Skip to content
Under attack?Get emergency help now
Emergency incident response

Under attack? We respond, fast.

If you're facing a live cyberattack, ransomware or a data breach, don't wait. The faster our incident response team is on it, the more we can contain, and the sooner you recover.

Monitored 24/7. If it's urgent, call, don't email.

While you wait for us, do this now.

Disconnect, don't power off

Unplug affected devices from the network and Wi-Fi to stop the spread, but leave them powered on so evidence in memory is preserved.

Do not pay any ransom

Paying rarely restores everything and marks you as a target. Talk to us before you take any action a criminal is demanding.

Preserve the evidence

Don't delete files, wipe machines or reset systems. Photograph ransom notes and error messages so we can trace the attack.

Call us

The sooner we're involved, the more we can contain. Our team will guide you through the next steps on the call.

The first hour

What the first hour looks like.

The order never changes, even though the clock does. Every incident is different in size, so we describe the sequence rather than pretend to know how long yours will take.

1

Triage, on the call

We ask what you are seeing, when you first noticed it, which systems and sites are affected, and who holds administrative access. That picture tells us whether this is one compromised device or something moving across your estate, and it decides what gets protected first. You will get instructions you can act on while we are still talking.

2

Containment

We work with whoever holds the keys, whether that is your team, ours or your existing IT provider, to isolate affected hosts, disable compromised accounts, revoke active sessions and access tokens, and close the route the attacker is using. Containment always comes before clean-up: restoring into a network the attacker still occupies simply hands the systems back.

3

Scoping

Once containment holds we establish the blast radius. Which identities were abused, which servers, mailboxes, file shares and cloud tenants were reached, whether persistence was planted, and whether data was copied out as well as encrypted. Scope drives every decision that follows, including the ones you may have to report on.

4

Evidence preservation

Logs roll over and memory vanishes the moment a machine is rebooted. We capture what matters early: endpoint and firewall logs, Microsoft 365 sign-in and audit trails, mailbox rules, ransom notes, and disk or memory images where the situation warrants them. That material is what your investigation, your insurer and your legal advisers will later rely on.

5

Communications

We help you work out who needs to know and in what order: leadership, staff, your IT provider, your insurer, affected customers or suppliers, and, where personal information is involved, the Information Regulator and the data subjects. We give you the technical facts in language you can put in front of a board without translation.

The first hour buys back control. What follows is the longer work of investigating properly, recovering cleanly and closing the gap, which is where our cybersecurity and backup and disaster recovery teams take over.

How we respond

Contain, investigate, recover, harden.

Backed by our 24/7 MDR, immutable backups and Disaster Recovery service, and continuous vulnerability management.

Step 1

Contain

We isolate affected systems and cut off the attacker's access to stop the incident spreading any further.

Step 2

Investigate

We establish what happened, what was reached and how, working with our 24/7 SOC and threat intelligence.

Step 3

Recover

We restore clean systems and data from immutable backups and our Disaster Recovery service, getting you operational.

Step 4

Harden

We close the gaps the attacker used and strengthen your defences so the same door can't be opened twice.

Scenarios

Most calls to this page are one of three things. Each behaves differently, and the wrong first move costs you more in each one.

Ransomware

What it looks like

Files across shares and servers renamed with an unfamiliar extension. A ransom note dropped into every folder. Line-of-business applications throwing database errors, staff locked out one department at a time, and the backup console either unreachable or showing jobs that were deleted days ago.

What we do

We isolate the affected hosts and the accounts being used to move between them, work out how the attacker got in and how far they went, and check whether your backups are both intact and clean. We look for signs that data was copied out before encryption, because that changes what you have to deal with afterwards. Only once the environment is contained and persistence has been hunted down do we rebuild and restore.

What not to do

Do not reboot or reimage the affected machines, do not restore into the same network before it has been cleared, do not delete the ransom note, and do not open a conversation with the attacker before you have advice.

Business email compromise

What it looks like

A supplier's banking details change by email and an invoice is paid to the wrong account. Replies to a live payment thread disappear into Deleted Items because of an inbox rule nobody created. Colleagues and clients receive convincing mail from your address that you never sent, or staff report authentication prompts they did not trigger.

What we do

We lock the identity down properly: reset credentials, revoke active sessions and application tokens, remove malicious forwarding and inbox rules, and check for registered authenticator methods the attacker added. Then we work through sign-in and audit logs to establish what was read, forwarded or downloaded, which other systems that identity could reach, and whether the compromise extended beyond the mailbox.

What not to do

Do not simply change the password: existing sessions and tokens survive a password reset. Do not delete the malicious rules before they have been recorded, do not keep negotiating payment details on the compromised thread, and if money has already moved, phone your bank immediately, because recovery chances fall away by the hour.

Data breach and POPIA-notifiable incidents

What it looks like

Personal information, whether staff, client, patient or learner records, has been accessed or copied by someone who should not have had it. An exposed database, a stolen unencrypted laptop, an over-shared cloud folder, a departing employee's bulk download, or your files appearing on an extortion leak site.

What we do

We establish the facts you need in order to decide: what categories of personal information were involved, whose, how much, over what period, and whether it actually left your environment or was only accessible. You get a written timeline and an evidence pack your Information Officer and legal advisers can rely on, plus help closing the exposure and hardening what allowed it.

