You're viewing Nosleinad Cyber — the security division of Nosleinad. Back to Nosleinad →
Nosleinad Cyber

Incident response assistance.

If you are dealing with an active intrusion — ransomware, a compromised mailbox, data you believe has been taken, or activity you cannot explain — tell us what you are seeing and we will get responders on it.

If you hold a Nosleinad Retainer, use the escalation path in your engagement documents — it reaches us faster than this page.

Before you do anything else

Four things that protect the investigation while you wait.

The hours before responders arrive are where evidence is most often lost — usually with the best intentions.

01

Isolate, don't power off

Pull affected systems off the network, but leave them running. Memory holds credentials, running processes, and attacker tooling that a shutdown destroys permanently.

02

Preserve the logs now

EDR, firewall, VPN, mail and identity logs are where the answer lives. Retention windows are often shorter than the dwell time, so export before they roll over.

03

Take the conversation off the network

Assume the intruder can read internal email and chat. Coordinate by phone or a channel that does not touch the environment you are investigating.

04

Don't respond to the extortion yet

Opening a conversation with an attacker changes your position, and sanctions screening has to come first. Preserve the note and any contact details, and leave it there.

Tell us what you are seeing

Send us the details.

Nothing here is required beyond a way to reach you. Fill in what you know — we would rather start with a partial picture than wait for a complete one.

Email us instead

Sending opens a message in your mail application with everything above filled in — nothing is submitted through this page. If you use webmail and nothing opens, take the second button and write to us directly.

What happens next

From your message to responders working.

First — triage

We come back to establish what you are dealing with, what is still running, and what needs to stop moving before anything else happens.

Then — scoping

We agree what the engagement covers, who from your side we need, and which systems and logs we require access to. Retainer clients skip this.

Then — response

Containment and eradication run in parallel with the investigation, so the intrusion stops while we establish how far it reached.

This page is for organisations reporting a security incident. For personal accounts, or anything unrelated to an incident, use the general contact route instead.