Incident response

Immediate attack response while protecting critical operations

We activate the SOC workflow, isolate compromised systems, preserve evidence and keep unaffected services running while determining incident scope and root cause.

24/7
Emergency channel
<1h
Initial response target
SOC
Technical coordination
Forensic
Evidence preservation

The first hours determine how far an incident spreads

Shutting down every system without a plan can destroy evidence and stop unaffected operations. Response must be coordinated:

  • Compromised accounts or servers continue to provide attacker access.
  • Logs and volatile memory disappear before collection.
  • It is unclear which data was accessed, stolen or published.
  • Recovery starts before the cause is removed and the incident returns.

How we respond during an attack

We make decisions with the authorized contact and document every action that may affect operations or evidence.

01

Triage and isolation

We confirm the incident, block malicious access and isolate only affected systems.

02

Snapshots and evidence

We capture servers, disks, memory and logs before irreversible changes.

03

Analysis

We determine affected systems, accessed or stolen data, the path and initial cause.

04

Recovery

We remove persistence, restore in a controlled way and monitor for recurring indicators.

SOC activation

One channel coordinates the technical team, suppliers and urgent decisions.

Selective isolation

We shut down compromised servers and keep services running where it is safe.

Snapshots before changes

We preserve system state for analysis and avoid losing volatile evidence.

Exfiltration analysis

We check which data was accessed, copied, encrypted or published.

Scope and root cause

We map affected systems and identify the initial vector and persistence.

Controlled recovery

We restore from verified sources, rotate access and harden systems.

Investigation capabilities

  • SIEM / EDR
  • Velociraptor
  • Volatility
  • YARA
  • DockerDocker
  • Amazon Web ServicesVercelAWS / Vercel
Pricing

Medium-premium incident response rates for Romania. Final cost depends on system count, data volume and investigation duration.

Containment

Triage and rapid containment for a limited incident.

from 15,000 RON
≈ €3,000
  • Activation and triage
  • Affected system isolation
  • Initial evidence collection
  • Critical access reset
  • Situation report
Get a quote Containment
Popular

Investigation

Complete investigation across several systems.

from 30,000 RON
≈ €6,000
  • Server and endpoint snapshots
  • Log and persistence analysis
  • Accessed or stolen data
  • Root cause and timeline
  • Recovery plan
Get a quote Investigation

Critical

Extended incident, critical operations or ransomware.

from 60,000 RON
≈ €12,000
  • 24/7 coordination
  • Multiple segments or locations
  • Malware and exfiltration analysis
  • Incident communication support
  • Post-recovery monitoring
Get a quote Critical

Prices exclude VAT and cover the initial response defined in the quote. Third-party services, travel, evidence storage and extended investigation are approved separately.

FAQ

Not automatically. We isolate compromised systems and assess dependencies so unaffected operations can continue when safe.

We analyze logs, traffic, accounts, files and exfiltration indicators. Conclusions distinguish what is confirmed, likely or impossible to determine from available evidence.

Yes, when the infrastructure permits and doing so does not worsen the incident. We collect disk images, memory and logs before irreversible changes.

Yes. We verify access removal, apply hardening measures and monitor indicators so the incident does not return.

Active incident? Use the emergency channel

Prepare an authorized contact, the system list and the time of detection. Do not delete logs or reinstall servers before triage.

Let's talk