What not to do

Do not quietly clean up and hope. Do not tell customers that no data was taken before the scoping supports that statement, and do not destroy or overwrite the logs and systems that show what happened.

POPIA notification is a legal decision, not a technical one. Our job is to give your Information Officer and your legal advisers an accurate, evidenced picture of what happened and what was affected, in time for them to act on it. Nothing on this page is legal advice. Where an incident reaches you through a supplier or a service provider, our third-party risk management work helps you see the same exposure before it becomes an incident.

Be ready

What to have ready before you call.

None of this is a prerequisite. Call first and gather it while we talk. It simply means the first hour is spent responding rather than hunting for passwords and phone numbers.

What you are actually seeing

A photograph of the ransom note or error message, when it was first noticed, and which people or departments have reported it.

A rough asset list

How many servers, endpoints and sites, and what runs where: on-premises, Microsoft 365 or Google Workspace, Azure or another cloud, and any hosted line-of-business applications.

Who has administrative access

Domain admin, Microsoft 365 global admin, firewall, hypervisor and backup console, with names and a way to reach those people out of hours.

Where your backups live

Which systems are covered, when the last successful job ran, when a restore was last tested, and whether the backups sit on the same network or domain as everything else.

Your cyber insurance policy

The policy number and the insurer's incident hotline. Check the wording early: some policies require the insurer to be notified before you appoint anyone to respond.

Key contacts and a decision-maker

Someone with authority to approve action, plus your Information Officer, legal adviser, finance or bank contact if money moved, and your existing IT provider.

A way to talk off the compromised network

Personal mobile numbers, a WhatsApp group or an out-of-band mail account. Assume the attacker can read your email until the investigation proves otherwise.

Straight talk

What a response engagement actually involves.

Before anyone touches a system, we agree in writing what we are authorised to do, who our single point of contact is and how decisions get made. It sounds like paperwork in the middle of a crisis, but unclear authority costs more time in an incident than any technical problem does.

Engagements are not all the same size. One compromised mailbox can be closed out quickly. Ransomware across a domain, with servers to rebuild and identities to rebuild trust in, runs for considerably longer, and the rebuild usually outlasts the response. We tell you which of those it looks like as soon as scoping supports an answer, and we say so plainly when we do not know yet.

We will not promise you full recovery. If your backups were reachable from the compromised network and went the same way as everything else, and there is no offline or immutable copy, some data may simply be gone. Decryption without paying is sometimes possible and often is not. Anyone who guarantees otherwise before looking at your environment is selling you something.

We work alongside the people you already have: your internal IT team or existing provider, your insurer and their appointed advisers, your attorneys, and law enforcement if you choose to report. When it closes, you get a written account of what happened, what was affected, what we changed and what still needs fixing, followed by the hardening work to make sure the same door does not open twice.

FAQ

Incident response, answered.

Should we pay the ransom?

Our advice is not to pay, and not to open any negotiation before you have taken advice. Payment funds the next attack, marks you as an organisation that pays, and buys a decryption tool that is frequently slow, partial or simply broken. It also does nothing about data that was copied out before the encryption started. The decision is ultimately yours, together with your insurer and legal advisers, but it should be made once scoping tells you what is actually recoverable, not in the first panicked hour.

Should we power the affected machines off?

Disconnect, do not power off. Pulling the network cable or turning off Wi-Fi stops the spread. Powering down destroys what is in memory, which is often where the evidence of what the attacker was running lives, and reimaging destroys it permanently. Leave affected machines switched on but isolated until the response team tells you otherwise.

Do we have to report the incident?

It depends what was affected. Under POPIA, where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, the responsible party must notify the Information Regulator and the affected data subjects as soon as reasonably possible after the compromise is discovered. Sector regulators, contracts and your insurer may impose their own reporting obligations, and reporting to the police is a separate decision. We give your Information Officer and legal advisers the factual scope and timeline they need to make those calls. We do not make them for you, and nothing here is legal advice.

Will we lose our data?

Honestly, sometimes some of it. What comes back depends on whether you have backups the attacker could not reach, how recent the last clean restore point is, and whether systems were encrypted, deleted or only accessed. Immutable or otherwise isolated backups are the single biggest factor in how much you recover, which is why they are the first thing we check. We tell you what is recoverable once we have verified it, rather than making a promise on day one that we cannot keep.

Do you work with our cyber insurer?

Yes. Tell us early that you are insured and give us the policy and the insurer's hotline. Many policies set out who must be notified and by when, and some restrict which firms may carry out response work or require approval before costs are incurred. We work within those requirements, and the timeline, evidence and written findings we produce are usually the material a claim is built on.

What does it cost to get started?

Calling us costs nothing, and neither does the initial triage conversation where we work out what you are facing and what to do in the next few minutes. If a response engagement follows, we agree the scope and the basis of the work with you in writing before it starts. Cost tracks the size of the incident, because a single compromised mailbox and an estate-wide ransomware event are not the same job, so we will not put a figure on it before we know which one you have.

We are not a client. Can you still help?

Yes. A large part of incident response work is for organisations we have not worked with before, frequently alongside their existing IT provider. What we need is fast access to the environment and one person who can authorise decisions quickly. Once the incident is closed you are under no obligation to move your IT to us, although plenty of organisations do choose to after seeing where the gaps were.

Every minute counts. Talk to us now.

Not yet a client? That's fine. We help organisations in the middle of an incident, then help make sure it never happens again.