Cyber Forensics & Investigation
Incident Response
Containment, eradication and recovery, led by responders who have done it under pressure before.
Every engagement includes manual validation, a two audience report and free re-testing.
Get a scoped quote+91 96682 00222What this actually is
When it happens, the first hour matters more than the next month. Wrong moves early destroy the evidence you will need and sometimes make the containment worse.
We respond, contain and recover, and we do it in a way that preserves the trail so you can answer your regulator, your insurer and your board afterwards.
Retainer clients get a named team who already know their estate. That is the difference between a response starting immediately and a response starting after four hours of onboarding.
What we go after
- Immediate triage and severity assessment
- Evidence preservation before containment
- Containment and eradication
- Malware and ransomware analysis
- Recovery planning and validation
- Regulatory notification support within required timelines
- Post-incident review and hardening
- Communications support for internal and external audiences
How we run it
- 01
Preserve
First priority is evidence integrity. We image and hash before anyone starts changing things.
- 02
Contain
Stop the bleeding without destroying the trail. These two goals fight each other, and experience is what balances them.
- 03
Investigate
Timeline reconstruction across endpoint, network, cloud and identity, until we can say what happened and when.
- 04
Report
Findings written to survive scrutiny from a regulator, an insurer or a court.
- 05
Harden
The root cause fixed, not just the symptom, so the same door is not open next quarter.
What you receive
- Incident timeline and impact assessment
- Containment and eradication actions log
- Forensic report suitable for regulator and insurer
- Recovery validation
- Post-incident hardening plan
Who needs this
Everyone, ideally before they need it. Retainers exist so the call is already answered when the day comes.
How long it takes
Response begins within hours for retainer clients, same or next business day otherwise.
Standards this satisfies
- NIST SP 800-61
- ISO 27035
- CERT-In reporting
- DPDP Act
Why it matters
After an incident there are three questions that have to be answered, and none of them can be answered well without preparation: when did it start, what was actually taken, and is the attacker still inside. Regulators, insurers and customers all ask them, and vague answers are treated as bad ones.
The most common problem we meet is that the evidence is already gone. Systems rebuilt, logs rotated, machines rebooted in good faith before anything was preserved. How the first hour is handled decides whether the rest of the investigation is possible.
Choose how you want this delivered
Most of the price difference between quotes comes down to this one choice, and it is rarely explained. Pick one to see what it covers, what it suits and what it costs you.
Terms, contacts and access agreed in advance, with a guaranteed response time. The value is not the discount, it is that the first day is spent responding rather than negotiating a contract while an intruder is still active.
Choose this when
- Any organisation holding regulated or personal data
- Boards or insurers asking about incident readiness
- You want the mobilisation clock to start in minutes, not days
Effort and cost
An annual fee, with unused hours typically usable for proactive work. The cheapest reduction in breach cost available.
Scope it yourself, before you call anyone
Answer a few questions and you get an indicative number, the working behind it and what your answers tell us. It runs in your browser, so nothing you type reaches us.
Roughly how many personal records do you hold?
What we look for, and keep finding
These are the classes of problem this work exists to surface. Not every engagement finds all of them, but these are the ones that turn up often enough to be worth naming.
Evidence destroyed by the response
The most common problem we meet. Systems rebuilt, logs rotated, machines rebooted before anything was preserved. What could have been established is often gone before we arrive.
Incomplete timeline
Knowing the breach happened but not when it began. Without an accurate first access, scope cannot be bounded and notification obligations cannot be answered honestly.
Unclear data exposure
The question every regulator and customer asks: what was actually taken. Answering it needs artefacts that only exist if logging and retention were adequate beforehand.
Chain of custody failures
Evidence handled in a way that will not survive challenge. If there is any prospect of proceedings, how the first hour was handled decides whether the findings are usable.
Persistence left behind
Recovery declared complete while access remains. We look specifically for the second and third mechanism, because a competent intruder does not rely on one.
Who runs your engagement
Investigators who have given evidence
Investigations are led by people who have produced findings that survived challenge. Our founder advises law enforcement and has trained officers in cyber crime investigation, so the method is one that police and courts recognise.
Questions we get asked
Should we pay a ransom?
That is your decision and it has legal and practical dimensions we will walk through with you. What we will tell you honestly is whether decryption is likely to work, whether the data is already gone, and what recovery without payment looks like.
How fast must we report to CERT-In?
Within six hours of noticing, for the incident types the directions specify. That clock is short, which is why the reporting workflow needs to exist before the incident rather than during it.
Often scoped alongside
- Digital ForensicsDisk, memory and log forensics that reconstruct the intrusion timeline and preserve the chain of custody.Read more
- Cyber Crime InvestigationInvestigative support for fraud, insider theft and law enforcement matters, with advisory experience across Indian agencies.Read more
- Crypto & Financial TracingBlockchain and payment trail analysis that follows stolen funds through mixers, exchanges and mule accounts.Read more
- Email & Cloud InvestigationBusiness email compromise and cloud tenant investigations across Microsoft 365, Google Workspace and IaaS audit logs.Read more
Ready to scope your incident response?
Thirty minutes with a senior engineer, and you leave with a written scope and indicative effort.












