Digital forensics & incident response
React quickly and correctly when an incident hits: understand what happened, contain the threat and restore a trusted environment. The moment cybersecurity is measured in hours, not weeks.
Incident under way?
Contact us straight away for an initial assessment.
Digital forensics & incident response
Understand, contain, recover.
When an incident occurs, we rebuild the timeline, preserve evidentiary value and restore a trusted environment — quickly and methodically, alongside your IT and cybersecurity teams.
InvestigationContainmentIOCChain of custody
Services
Services in detail
Digital investigations
Evidence collection and analysis under a rigorous chain of custody: endpoints, servers, logs and cloud.
Incident response
Containment, eradication and recovery, with technical coordination and support to crisis management.
What you get
Deliverables & approach
- Fast, structured intervention
- Evidentiary value preserved
- Compromise analysis (timeline, IOCs)
- Report and lessons learned
- Hardening recommendations
Methodology
How an incident response unfolds
- 1DetectionQualifying the alert and scoping the affected perimeter.
- 2ContainmentHolding the threat back to stop it spreading.
- 3EradicationRemoving the attacker's presence and any residual access.
- 4RecoveryReturn to a trusted environment, under close watch.
- 5Lessons learnedAnalysis (timeline, IOCs) and hardening recommendations.
Related use cases
This service in practice
Frequently asked questions
Frequently asked questions
Do not power the machines off and do not rebuild them: volatile memory and logs often hold most of what will explain the incident. Isolate from the network rather than shut down, preserve logs before they roll over, note the time and nature of every action taken, and move internal communication to a channel known not to be compromised. Then call. The decisions of the first hour shape everything that follows.
Yes. The emergency number on this page is open, and an initial assessment is done by phone to gauge the situation and the immediate steps. Contracting follows, it does not come first. That said, a retainer prepared in calm conditions — scope known, contacts identified, access arranged — buys back the hours that matter most.
That is what the chain of custody is for: every item is collected, hashed, sealed and traced, so that it can be shown not to have been altered between collection and analysis. We work that way by default, even when no complaint is being considered — the decision to take the matter further often comes later. Admissibility is then for the authority seized of the case and your legal counsel; our part is not to compromise it.
Prepare now, or respond right now.
Whether you are anticipating an incident or facing one, our cybersecurity team is with you.