When is a response needed?
Situations in which we help
The worst decisions after an incident result from haste and lack of procedure. We help you determine what needs to be disconnected, what should be secured, what should not be overwritten and what steps should be taken to avoid making the problem worse.
- Your email or Microsoft 365 account may have been compromised.
- The user clicked on a suspicious link or provided login details.
- The computer or server is exhibiting unusual processes, communications, or alerts.
- Data has been deleted, encrypted or a ransom demand has been made.
- A company needs a remediation plan when a vulnerability or configuration error is discovered.
Fit
Who is this service for?
Companies without their own security team
We help you make your first decisions and organise further actions.
Companies with an IT administrator
We support the administrator with analysis, second opinions and a specific recovery plan.
Companies after phishing
We check accounts, email and login rules and the possible scope of attacker access.
Companies after a disaster or ransomware
We help you evaluate your copies, isolate your environment, and plan for a safe recovery.
Service scope
What does incident response involve?
First rating
We determine what happened and which areas may be at risk.
- description of symptoms and timeline,
- system priorities,
- risk of further spread.
Limiting the effects
We help stop escalation without destroying traces.
- blocking of accounts and sessions,
- device insulation,
- changing passwords and tokens.
Technical analysis
We are reviewing available data to understand the scope of the problem.
- Microsoft 365 and system logs,
- email rules and delegations,
- endpoint and firewall alerts.
Recovery plan
We provide the actions needed to return and strengthen the environment.
- data recovery,
- removing vulnerabilities,
- organisational and technical recommendations.
Outcomes
What will you receive?
- a structured assessment of the situation and the possible scope of the incident,
- actions to reduce further risk to accounts, devices and data,
- indication of information needed for further analysis,
- a safe return to work or environmental recovery plan,
- recommendations that will reduce the risk of a similar event.
The scope depends on the situation. A mailbox takeover is different, ransomware is different, and an incorrect configuration exposing data is different.
Delivery approach
How is the service delivered?
- Report. We collect symptoms, time of event and available information.
- Stabilisation. We limit the risk of further access or loss of data.
- Analysis. We check logs, accounts, devices and visible traces.
- Decisions. We decide what to play, what to block and what to communicate.
- Repair. We help in restoring systems and removing the causes.
- Conclusions. We provide recommendations, documentation and a security plan.
Reaction standard
How do we limit the damage?
- We do not delete diagnostic traces unnecessarily.
- First, we limit further access, then we plan a full clean-up.
- We document decisions so that after the incident it is known what was done.
- We separate quick rescue actions from subsequent developmental changes.
- After the incident, we point out specific security measures that need to be improved.
Cost
What determines the price?
The price depends on the type of incident, number of systems, availability of logs, scale of the environment, need for data recovery, response time and the scope of documentation and corrective actions.
FAQ
Frequently asked questions
What should you do first when you suspect an incident?
It's best not to act chaotically. It's a good idea to secure information, disconnect vulnerable items only when it makes sense, and quickly determine the extent of the risk.
Can you help with a compromised email account?
Yes. We check logins, rules, sessions, delegations and help you regain control over your account.
Will you recover data from ransomware?
We can help you evaluate your backups, encryption coverage and recovery plan, but the outcome depends on the condition of the backup and the extent of the damage.
Will you prepare a post-incident report?
We can prepare a description of the event, actions taken, risks and corrective recommendations.
Do you also help after the incident?
Yes. Once the environment is stabilised, we can implement security, monitoring and preventive procedures.