Skip to content

CERT-Cyberross · Staffed 24/7/365

If you are being attacked right now, call us.

+372 5370 2630

Answered by a duty analyst, not an answering service. You do not need to be a customer, there is no triage form, and the first call costs nothing.

47 min
Median time to first responder
24/7/365
Duty analyst on shift
EU
Data and team resident

Before you call

Do these five things now

In roughly this order. If you only manage two, make them the first two — the rest can wait for an analyst.

  1. 01

    Isolate, do not power off

    Disconnect affected hosts from the network but leave them running. Powering down destroys memory-resident evidence that often holds the only copy of the attacker's tooling.

  2. 02

    Preserve the logs

    Export firewall, VPN, identity provider, EDR and mail logs now, before retention windows roll them off. This is the most common irreversible loss in the first hour.

  3. 03

    Move to out-of-band comms

    Assume email and chat are being read. Move incident coordination to phone or a channel on infrastructure the attacker does not control.

  4. 04

    Reset privileged credentials

    Domain admin, cloud root, service accounts and any credential with lateral reach — from a host you have confirmed is clean.

  5. 05

    Start a timeline

    One shared document, timestamped, recording what was observed and what was changed by whom. Your regulator, insurer and forensic team will all need it.

Do not wipe or rebuild yet.

Reimaging a compromised host destroys the evidence needed to establish scope, satisfy your insurer and meet GDPR Article 33 or NIS2 Article 23 reporting duties. Isolate the machine; preserve it.

Afterwards

A retainer means you skip this page next time.

Retainer clients get a named lead responder, an agreed playbook, pre-signed engagement paperwork and a guaranteed response window — so the first hour is spent containing the incident rather than negotiating a contract.