Cyber Security
Emergency cyber incident response
When something is actively going wrong, the priority is containment, evidence and a defensible timeline, in that order.
The first hour: contain without destroying evidence
The instinct to wipe and reinstall is understandable and it is usually wrong. Once the machines are rebuilt you cannot answer how the attacker got in, what they took, or whether they still have access, and those are exactly the questions your customers, insurers and regulators will ask.
We isolate affected systems from the network while leaving them powered where volatile memory matters, capture memory and disk images, preserve firewall, authentication and mail logs before rotation deletes them, and rotate credentials in an order that does not tip off an attacker who still has a foothold.
A single incident commander is named and a written log is started immediately, because reconstructing a timeline from memory three days later is not defensible.
Reporting obligations you are working against the clock on
The CERT-In directions of April 2022 require covered entities to report listed incident types, including ransomware, data breaches, unauthorised access and website defacement, within six hours of noticing or being notified about them. Six hours is a short window, which is why the reporting template should exist before the incident.
Where personal data is involved, the Digital Personal Data Protection Act 2023 and the DPDP Rules notified in November 2025 require notification to affected individuals and to the Data Protection Board, with details of the breach and the mitigation taken.
Regulated sectors add their own duties, such as the SEBI cyber security and cyber resilience framework for market intermediaries. We help you meet the deadline with accurate content rather than a rushed filing you later have to correct.
Investigation, eradication and safe recovery
Investigation answers four questions: how entry was gained, how long the attacker was present, what was accessed or exfiltrated, and whether persistence remains. Answering the fourth properly is what stops the same incident happening again a fortnight later.
Eradication means closing the entry point, removing web shells, scheduled tasks, rogue accounts and mail forwarding rules, and resetting authentication material including service accounts and API keys that are usually forgotten.
Recovery is staged and verified. Backups are restored to a clean, segmented environment, checked for the same implant, and only then returned to service, with monitoring raised for a defined period afterwards.
After the incident: making the next one less likely
Every engagement ends with a written report covering the timeline, root cause, scope of impact, actions taken and the evidence supporting each conclusion. It is written to be readable by your board and defensible to an assessor.
The recommendations are ranked by how much risk they remove per rupee spent. In most cases the top items are unremarkable: multi-factor authentication everywhere, tested offline backups, network segmentation and a patching routine with an owner.
We also rehearse the plan with you afterwards. A tabletop exercise that surfaces who calls the bank at eleven at night is worth more than another tool.
What you get with emergency service
- Rapid triage call and containment plan within the first response window
- Forensic preservation of memory, disk images and relevant logs
- Credential rotation and access revocation across affected systems
- Root cause and scope analysis covering entry, dwell time and exfiltration
- Eradication of persistence including web shells, tasks and rogue accounts
- Support for CERT-In and DPDP breach notification content and timing
- Staged clean recovery with heightened monitoring afterwards
- Written incident report with timeline, evidence and ranked recommendations
How an engagement runs
Every project goes through the same six stages, so you always know what happens next and what it costs.
01
Requirement analysis
We map what you actually need before proposing anything.
02
Strategic planning
Scope, milestones and a fixed number, agreed in writing.
03
Implementation
Built in the open, with a live staging link from week one.
04
Quality assurance
Functional, security and performance testing before sign-off.
05
Deployment
A launch plan with rollback, monitoring and zero surprises.
06
Continuous support
We stay on for as long as you use what we built.
FAQ
Emergency Service: questions we are asked
Isolate affected systems from the network but do not wipe or rebuild them, because that destroys the evidence needed to find the entry point. Preserve firewall, authentication and mail logs before they rotate, name one incident commander, start a written log, and call for help before rotating credentials in the wrong order.
Under the CERT-In directions issued in April 2022, covered entities must report listed cyber incidents within six hours of noticing them or being notified. Personal data breaches additionally trigger notification duties to affected individuals and the Data Protection Board under the DPDP framework. The clock starts at awareness, not at confirmation.
We do not facilitate ransom payments and we advise against them. Payment funds further attacks, provides no guarantee of a working decryptor, and does nothing about data already exfiltrated. The productive path is containment, recovery from clean backups, and closing the entry point so the same route cannot be reused.
Incidents rarely start at eleven in the morning. Emergency response is arranged on an out-of-hours basis, with a triage call to establish scope and immediate containment steps before anyone travels. Organisations that want a guaranteed response window can put a retainer in place in advance, which also means we already know your estate.
Yes. Website defacement is a reportable incident type under the CERT-In directions, so we preserve evidence before cleaning, identify the entry point, remove injected content and backdoors, patch the vulnerability, and handle Safe Browsing or host blacklist removal. Restoring a backup alone usually leads to reinfection within days.
Often bought together
What pairs well with emergency service
Cyber Security
Enterprise Security
End-to-end security architecture for large-scale organizations.
Cyber Security
Penetration Testing
Identifying vulnerabilities before hackers do.
Cyber Security
Data Recovery
Recovering critical business data from hardware failures or cyber attacks.
Web Services
Upgrade & Repair
Modernizing legacy systems and fixing performance bottlenecks.
Get a written quote for emergency service.
Tell us what you are trying to achieve and we will come back with scope, timeline and a fixed number — or tell you honestly that we are not the right team.
Talk to a specialist