Emergency Cybersecurity Incident Response
If you are dealing with an active incident right now, contact us before reading any further. The first hour determines how much of this you recover. Everything below explains what happens after you make that call.
What we do
Contain first, investigate second, rebuild third
The instinct during a breach is to start fixing things. That destroys the evidence you need and often reinfects what you just cleaned. Order matters.
Immediate Containment
Isolating affected systems and cutting the attacker's access before anything else. Every minute of continued access is more data taken and more systems encrypted.
Scope Assessment
Establishing what was actually reached, what was taken, and whether the attacker still has a foothold. Restoring before you know the answer is how businesses get hit twice in a fortnight.
Evidence Preservation
Capturing logs and forensic images before remediation destroys them. Your insurer will ask, your lawyer will ask, and if regulated data was involved, so will a regulator.
Eradication
Removing persistence mechanisms, backdoors, and compromised credentials. Attackers routinely leave multiple ways back in, and cleaning only the obvious one guarantees a second visit.
Recovery
Restoring from verified-clean backups in a sequence that gets your revenue-generating systems working first, without reintroducing the compromise.
Post-Incident Hardening
Closing the gap that let them in, plus the adjacent ones the investigation exposed. A breach is expensive information about your defenses, and it is worth acting on.
What the first 48 hours look like
Structured response, not improvisation.
Hour Zero to Four
Contain and isolate. Attacker access cut, spread stopped, evidence preserved, and a clear picture of what we are dealing with.
Hour Four to Twenty-Four
Scope and eradicate. Determining what was reached and taken, removing persistence, and resetting compromised credentials.
Day Two Onward
Restore and harden. Clean recovery in business-priority order, then closing what let them in.
Dealing with an incident right now?
Do not wait to see whether it gets worse. Containment speed is the single largest factor in what an incident ends up costing.
FAQ
Incident response questions
Disconnect affected machines from the network, but do not power them off, because shutting down destroys memory-resident evidence. Do not start deleting files or reinstalling. Do not pay anything yet. Then call someone who does this. Preserving the current state matters more than it feels like it does in the moment.
That is a decision for you, your counsel, and your insurer, and it is not one we make for you. What we can tell you is that payment does not guarantee usable decryption, it does not stop stolen data from being published, and it marks you as a business that pays. Understanding your restore options before deciding usually changes the calculation.
Possibly, and it depends on what data was involved. Illinois has breach notification requirements, and sector rules like HIPAA carry their own. This is a legal question rather than a technical one, so involve counsel early. We preserve the evidence needed to answer it accurately.
Usually only if you follow their process, which normally means notifying them immediately and often using their approved response vendors. Call your carrier early. Acting first and notifying later is a common way to end up with a denied claim.
Days to weeks, driven mostly by whether you have clean, tested backups. Businesses with verified backups and documentation are often substantially operational within a week. Businesses without them can be looking at a month or more, and sometimes at permanent data loss.