Preserve. Contain.
Recover.
We take on coordination and analysis: what happened, since when, how far, what was exfiltrated. We preserve evidence forensically, with a documented chain of custody. In parallel we restore the environment with your team so that the attacker does not come back.
What is included.
Contain, investigate, recover — with evidence that holds up.
Initial assessment
Situation, timing, affected systems, steps already taken; objectives agreed with management.
Evidence preservation
Forensic images, log preservation, documented chain of custody.
Analysis
Timeline, entry vector, spread, data exfiltration; malware analysis where needed.
Containment and recovery
A plan scaled to the incident; implementation with your team — identity reset, rebuild, hardening. Notifications to the authorities prepared within the deadlines.
In an incident: phone +49 40 64 88 17 57. In the first call we tell you whether and how quickly we can take over.
Five steps,
one deliverable.
Assessment
Capture the situation, set communication channels and reporting cadence.
Preservation
Preserve evidence forensically before anything is changed.
Containment
Close attacker access without destroying evidence.
Analysis
Establish timeline and scope; meet the notification duties.
Recovery
Clean up and harden the environment; final report for management, insurer and regulator.