Latest alerts
  1. Home
  2. Incident response
// incident response · 24/7

Under attack? We'll help right now.

Ransomware, a hacked website, suspicious logins, a data leak or a fraudulent payment email — call us first. Every minute counts, and so does the evidence.

Call the incident line+91 00000 00000

Can't call? Use the form — it alerts our team immediately.

Request an urgent call-back

We use these details only to contact you about this incident. Kept up to 12 months, encrypted. Privacy notice

Our team has been alerted

We'll call you as soon as possible. If you haven't heard from us in 30 minutes, call +91 00000 00000.

// the first hour

What to do right now — and what not to.

Do

  1. Disconnect, don't switch off. Pull the network cable or turn off Wi-Fi on affected machines. Powering off destroys evidence in memory.
  2. Keep everything. Logs, ransom notes, suspicious emails, screenshots — don't delete or "clean up" yet.
  3. Change passwords from a clean device — email, admin and banking first — and turn on 2FA.
  4. Write down a timeline: when you noticed, what you saw, who did what.
  5. Call us. We'll help contain it and prepare the CERT-In report, which is due within 6 hours of noticing a reportable incident.

Don't

  • Don't pay a ransom before talking to professionals — payment doesn't guarantee recovery and can create legal and sanctions risk.
  • Don't wipe or reinstall systems before evidence is preserved.
  • Don't use the compromised email to discuss the incident — attackers may be reading it.
  • Don't announce it publicly before you know the facts — but do plan DPDP notifications if personal data is involved.
  • Don't plug in backups until the infection is contained.
// how we respond

From first call to back in business

01

Triage

A responder calls you, assesses scope and tells you what to do immediately.

02

Contain

Isolate affected systems, block the attacker's access, stop the spread.

03

Investigate

Forensics to find the entry point, what was accessed and what was taken.

04

Recover

Clean rebuilds, restore from safe backups, harden what was exploited.

05

Report

CERT-In report, DPDP breach notifications where needed, lessons learned.

Call Email Under attack? Free DPDP Check