Services
Partners
Use cases
Clients
Company
Contact
FRENDE

Digital forensics & incident response

React quickly and correctly when an incident hits: understand what happened, contain the threat and restore a trusted environment. The moment cybersecurity is measured in hours, not weeks.

Incident under way?
Contact us straight away for an initial assessment.
+41 22 565 33 71
Digital forensics & incident response

Understand, contain, recover.

When an incident occurs, we rebuild the timeline, preserve evidentiary value and restore a trusted environment — quickly and methodically, alongside your IT and cybersecurity teams.

InvestigationContainmentIOCChain of custody
Timeline of an incident response INCIDENT RESPONSE INCIDENTDetectionContainmentEradicationRecoveryLessons
Services

Services in detail

Digital investigations

Evidence collection and analysis under a rigorous chain of custody: endpoints, servers, logs and cloud.

Incident response

Containment, eradication and recovery, with technical coordination and support to crisis management.

What you get

Deliverables & approach

  • Fast, structured intervention
  • Evidentiary value preserved
  • Compromise analysis (timeline, IOCs)
  • Report and lessons learned
  • Hardening recommendations
Request a quote
Methodology

How an incident response unfolds

  1. 1
    Detection
    Qualifying the alert and scoping the affected perimeter.
  2. 2
    Containment
    Holding the threat back to stop it spreading.
  3. 3
    Eradication
    Removing the attacker's presence and any residual access.
  4. 4
    Recovery
    Return to a trusted environment, under close watch.
  5. 5
    Lessons learned
    Analysis (timeline, IOCs) and hardening recommendations.
Frequently asked questions

Frequently asked questions

Do not power the machines off and do not rebuild them: volatile memory and logs often hold most of what will explain the incident. Isolate from the network rather than shut down, preserve logs before they roll over, note the time and nature of every action taken, and move internal communication to a channel known not to be compromised. Then call. The decisions of the first hour shape everything that follows.

Yes. The emergency number on this page is open, and an initial assessment is done by phone to gauge the situation and the immediate steps. Contracting follows, it does not come first. That said, a retainer prepared in calm conditions — scope known, contacts identified, access arranged — buys back the hours that matter most.

That is what the chain of custody is for: every item is collected, hashed, sealed and traced, so that it can be shown not to have been altered between collection and analysis. We work that way by default, even when no complaint is being considered — the decision to take the matter further often comes later. Admissibility is then for the authority seized of the case and your legal counsel; our part is not to compromise it.

Prepare now, or respond right now.

Whether you are anticipating an incident or facing one, our cybersecurity team is with you.