Under attack? Act now.

Every minute an attacker keeps access, the damage compounds. Report the incident and it lands in front of the response team immediately — flagged urgent, ahead of everything else.

24/7 intakeRouted URGENTHuman triageConfidential

Report an active incident

Tell us only what you safely can — we’ll take it from there.

While you wait: incident first aid

The first hour decides how much evidence survives and how far the attacker gets. These hold for almost every incident.

Do

  • Disconnect affected machines from the network — but leave them powered on (memory is evidence)
  • Preserve logs, alerts and screenshots; note times of everything you saw
  • Move your team's coordination to a channel the attacker can't read (personal phones beat company email)
  • Reset credentials from a known-clean device, starting with admin and email accounts
  • Tell leadership and, if you have them, your insurer and counsel — early

Don’t

  • Don't wipe, reimage or "clean up" compromised systems yet — you'd destroy the evidence that shows what happened
  • Don't pay a ransom before getting advice — payment rarely ends the incident
  • Don't discuss the incident over possibly-compromised email or chat
  • Don't mass-delete attacker accounts or files the moment you spot them — coordinated eviction beats whack-a-mole
  • Don't announce anything publicly before you know what actually happened

General guidance, not legal advice — your counsel and insurer may have specific requirements for your jurisdiction and policy.

What happens when you hit send

  1. The moment you submit

    Flagged URGENT, ahead of everything

    Your report lands in the response queue marked urgent — above every sales enquiry and support ticket, visible to the team instantly.

  2. First contact

    A human triages with you

    If you left a number we call it first. We establish what's happening, what's at stake, and what to do in the next hour — before any paperwork.

  3. Immediately after

    Containment guidance

    Concrete steps for your team: what to isolate, what to preserve, what not to touch. You act; we direct; the attacker loses ground.

  4. Once stabilised

    Scoped response engagement

    Full investigation, eradication and recovery, scoped in writing with a fixed price — and a hardening plan so this doesn't happen twice.

Incidents we respond to

Ransomware & extortion

Encrypted systems, ransom notes, double-extortion threats. Containment first, negotiation advice second — never pay before you understand your position.

Business email compromise

Hijacked mailboxes, redirected invoices, fraudulent payment instructions. We trace the access, cut it off, and scope what the attacker read.

Active intrusion

Suspicious logins, privilege escalation, lateral movement in progress. We help you watch, contain, and evict without tipping the attacker off early.

Data breach & exfiltration

Customer data on a leak site, unusual outbound transfers, an S3 bucket in the news. We establish what left, when, and through which door.

Web app compromise

Defacement, web shells, injected skimmers, poisoned dependencies. We find the entry point and close it — then verify it stays closed.

AI system abuse

Prompt-injected agents, jailbroken chatbots leaking data, poisoned tool calls. A failure mode most responders have never seen — we test these systems for a living.

The response, in three phases

01

Contain

Stop the bleeding first.

  • Isolate affected systems
  • Block attacker access & traffic
  • Segment what still stands
  • Preserve evidence as you go
02

Eradicate

Remove the cause, not just the symptom.

  • Malware & web shell removal
  • Backdoor & persistence hunting
  • Exploited vulnerabilities patched
  • Compromised credentials reset
03

Recover

Back to business, provably clean.

  • Restore from clean state
  • Watch for re-entry attempts
  • Post-incident review & report
  • Hardening recommendations

After the fire: make sure it can’t reignite

Most victims are re-attacked through the same door. Once you’ve recovered, our AI agents and certified testers verify the fix, hunt for the paths nobody checked, and close the engagement with a certificate that proves it.