X://EMERGENCYX1Incident Response
Something has gone wrong.
Start here.
Emergency response for ransomware, business email compromise, and suspected data breaches. If you are in an incident right now, call us before you change anything. The first hour decides how much of the next month you lose.
THE FIRST HOUR
In an incident, the instinct to fix it quickly is usually what makes it expensive.
Rebuilding the machine destroys the evidence needed to work out what was taken. Paying the ransom before scoping the damage funds a second visit. Telling everyone before you know the facts turns a technical problem into a legal one.
Containment comes first, then scope, then recovery, in that order, every time. The point of a response plan is that nobody has to invent one while the phones are ringing.
- 01Files renamed, or a ransom noteDisconnect from the network. Do not power off, because memory holds evidence.
- 02An invoice was paid to the wrong accountCall your bank first, then us. Some payments can still be recalled.
- 03Staff report emails they did not sendA mailbox is likely compromised. Do not just reset the password.
- 04You have been told you are in a breachBy a customer, a partner, or the police. Treat it as real until proven otherwise.
WHAT WE DO
Contain, understand, recover
One engagement, four workstreams, run in parallel where it is safe to and in sequence where it is not.
- 01
Containment
Isolate affected systems, cut attacker access, force credential and token resets, and stop the spread before it reaches backups.
- 02
Forensic scope
Establish what was reached, what was taken, and when it started. Evidence is preserved properly in case it is needed later by insurers or regulators.
- 03
Recovery
Rebuild from known-good backups onto a hardened environment, rather than restoring the same weakness you started with.
- 04
Notification support
Plain-English findings you can give your lawyer, insurer, board, and the Office of the Privacy Commissioner if the breach is notifiable.
- 05
Root cause
How they got in, written down. Without this the same door is open next quarter.
- 06
Hardening
The specific changes that would have stopped it, prioritised by what buys the most safety fastest.
HOW IT RUNS
Triage, contain, recover, review
You get a named lead and a single line of communication. No being handed between queues while your business is down.
- 01First call
Triage
We establish what is happening, what to stop touching, and what to disconnect. You get immediate instructions before anyone is dispatched.
- 02Hours 1 – 8
Contain
Attacker access is cut, credentials rotated, and the blast radius fixed so the problem stops growing while we work out its shape.
- 03Days 1 – 5
Recover
Systems come back in priority order. The ones your business cannot trade without go first, onto a clean environment.
- 04Week 2
Review
A written report: what happened, what it cost, what we changed, and what still needs doing. Useful for your insurer, and for making sure it does not recur.
WHAT YOU GET
What you are left holding
- A written timeline of what happened, defensible to an insurer.
- A clean environment rather than a restored copy of the old one.
- A clear answer on whether the breach is notifiable, and to whom.
- The specific gap that let it happen, closed and documented.
FAQ
Questions we get asked
01We are in an incident right now. What do we do first?
Call us. While you wait: disconnect affected machines from the network but do not turn them off, stop anyone from deleting or reinstalling anything, and do not pay a ransom. Powering a machine off destroys evidence held in memory that helps establish what was actually taken.
02Do we need to be an existing client?
No. We take incident response calls from organisations we have never worked with. You will be asked for more detail up front because we are starting without any knowledge of your environment.
03What does it cost?
Incident work is charged on time and materials, because nobody can scope an incident before seeing it. We give you a running estimate as the picture becomes clear, and we tell you when spending more stops being worth it.
04Will you talk to our insurer?
Yes. Many cyber policies require the insurer to be notified before response work begins and some mandate their own panel providers, so tell us early if you hold a policy. Our reporting is written to be usable as part of a claim.
05Do we have to tell anyone?
Under the Privacy Act 2020, a privacy breach likely to cause serious harm must be notified to the Office of the Privacy Commissioner and to affected people as soon as practicable. We give you the factual findings; the notification decision is one to make with your lawyer.
06Should we pay the ransom?
It is your decision and we will not make it for you, but payment does not guarantee a working decryptor, does not stop the data being sold, and marks you as a paying target. We scope recovery from backups first so the choice is an informed one.
If it is happening now, call.
Do not wait for a reply to an email. Phone the number below and ask for incident response.
← All services