Incident response
Under attack?
Act in this order.
Whether it's ransomware, a compromised inbox or something that just feels wrong - the first hour decides how bad this gets. Follow the four steps below, then get us on the line. First response guidance is free, client or not.
The first hour, done right.
Don't power machines off
Shutting down destroys the evidence in memory that tells us how far the attacker got. Disconnect affected machines from the network instead - unplug the cable, kill the Wi-Fi.
Preserve, don't clean
Do not delete suspicious files, wipe machines or restore backups yet. If the backup is connected to an infected network, restoring can spread the problem or overwrite what's recoverable.
Change credentials from a clean device
From a phone or an untouched machine: change passwords for email, banking and admin accounts - in that order. Turn on MFA anywhere it's off.
Write down the timeline
What was seen, when, by whom. The ransom note text, odd emails, locked files. Every detail shortens the investigation.
Then we take it from there.
Contain
We isolate affected systems, cut attacker access and stop the spread - remotely within hours, on-site in Dubai when it matters.
Investigate
We establish what happened, what was touched and whether data left the building - in plain language, with evidence you can hand to regulators, insurers or your board.
Recover
Clean restoration, verified backups, closed entry points - and a hardening plan so the same door never opens twice.
After recovery, most clients move onto managed detection so the next attempt is a log line instead of a crisis. That conversation happens later - when you're back on your feet.