Investigations
Full-scope investigations carried to conclusion — establishing what happened, how, and who, to the standard the outcome actually requires.
- 57+
- 0
An investigation runs to a conclusion, not to a budget. We establish what happened, how, and who — to the evidentiary standard the outcome requires, whether that is an insurance claim, a regulatory notification or a prosecution.
Where a case crosses borders we work with national CERTs and law enforcement. That cooperation is unpaid and often invisible, and it is the reason our intelligence on regional adversaries is worth having.
Who runs it
The responders who take the first call stay on the case to the end. An investigation handed between teams loses the context that makes the second half fast.
If it goes to court
Findings are written to survive challenge, and the examiner who produced them will testify to them.
What it covers
Six disciplines, run in this order. Not every case needs all six.
Preservation
Volatile evidence first, in a defensible order, before anything is remediated. What is lost in the first hour cannot be recovered later.
Timeline reconstruction
A single ordered account of what happened across endpoint, network, identity and cloud telemetry — not four systems telling four stories.
Tooling analysis
Malware, loaders and living-off-the-land technique, examined to establish capability and to produce detections that survive the engagement.
Infrastructure attribution
Staging domains, hosting, reuse patterns and operator tradecraft, assessed against what we already track — with our confidence stated, not implied.
Financial tracing
Where money moved and how it was cashed out, which is usually the part that determines whether recovery is possible at all.
Reporting to standard
Written to the evidentiary standard the outcome requires — insurance claim, regulatory notification or prosecution — and defended if challenged.
No case studies
Why you will not find case studies here
A published incident is a permanent, searchable record that an organisation was breached. Most of our clients are regulated financial institutions, and for them that record has consequences long after the incident is closed.
So a write-up appears only when the client has approved the exact wording, no active proceedings would be prejudiced, and enough time has passed that publication cannot be traced back to a specific event — which in practice means a year or more after the work concludes. None have cleared that bar yet.
We would rather this page stay empty than earn traffic with somebody else’s bad week. If you are evaluating us, ask on the scoping call — we will introduce you to a client in your sector who has agreed to speak about the work privately, which is more useful than a case study anyway.
Journalists and researchers
If you have a specific question about a campaign or an actor we track, write to security@cyberross.com and we will tell you what we are able to say.
Dealing with something now?
If you are mid-incident, do not use a form. The hotline reaches a duty analyst directly, around the clock, and the first call costs nothing.
30 min
A scoping call, with an engineer rather than a sales rep.
What it costs
Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.
Under attack now?
Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.