If you are being attacked right now, call us.
+372 5370 2630Answered by a duty analyst, not an answering service. You do not need to be a customer, there is no triage form, and the first call costs nothing.
- 47 min
- Median time to first responder
- 24/7/365
- Duty analyst on shift
- EU
- Data and team resident
Do these five things now
In roughly this order. If you only manage two, make them the first two — the rest can wait for an analyst.
Isolate, do not power off
Disconnect affected hosts from the network but leave them running. Powering down destroys memory-resident evidence that often holds the only copy of the attacker's tooling.
Preserve the logs
Export firewall, VPN, identity provider, EDR and mail logs now, before retention windows roll them off. This is the most common irreversible loss in the first hour.
Move to out-of-band comms
Assume email and chat are being read. Move incident coordination to phone or a channel on infrastructure the attacker does not control.
Reset privileged credentials
Domain admin, cloud root, service accounts and any credential with lateral reach — from a host you have confirmed is clean.
Start a timeline
One shared document, timestamped, recording what was observed and what was changed by whom. Your regulator, insurer and forensic team will all need it.
Do not wipe or rebuild yet.
Reimaging a compromised host destroys the evidence needed to establish scope, satisfy your insurer and meet GDPR Article 33 or NIS2 Article 23 reporting duties. Isolate the machine; preserve it.
A retainer means you skip this page next time.
Retainer clients get a named lead responder, an agreed playbook, pre-signed engagement paperwork and a guaranteed response window — so the first hour is spent containing the incident rather than negotiating a contract.