Containment · Forensics

Incident Response

Offensive mindset. Defensive results.

Rapid containment, thorough investigation, and recovery with the root cause eliminated. When every minute counts, you need experienced hands.

Capabilities

How we help

Breach Containment

Immediate guidance to isolate compromised systems, revoke credentials, and stop active attackers from moving laterally.

Digital Forensics

Evidence-preserving investigation of logs, disk images, memory dumps, and network captures to determine what happened.

Root Cause Analysis

Identify exactly how the attacker got in, what they accessed, and which vulnerabilities were exploited.

Recovery & Hardening

Rebuild compromised systems securely, patch exploited vulnerabilities, and implement controls to prevent recurrence.

Incident Documentation

Complete timeline and technical report suitable for internal stakeholders, legal counsel, and regulatory notifications.

Lessons Learned

Post-incident review workshop with your team to improve detection, response procedures, and overall security posture.

Response lifecycle

The IR process

The phases below follow NIST SP 800-61, compressed for the reality that during a live incident the first hour matters more than the next ten. If you are in one now, contact us first and read this afterwards.

  1. 01

    Detect & Triage

    The first job is to establish what is actually happening, because a meaningful share of “we have been hacked” calls turn out to be a misconfiguration, a pen test nobody told the SOC about, or a bill for a crypto-miner that was running for a week. We work from the evidence you have — alerts, logs, the ransom note, the odd outbound traffic — and confirm or rule out compromise.

    If it is real, we classify it: what kind of intrusion, which systems are implicated, whether the attacker is still active, and whether regulated data is in play. You get containment guidance during this phase, not after it, including what not to do — rebooting the affected host or deleting the malware is the most common way evidence is destroyed before anyone understands what happened.

    You provide
    Access to logs and affected systems, and one decision-maker who can authorise disruptive action.
    We do
    Validate the incident, classify severity and type, identify patient zero, and establish a timeline.
    You get
    A confirmed severity call, an initial scope of compromise, and immediate do/do-not-do guidance.
    Typical time
    First 1–4 hours
  2. 02

    Contain

    Containment buys time without destroying the evidence you will need later. That usually means network isolation rather than shutdown, revoking sessions and credentials rather than only resetting passwords, and taking memory and disk images of key hosts before they are touched.

    We prioritise cutting the attacker's access and stopping lateral movement: killing persistence on identity systems, rotating the credentials that matter (service accounts and API keys before user passwords), and closing the route in. Containment is staged so that each step is reversible if it turns out to harm operations more than the intrusion does.

    You provide
    Authority to isolate systems and revoke credentials, plus access to your identity and network controls.
    We do
    Isolate affected hosts, revoke attacker access, preserve forensic images, and block the entry vector.
    You get
    Attacker access cut off, a preserved evidence set, and a written containment log.
    Typical time
    Hours 2–24
  3. 03

    Eradicate

    With the attacker locked out we remove what they left behind: malware and web shells, scheduled tasks and services created for persistence, rogue accounts and OAuth grants, modified startup items, and any tampering with logging or backups. Every host implicated in the timeline is checked, not just the one that raised the alert.

    In parallel we close the vulnerability that allowed entry — the unpatched service, the exposed admin panel, the phished account without MFA. Skipping this step is why organisations get hit twice by the same actor within a month.

    You provide
    Patching windows, and willingness to rebuild rather than clean hosts where that is the safer call.
    We do
    Remove malware and persistence, close the entry vector, harden the affected identity and access paths.
    You get
    A cleaned, documented environment with the initial access route closed.
    Typical time
    1–5 days
  4. 04

    Recover

    Systems come back in a controlled sequence, restored from backups verified as predating the compromise — a step worth being pedantic about, since restoring a backdoored backup is a well-worn way to restart an incident. Integrity is checked before each system rejoins the network.

    For the first weeks after recovery we run enhanced monitoring focused on the attacker's known techniques and indicators, because attempted re-entry is common and the second attempt is usually quieter than the first.

    You provide
    Backup access and restore testing capacity; a decision on the order services come back.
    We do
    Staged restoration, integrity verification, and heightened monitoring tuned to this attacker.
    You get
    Verified clean systems back in service, with watch-list detections in place.
    Typical time
    2–10 days
  5. 05

    Post-Incident Review

    You receive a written report: the timeline of what happened, how entry was gained, what the attacker did and touched, what data was and was not affected, and what stopped them. It is written to be usable in the conversations that follow — with your board, your customers, your insurer, and where required your regulator.

    The last section is the one that pays for the engagement: the specific changes, ranked, that would have prevented this or caught it sooner. We keep it honest, including where the answer is an unglamorous control like egress filtering or offline backups rather than a new product.

    You provide
    Time for a review session, and any internal notes kept during the incident.
    We do
    Root-cause analysis, full timeline reconstruction, impact and data-exposure assessment, lessons learned.
    You get
    An incident report suitable for board, customer, insurer and regulator use, plus a prevention roadmap.
    Typical time
    3–7 days after recovery
FAQ

Common questions

What is incident response in cybersecurity?

Incident response is the organised process of detecting, containing, eradicating, and recovering from a cybersecurity incident such as a data breach, ransomware attack, or unauthorised access. The goal is to limit damage, preserve evidence, and prevent recurrence.

How quickly can Secracy respond to an incident?

We aim to begin initial triage within 2-4 hours of engagement. For active incidents, containment guidance is provided immediately while the full investigation is set up.

What should I do if I think I've been breached?

First, do not shut down affected systems as this can destroy forensic evidence. Isolate compromised systems from the network, preserve all logs, and contact us immediately at contact@secracy.in. We will guide you through the next steps.

Incident in progress? We're here.

Don't wait. Reach out now and we'll help you contain the situation and start recovery.