Isolate, don't power off
Pull affected systems off the network, but leave them running. Memory holds credentials, running processes, and attacker tooling that a shutdown destroys permanently.
If you are dealing with an active intrusion — ransomware, a compromised mailbox, data you believe has been taken, or activity you cannot explain — tell us what you are seeing and we will get responders on it.
If you hold a Nosleinad Retainer, use the escalation path in your engagement documents — it reaches us faster than this page.
The hours before responders arrive are where evidence is most often lost — usually with the best intentions.
Pull affected systems off the network, but leave them running. Memory holds credentials, running processes, and attacker tooling that a shutdown destroys permanently.
EDR, firewall, VPN, mail and identity logs are where the answer lives. Retention windows are often shorter than the dwell time, so export before they roll over.
Assume the intruder can read internal email and chat. Coordinate by phone or a channel that does not touch the environment you are investigating.
Opening a conversation with an attacker changes your position, and sanctions screening has to come first. Preserve the note and any contact details, and leave it there.
Nothing here is required beyond a way to reach you. Fill in what you know — we would rather start with a partial picture than wait for a complete one.
We come back to establish what you are dealing with, what is still running, and what needs to stop moving before anything else happens.
We agree what the engagement covers, who from your side we need, and which systems and logs we require access to. Retainer clients skip this.
Containment and eradication run in parallel with the investigation, so the intrusion stops while we establish how far it reached.
This page is for organisations reporting a security incident. For personal accounts, or anything unrelated to an incident, use the general contact route instead.