Company Partners Our Teams Contact Blog
Services
Industries
Talk to an expert
Incident Response

Security incident response: contain, investigate and recover.

Ransomware, data leaks, compromised accounts. Our team steps in to contain the attack, understand what happened and get your operations back up and running.

First hours

Incident in progress: what to do now

Your first decisions determine how much the attack will cost. Before anything else:

1 · Isolate, don't shut downDisconnect the affected devices from the network, but keep them powered on. Memory holds evidence of the attack.
2 · Preserve the evidenceDon't delete the ransom note, the logs or the suspicious emails. Take photos of the screens.
3 · Don't negotiate aloneDon't respond to the attacker or pay anything before you understand the scope of the incident.
4 · Call in the response teamCall 0800 073 2222. Change passwords only from a device that was not affected.
Situations we handle

From ransomware to compromised accounts

Ransomware

Data or systems held hostage. We contain the spread, identify the point of entry and support recovery from secure backups.

Data leak

Exposed or exfiltrated information. We determine what left, how and since when — the basis for the decisions and notifications required by the LGPD.

Compromised accounts and email

Unauthorized access, email fraud and suspicious activity. We cut off the attacker's access and determine how far they got.

How we work

A process to get out of the incident — and stay out

We follow the phases of the NIST incident response guide (SP 800-61), adapted to your environment.

ContainmentStop the attacker's activity and keep the incident from spreading.
InvestigationFind out how the attacker got in, what they accessed and which systems and data were affected.
Eradication and recoveryRemove the attacker from the environment and restore operations securely.
Post-incidentA report on what happened and the fixes needed to keep it from happening again.
LGPD

The notification clock starts ticking

When the incident involves personal data and may cause relevant risk or harm to data subjects, the controller must report it to the ANPD and the data subjects within three business days, as required by ANPD Resolution CD/ANPD No. 15/2024.

The notification requires information that only a technical investigation can provide: what happened, which data was affected, how many data subjects and what measures were taken. We deliver those answers so your legal team and your DPO can decide based on facts.

After the incident

So the next attack finds a different company

24×7 SOC and MDR

Continuous monitoring to detect and contain threats before they have an impact.

Vulnerability Management

Continuously close entry points, in order of risk.

Pentest

Test your defenses the way an attacker would, before they try.

Frequently asked questions

Frequently asked questions about incident response

Disconnect the affected devices from the network without shutting them down, preserve the evidence (ransom note, logs, suspicious emails) and call in the response team. Shutting down or formatting machines erases information that shows how the attacker got in.

Paying does not guarantee your data will be returned, nor does it prevent another attack. It is a decision for company leadership, with legal support, and should be made after understanding the scope of the incident and the recovery alternatives — never in a rush or without information.

If the incident involves personal data and may cause relevant risk or harm to data subjects, the controller must report it to the ANPD and the data subjects within three business days, under ANPD Resolution CD/ANPD No. 15/2024. The technical investigation provides the information this notification requires.

SOC/MDR continuously monitors the environment to detect and contain threats. Incident response is the focused work of containing, investigating and recovering once an incident has already happened. The two complement each other.

Incident in progress?

Call our Service Center now. The sooner containment starts, the less damage is done.

Call 0800 073 2222 →