HALLATEC

Incident response

Under attack?
Act in this order.

Whether it's ransomware, a compromised inbox or something that just feels wrong - the first hour decides how bad this gets. Follow the four steps below, then get us on the line. First response guidance is free, client or not.

The first hour, done right.

Don't power machines off

Shutting down destroys the evidence in memory that tells us how far the attacker got. Disconnect affected machines from the network instead - unplug the cable, kill the Wi-Fi.

Preserve, don't clean

Do not delete suspicious files, wipe machines or restore backups yet. If the backup is connected to an infected network, restoring can spread the problem or overwrite what's recoverable.

Change credentials from a clean device

From a phone or an untouched machine: change passwords for email, banking and admin accounts - in that order. Turn on MFA anywhere it's off.

Write down the timeline

What was seen, when, by whom. The ransom note text, odd emails, locked files. Every detail shortens the investigation.

Then we take it from there.

Contain

We isolate affected systems, cut attacker access and stop the spread - remotely within hours, on-site in Dubai when it matters.

Investigate

We establish what happened, what was touched and whether data left the building - in plain language, with evidence you can hand to regulators, insurers or your board.

Recover

Clean restoration, verified backups, closed entry points - and a hardening plan so the same door never opens twice.

After recovery, most clients move onto managed detection so the next attempt is a log line instead of a crisis. That conversation happens later - when you're back on your feet.