Under attack? Act now.
Every minute an attacker keeps access, the damage compounds. Report the incident and it lands in front of the response team immediately — flagged urgent, ahead of everything else.
Report an active incident
Tell us only what you safely can — we’ll take it from there.
While you wait: incident first aid
The first hour decides how much evidence survives and how far the attacker gets. These hold for almost every incident.
Do
- Disconnect affected machines from the network — but leave them powered on (memory is evidence)
- Preserve logs, alerts and screenshots; note times of everything you saw
- Move your team's coordination to a channel the attacker can't read (personal phones beat company email)
- Reset credentials from a known-clean device, starting with admin and email accounts
- Tell leadership and, if you have them, your insurer and counsel — early
Don’t
- Don't wipe, reimage or "clean up" compromised systems yet — you'd destroy the evidence that shows what happened
- Don't pay a ransom before getting advice — payment rarely ends the incident
- Don't discuss the incident over possibly-compromised email or chat
- Don't mass-delete attacker accounts or files the moment you spot them — coordinated eviction beats whack-a-mole
- Don't announce anything publicly before you know what actually happened
General guidance, not legal advice — your counsel and insurer may have specific requirements for your jurisdiction and policy.
What happens when you hit send
The moment you submit
Flagged URGENT, ahead of everything
Your report lands in the response queue marked urgent — above every sales enquiry and support ticket, visible to the team instantly.
First contact
A human triages with you
If you left a number we call it first. We establish what's happening, what's at stake, and what to do in the next hour — before any paperwork.
Immediately after
Containment guidance
Concrete steps for your team: what to isolate, what to preserve, what not to touch. You act; we direct; the attacker loses ground.
Once stabilised
Scoped response engagement
Full investigation, eradication and recovery, scoped in writing with a fixed price — and a hardening plan so this doesn't happen twice.
Incidents we respond to
Ransomware & extortion
Encrypted systems, ransom notes, double-extortion threats. Containment first, negotiation advice second — never pay before you understand your position.
Business email compromise
Hijacked mailboxes, redirected invoices, fraudulent payment instructions. We trace the access, cut it off, and scope what the attacker read.
Active intrusion
Suspicious logins, privilege escalation, lateral movement in progress. We help you watch, contain, and evict without tipping the attacker off early.
Data breach & exfiltration
Customer data on a leak site, unusual outbound transfers, an S3 bucket in the news. We establish what left, when, and through which door.
Web app compromise
Defacement, web shells, injected skimmers, poisoned dependencies. We find the entry point and close it — then verify it stays closed.
AI system abuse
Prompt-injected agents, jailbroken chatbots leaking data, poisoned tool calls. A failure mode most responders have never seen — we test these systems for a living.
The response, in three phases
Contain
Stop the bleeding first.
- Isolate affected systems
- Block attacker access & traffic
- Segment what still stands
- Preserve evidence as you go
Eradicate
Remove the cause, not just the symptom.
- Malware & web shell removal
- Backdoor & persistence hunting
- Exploited vulnerabilities patched
- Compromised credentials reset
Recover
Back to business, provably clean.
- Restore from clean state
- Watch for re-entry attempts
- Post-incident review & report
- Hardening recommendations
After the fire: make sure it can’t reignite
Most victims are re-attacked through the same door. Once you’ve recovered, our AI agents and certified testers verify the fix, hunt for the paths nobody checked, and close the engagement with a certificate that proves it.