Ransomware, data leaks, compromised accounts. Our team steps in to contain the attack, understand what happened and get your operations back up and running.
Your first decisions determine how much the attack will cost. Before anything else:
Data or systems held hostage. We contain the spread, identify the point of entry and support recovery from secure backups.
Exposed or exfiltrated information. We determine what left, how and since when — the basis for the decisions and notifications required by the LGPD.
Unauthorized access, email fraud and suspicious activity. We cut off the attacker's access and determine how far they got.
We follow the phases of the NIST incident response guide (SP 800-61), adapted to your environment.
When the incident involves personal data and may cause relevant risk or harm to data subjects, the controller must report it to the ANPD and the data subjects within three business days, as required by ANPD Resolution CD/ANPD No. 15/2024.
The notification requires information that only a technical investigation can provide: what happened, which data was affected, how many data subjects and what measures were taken. We deliver those answers so your legal team and your DPO can decide based on facts.
Continuous monitoring to detect and contain threats before they have an impact.
Continuously close entry points, in order of risk.
Test your defenses the way an attacker would, before they try.
Disconnect the affected devices from the network without shutting them down, preserve the evidence (ransom note, logs, suspicious emails) and call in the response team. Shutting down or formatting machines erases information that shows how the attacker got in.
Paying does not guarantee your data will be returned, nor does it prevent another attack. It is a decision for company leadership, with legal support, and should be made after understanding the scope of the incident and the recovery alternatives — never in a rush or without information.
If the incident involves personal data and may cause relevant risk or harm to data subjects, the controller must report it to the ANPD and the data subjects within three business days, under ANPD Resolution CD/ANPD No. 15/2024. The technical investigation provides the information this notification requires.
SOC/MDR continuously monitors the environment to detect and contain threats. Incident response is the focused work of containing, investigating and recovering once an incident has already happened. The two complement each other.
Call our Service Center now. The sooner containment starts, the less damage is done.