Immediate attack response while protecting critical operations
We activate the SOC workflow, isolate compromised systems, preserve evidence and keep unaffected services running while determining incident scope and root cause.
- 24/7
- Emergency channel
- <1h
- Initial response target
- SOC
- Technical coordination
- Forensic
- Evidence preservation
The first hours determine how far an incident spreads
Shutting down every system without a plan can destroy evidence and stop unaffected operations. Response must be coordinated:
- Compromised accounts or servers continue to provide attacker access.
- Logs and volatile memory disappear before collection.
- It is unclear which data was accessed, stolen or published.
- Recovery starts before the cause is removed and the incident returns.
How we respond during an attack
We make decisions with the authorized contact and document every action that may affect operations or evidence.
Triage and isolation
We confirm the incident, block malicious access and isolate only affected systems.
Snapshots and evidence
We capture servers, disks, memory and logs before irreversible changes.
Analysis
We determine affected systems, accessed or stolen data, the path and initial cause.
Recovery
We remove persistence, restore in a controlled way and monitor for recurring indicators.
SOC activation
One channel coordinates the technical team, suppliers and urgent decisions.
Selective isolation
We shut down compromised servers and keep services running where it is safe.
Snapshots before changes
We preserve system state for analysis and avoid losing volatile evidence.
Exfiltration analysis
We check which data was accessed, copied, encrypted or published.
Scope and root cause
We map affected systems and identify the initial vector and persistence.
Controlled recovery
We restore from verified sources, rotate access and harden systems.
Investigation capabilities
- SIEM / EDR
- Velociraptor
- Volatility
- YARA
Docker
AWS / Vercel
Medium-premium incident response rates for Romania. Final cost depends on system count, data volume and investigation duration.
Containment
Triage and rapid containment for a limited incident.
- Activation and triage
- Affected system isolation
- Initial evidence collection
- Critical access reset
- Situation report
Investigation
Complete investigation across several systems.
- Server and endpoint snapshots
- Log and persistence analysis
- Accessed or stolen data
- Root cause and timeline
- Recovery plan
Critical
Extended incident, critical operations or ransomware.
- 24/7 coordination
- Multiple segments or locations
- Malware and exfiltration analysis
- Incident communication support
- Post-recovery monitoring
Prices exclude VAT and cover the initial response defined in the quote. Third-party services, travel, evidence storage and extended investigation are approved separately.
FAQ
Not automatically. We isolate compromised systems and assess dependencies so unaffected operations can continue when safe.
We analyze logs, traffic, accounts, files and exfiltration indicators. Conclusions distinguish what is confirmed, likely or impossible to determine from available evidence.
Yes, when the infrastructure permits and doing so does not worsen the incident. We collect disk images, memory and logs before irreversible changes.
Yes. We verify access removal, apply hardening measures and monitor indicators so the incident does not return.
Active incident? Use the emergency channel
Prepare an authorized contact, the system list and the time of detection. Do not delete logs or reinstall servers before triage.
Let's talk