Services
Partners
Use cases
Clients
Company
Contact
FRENDE
Response & resilience

Responding to a compromise

Ransomware, account compromise, exfiltration: when an incident hits, every hour counts. Here is how we intervene to contain, understand, recover — and make sure it does not happen again.

The challenge

Act fast, but act right

Faced with a compromise, haste is expensive: switching a machine off can destroy evidence, restoring too early can let the attacker back in. The right response combines speed with method — contain without destroying, investigate to establish the real extent, then restore on sound foundations.

The attacker's dwell time often determines the scale of the damage. Structured detection and response shorten it, limit the impact and speed up the return to normal.

Our role: to be alongside you through the whole response cycle, preserve evidentiary value, and turn the ordeal into lasting hardening — with continuous monitoring, if needed, to prevent a repeat.

What is at stake
  • Evidence destroyed by hasty action
  • The real extent of the compromise underestimated
  • The attacker let back in during recovery
  • Business interruption and regulatory / communication pressure
  • A repeat, for want of hardening and detection
Diagram

Incident response cycle

Incident response cycle 1Prepa-ration2Detection& analysis3Contain-ment4Eradi-cation5Reco-very6LessonslearnedContinuous improvement
A structured cycle (preparation, detection, containment, eradication, recovery, lessons learned) that feeds continuous improvement.
Our approach

How we proceed

A scoped intervention across the whole cycle, from the first call to the lessons learned.

01

Scoping & containment

Immediate handling: qualifying the incident and taking first containment measures to stop it spreading, while preserving evidence.

02

Forensic investigation (DFIR)

Evidence collection and analysis under a rigorous chain of custody: rebuilding the timeline, identifying the initial vector, the lateral movement and the data affected (IOCs).

03

Eradication & recovery

Removal of the attacker's access and implants, then controlled recovery on sound foundations, without letting the threat back in.

04

Hardening

Fixing the flaws that were exploited and hardening the weak points (identity, exposure, configuration) to cut the attack paths.

05

Continuous detection & lessons

Setting up or strengthening monitoring (SOC) to catch any resumption, and documented lessons learned to improve the posture.

Services involved

Several disciplines, a single point of contact

Containing, understanding and recovering call on distinct skills that we bring together, in the emergency and over time.

Deliverables
  • Immediate containment measures
  • Forensic report (timeline, vector, scope, IOCs)
  • Eradication and recovery plan
  • Prioritised hardening recommendations
  • Lessons learned and detection capability
Frequently asked questions

Frequently asked questions

Avoid switching off or reinstalling the machines concerned (that destroys evidence) and isolate them from the network if you can. Then contact us: we frame the situation and begin containment while preserving evidentiary value.

Because restoring without understanding the initial vector often brings the attacker straight back. The investigation establishes how access was obtained and how far it spread — the condition for a lasting recovery.

It is never a guarantee and it sustains the criminal ecosystem. Our priority is to assess the technical options (containment, restoration, possible decryption) and help you decide with full knowledge of the facts, alongside your legal advisers.

By hardening the points that were exploited and by continuous detection. The lessons learned turn into concrete actions, and SOC monitoring makes any resumption of malicious activity visible quickly.

An incident under way, or one to anticipate?

Whether you are facing a compromise or preparing for one, our team is with you.