Incident response
If something is happening right now, call.
Monitored 24×7 from Kolkata. Ask for the incident desk.
Before you call, if you have two minutes.
- 01
Do not power anything off
Shutting a compromised machine down destroys volatile evidence and rarely stops what is already running. Isolate from the network instead.
- 02
Do not start deleting
Logs, mailboxes and temporary files are how the timeline gets built. Preserve first, clean later.
- 03
Write down when you knew
The regulatory notification clock runs from the moment of knowledge. That timestamp matters more than most people expect.
- 04
Decide who is authorised
One named decision-maker who can authorise containment actions, and one deputy. Containment stalls on approvals more often than on technique.
What happens when you call.
We identify what is affected, isolate impacted systems safely, and check whether any notification deadlines have started.
We assess the compromise, conduct forensics, support recovery, and handle regulatory notification requirements alongside the investigation.
Existing managed SOC clients already have an agreed escalation path, and our analysts are familiar with their environment.