03 · IT Security
Has your organization been hit by an attack? We secure the evidence, establish how it happened and how far it went, support containment and recovery, and deliver a report you can give to your board, your regulator and your insurer.
Service details
If you have landed here after a security incident wondering what to do next, that is exactly the question our experts answer every day. Incident forensics finds the root cause, shows which parts of your infrastructure were compromised and secures the evidence — before the traces disappear.
Time matters. Logs rotate, memory is lost at shutdown and attackers clean up after themselves. The earlier the analysis starts, the more we can prove — and the sooner you know whether the intruder is still inside.
Every hour matters, and the most common mistake is destroying the evidence while trying to clean up. Our incident hotline is open 24/7 — we start with triage, tell you what to secure first and take over the technical side of the response.
Scope
Forensically sound disk images, memory dumps, log copies and cloud audit exports — collected with a documented chain of custody.
How the attacker got in: phishing, an exposed service, stolen credentials, a vulnerability or a supplier's access.
A minute-by-minute picture of the intrusion: initial access, lateral movement, privilege escalation and persistence.
What was executed, what it did and what it communicated with — including indicators you can block everywhere else.
Whether data left the organization, which data, how much — and whether it has already surfaced on the public internet or leak sites.
Which systems, accounts and backups were touched — so recovery does not restore the attacker along with the data.
Support in cutting the attacker off, rebuilding clean systems and returning to normal operations safely.
Documentation for the board, the regulator, your insurer and, if you decide to file, for law enforcement.
Concrete recommendations and new detection rules, so the same path cannot be used twice.
How we work
A call within the hour: what happened, what is still running, what to secure right now and what not to touch.
Images, memory, logs and exports collected before they disappear, with documentation of who collected what and when.
Vector, timeline, scope, malware and exfiltration — with interim findings passed to you as soon as they are confirmed.
Cutting off access, cleaning or rebuilding systems and restoring operations from verified, clean copies.
Findings for the board and the technical team, evidence package, recommendations and new detection rules.
Work can start remotely within hours; on-site acquisition is arranged where the evidence requires it.
Obligations
An incident is not only a technical problem. Depending on your sector and the data involved, the clock starts running the moment you become aware of it. We deliver the technical facts in a form your lawyers and management can act on — and we do it fast enough to make the deadlines.
| Regime | Deadline | What is reported |
|---|---|---|
| GDPR | 72 hours | Personal data breach notified to the supervisory authority; affected people informed when the risk is high |
| NIS2 / KSC 2.0 | 24 h / 72 h / 1 month | Early warning, incident notification with assessment, final report — see NIS2 audit |
| DORA | 4 h / 72 h / 1 month | Major ICT incident reported to the financial supervisor — see DORA audit |
| Insurer | Per policy | Notification and evidence required for a cyber insurance claim |
| Law enforcement | Your decision | Evidence package prepared so it can be handed over if you file a report |
We provide the technical part of the notifications. Legal assessment and the decision to notify stay with your lawyers and management — we work alongside them.
Ransomware
Ransomware is the most common reason clients call us. The order of work matters: first we establish how the attacker got in and whether they still have access, then we check which copies of your data are clean, and only then do we restore. Restoring first — without knowing the vector — usually means being encrypted again within days.
Prevention side: immutable copies and tested restores in backup and disaster recovery, plus 24/7 monitoring by our SOC.
Deliverables
What happened, what the impact is and what must be decided — in language the board and the regulator can read.
Vector, timeline, affected systems and accounts, malware analysis and evidence for every conclusion.
Hashes, addresses, domains and techniques, ready to block and to hunt for across the rest of your environment.
Secured images and logs with chain-of-custody documentation, retained for as long as you need them.
Prioritized actions: what to fix today, what within a month and what belongs in next year's budget.
New rules and use cases for your SIEM, so the same technique triggers an alert next time — see threat hunting.
A 30-minute call with an engineer — we'll outline the scope and ballpark budget, with no sales pitch.
Questions and answers
It is the investigation of a security incident: securing evidence, establishing how the attacker got in, what they did, which systems and data were affected — and producing a report with recommendations that prevents a repeat.
Our incident hotline is open 24/7 and we begin with triage within the hour: what to isolate, what to preserve and what not to touch. Remote analysis usually starts the same day; on-site acquisition is arranged where it is needed.
No. Disconnect them from the network but leave them powered on — a large part of the evidence lives only in memory and disappears at shutdown. If a machine must be turned off for safety reasons, tell us first so we can plan around it.
Not before the vector is known. Restoring into an environment the attacker still controls — or restoring a copy that already contains their tools — is the most common reason companies get hit twice within a week.
We assess exfiltration based on network, proxy, cloud and endpoint evidence, and we check whether the data has appeared on leak sites. Where evidence is missing — for example logs were already rotated — we say so plainly instead of guessing.
Yes, with the technical content: what happened, when, what was affected and what the impact is, in the form required by GDPR, NIS2 or DORA. The legal assessment and the decision to notify remain with your lawyers and management.
We work with a documented chain of custody and keep the evidence package, so the material can be handed to law enforcement or an insurer. Whether to file a report or a claim is your decision, taken with your legal counsel.
That is a business and legal decision, not a technical one — and it should never be taken before the analysis. We first check for a legitimate decryptor, assess which backups are clean and evaluate the exfiltration risk, so the decision is made with facts on the table.
Triage and first findings usually within days; a full analysis depends on the size of the environment and the telemetry available. You receive interim findings as soon as they are confirmed, not only at the end.
We work with what exists — disk and memory artefacts often tell the story even without central logs. We will also tell you exactly which sources to start collecting, so the next investigation takes hours instead of weeks.
You get prioritized hardening recommendations and new detection rules. Many clients then add continuous monitoring with our SOC, periodic threat hunting and penetration tests to verify the fixes.
Related services
First step
30 minutes, no slide deck. We'll tell you straight whether this service solves your problem, what scope makes sense and how much it costs.
A proposal with scope and pricing within 48 hours of the call.
Go to contact