memory evidence survives
  • Preserve logs: firewall, VPN, domain controllers, mail, EDR — before retention rotates them out
  • Write down a timeline: who noticed what and when, what was changed already
  • Reset credentials of privileged accounts from a clean device
  • Check whether your backups are intact and offline
  • Involve legal and management early — reporting deadlines start running immediately

Don't

  • Don't reinstall or wipe systems "to get back up quickly" — you erase the evidence with the attacker's traces
  • Don't run antivirus cleanups across the environment before the scope is known
  • Don't log in with domain administrator accounts on suspect machines
  • Don't restore from backup before you know how the attacker got in
  • Don't negotiate or pay a ransom without technical and legal assessment
  • Don't communicate about the incident through systems that may be compromised

Scope

What our analysis covers

Evidence acquisition

Forensically sound disk images, memory dumps, log copies and cloud audit exports — collected with a documented chain of custody.

Attack vector

How the attacker got in: phishing, an exposed service, stolen credentials, a vulnerability or a supplier's access.

Timeline reconstruction

A minute-by-minute picture of the intrusion: initial access, lateral movement, privilege escalation and persistence.

Malware analysis

What was executed, what it did and what it communicated with — including indicators you can block everywhere else.

Data exfiltration

Whether data left the organization, which data, how much — and whether it has already surfaced on the public internet or leak sites.

Scope of compromise

Which systems, accounts and backups were touched — so recovery does not restore the attacker along with the data.

Containment and recovery

Support in cutting the attacker off, rebuilding clean systems and returning to normal operations safely.

Report and evidence package

Documentation for the board, the regulator, your insurer and, if you decide to file, for law enforcement.

Hardening and detections

Concrete recommendations and new detection rules, so the same path cannot be used twice.

What we analyze

Workstations and serversWindows event logsLinux logs and artefactsActive Directory / Entra IDMicrosoft 365 and mailFirewall, proxy and VPNEDR telemetryNetwork captures and NetFlowCloud audit logsBackup systemsWeb servers and applicationsMemory dumps

How we work

From the first call to a closed case

STEP 1

Triage

A call within the hour: what happened, what is still running, what to secure right now and what not to touch.

STEP 2

Evidence

Images, memory, logs and exports collected before they disappear, with documentation of who collected what and when.

STEP 3

Analysis

Vector, timeline, scope, malware and exfiltration — with interim findings passed to you as soon as they are confirmed.

STEP 4

Containment

Cutting off access, cleaning or rebuilding systems and restoring operations from verified, clean copies.

STEP 5

Report

Findings for the board and the technical team, evidence package, recommendations and new detection rules.

Work can start remotely within hours; on-site acquisition is arranged where the evidence requires it.

Obligations

Reporting deadlines you need to meet

An incident is not only a technical problem. Depending on your sector and the data involved, the clock starts running the moment you become aware of it. We deliver the technical facts in a form your lawyers and management can act on — and we do it fast enough to make the deadlines.

RegimeDeadlineWhat is reported
GDPR72 hoursPersonal data breach notified to the supervisory authority; affected people informed when the risk is high
NIS2 / KSC 2.024 h / 72 h / 1 monthEarly warning, incident notification with assessment, final report — see NIS2 audit
DORA4 h / 72 h / 1 monthMajor ICT incident reported to the financial supervisor — see DORA audit
InsurerPer policyNotification and evidence required for a cyber insurance claim
Law enforcementYour decisionEvidence package prepared so it can be handed over if you file a report

We provide the technical part of the notifications. Legal assessment and the decision to notify stay with your lawyers and management — we work alongside them.

Ransomware

If your files are already encrypted

Ransomware is the most common reason clients call us. The order of work matters: first we establish how the attacker got in and whether they still have access, then we check which copies of your data are clean, and only then do we restore. Restoring first — without knowing the vector — usually means being encrypted again within days.

  • Identification of the ransomware family and check whether a legitimate decryptor exists
  • Assessment of which backups are intact, offline or immutable
  • Search for the persistence the attacker left behind before any restore
  • Assessment of data exfiltration and the risk of publication on leak sites
  • Rebuild plan with a clean-room approach for critical systems
  • Support for management in the decision on contact with the attacker, together with your legal counsel

Prevention side: immutable copies and tested restores in backup and disaster recovery, plus 24/7 monitoring by our SOC.

Deliverables

What you receive

Executive summary

What happened, what the impact is and what must be decided — in language the board and the regulator can read.

Technical report

Vector, timeline, affected systems and accounts, malware analysis and evidence for every conclusion.

Indicators of compromise

Hashes, addresses, domains and techniques, ready to block and to hunt for across the rest of your environment.

Evidence package

Secured images and logs with chain-of-custody documentation, retained for as long as you need them.

Recommendations

Prioritized actions: what to fix today, what within a month and what belongs in next year's budget.

Detection rules

New rules and use cases for your SIEM, so the same technique triggers an alert next time — see threat hunting.

Not sure which option to choose?

A 30-minute call with an engineer — we'll outline the scope and ballpark budget, with no sales pitch.

Book a consultation

Questions and answers

Incident forensics FAQ

What is incident forensics?

It is the investigation of a security incident: securing evidence, establishing how the attacker got in, what they did, which systems and data were affected — and producing a report with recommendations that prevents a repeat.

How quickly can you start?

Our incident hotline is open 24/7 and we begin with triage within the hour: what to isolate, what to preserve and what not to touch. Remote analysis usually starts the same day; on-site acquisition is arranged where it is needed.

Should we shut the affected machines down?

No. Disconnect them from the network but leave them powered on — a large part of the evidence lives only in memory and disappears at shutdown. If a machine must be turned off for safety reasons, tell us first so we can plan around it.

Can we restore from backup right away?

Not before the vector is known. Restoring into an environment the attacker still controls — or restoring a copy that already contains their tools — is the most common reason companies get hit twice within a week.

Will you tell us whether data was stolen?

We assess exfiltration based on network, proxy, cloud and endpoint evidence, and we check whether the data has appeared on leak sites. Where evidence is missing — for example logs were already rotated — we say so plainly instead of guessing.

Do you help with the notification to the authorities?

Yes, with the technical content: what happened, when, what was affected and what the impact is, in the form required by GDPR, NIS2 or DORA. The legal assessment and the decision to notify remain with your lawyers and management.

Is the report usable in court or for an insurance claim?

We work with a documented chain of custody and keep the evidence package, so the material can be handed to law enforcement or an insurer. Whether to file a report or a claim is your decision, taken with your legal counsel.

Should we pay the ransom?

That is a business and legal decision, not a technical one — and it should never be taken before the analysis. We first check for a legitimate decryptor, assess which backups are clean and evaluate the exfiltration risk, so the decision is made with facts on the table.

How long does an investigation take?

Triage and first findings usually within days; a full analysis depends on the size of the environment and the telemetry available. You receive interim findings as soon as they are confirmed, not only at the end.

What if we have no logs or EDR?

We work with what exists — disk and memory artefacts often tell the story even without central logs. We will also tell you exactly which sources to start collecting, so the next investigation takes hours instead of weeks.

What happens after the investigation?

You get prioritized hardening recommendations and new detection rules. Many clients then add continuous monitoring with our SOC, periodic threat hunting and penetration tests to verify the fixes.

First step

Let's talk about incident forensics.

30 minutes, no slide deck. We'll tell you straight whether this service solves your problem, what scope makes sense and how much it costs.

Book a consultation

A proposal with scope and pricing within 48 hours of the call.

Go to contact