Skip to content

CERT-Cyberross

Investigations

Full-scope investigations carried to conclusion — establishing what happened, how, and who, to the standard the outcome actually requires.

Concluded
57+
Public write-ups
0

How we work

An investigation runs to a conclusion, not to a budget. We establish what happened, how, and who — to the evidentiary standard the outcome requires, whether that is an insurance claim, a regulatory notification or a prosecution.

Where a case crosses borders we work with national CERTs and law enforcement. That cooperation is unpaid and often invisible, and it is the reason our intelligence on regional adversaries is worth having.

Who runs it

The responders who take the first call stay on the case to the end. An investigation handed between teams loses the context that makes the second half fast.

If it goes to court

Findings are written to survive challenge, and the examiner who produced them will testify to them.

What it covers

Six disciplines, run in this order. Not every case needs all six.

  • 01

    Preservation

    Volatile evidence first, in a defensible order, before anything is remediated. What is lost in the first hour cannot be recovered later.

  • 02

    Timeline reconstruction

    A single ordered account of what happened across endpoint, network, identity and cloud telemetry — not four systems telling four stories.

  • 03

    Tooling analysis

    Malware, loaders and living-off-the-land technique, examined to establish capability and to produce detections that survive the engagement.

  • 04

    Infrastructure attribution

    Staging domains, hosting, reuse patterns and operator tradecraft, assessed against what we already track — with our confidence stated, not implied.

  • 05

    Financial tracing

    Where money moved and how it was cashed out, which is usually the part that determines whether recovery is possible at all.

  • 06

    Reporting to standard

    Written to the evidentiary standard the outcome requires — insurance claim, regulatory notification or prosecution — and defended if challenged.

No case studies

Why you will not find case studies here

A published incident is a permanent, searchable record that an organisation was breached. Most of our clients are regulated financial institutions, and for them that record has consequences long after the incident is closed.

So a write-up appears only when the client has approved the exact wording, no active proceedings would be prejudiced, and enough time has passed that publication cannot be traced back to a specific event — which in practice means a year or more after the work concludes. None have cleared that bar yet.

We would rather this page stay empty than earn traffic with somebody else’s bad week. If you are evaluating us, ask on the scoping call — we will introduce you to a client in your sector who has agreed to speak about the work privately, which is more useful than a case study anyway.

Journalists and researchers

If you have a specific question about a campaign or an actor we track, write to security@cyberross.com and we will tell you what we are able to say.

Next step

Dealing with something now?

If you are mid-incident, do not use a form. The hotline reaches a duty analyst directly, around the clock, and the first call costs nothing.

30 min

A scoping call, with an engineer rather than a sales rep.

What it costs

Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.

Under attack now?

Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.