Incident response & crisis support

Under attack? Get immediate assistance.

Senior responders on standby to contain, investigate and recover, wherever your systems are. Available 24/7 on part and full retainers. If you are dealing with an incident now, use the urgent form below.

Urgent report

Tell us what is happening

Your report goes straight to our team and is flagged as urgent. Share only what you're comfortable with; we'll follow up to understand the details.

Include your country code, e.g. +20.
If your email may be compromised, use a different address.
Is the incident still ongoing? *
Never send passwords, keys or other credentials in this form.
How we help

From first call to full recovery

  1. 01

    Triage

    We assess what is happening, how far it has spread and what needs protecting first.

  2. 02

    Containment

    We help you stop the attack spreading and cut off the attacker's access.

  3. 03

    Investigation

    Forensic analysis to establish how they got in, what they touched and what data is affected.

  4. 04

    Recovery

    Clean restoration of systems and services, with the entry point closed so it doesn't happen again.

  5. 05

    Report & hardening

    A clear incident report for management and practical fixes to strengthen your defences.

What we respond to

Incidents we handle

01

Ransomware / files encrypted

02

Data breach or data leak

03

Email or account takeover

04

Website hacked or defaced

05

Malware or suspicious activity

06

DDoS / service down from an attack

07

Payment fraud or fake invoice emails

Retainers

Be ready before it happens

Clients on part and full incident response retainers get 24/7 access to senior responders, agreed response procedures and a team that already knows their environment.

Ask about retainers
01

Part retainer

On-call access to senior responders with agreed response procedures, for organisations that want a plan in place.

02

Full retainer

24/7 priority response backed by preparation work, so responders already know your systems when it matters.

Questions

Incident response FAQ

Can you help if we're not a CYBEROCO client?

Yes. Send the urgent report and our team will review it. 24/7 guaranteed availability is part of our retainers; for everyone else we respond as quickly as our team can.

Should we pay the ransom?

Don't pay or negotiate before speaking to responders. Payment doesn't guarantee your data back or that it won't be leaked, and there may be legal implications.

Should we switch the affected computers off?

No. Disconnect them from the network but keep them powered on. Shutting down can destroy evidence held in memory that helps us understand the attack.

What information should we have ready?

When the problem started, which systems and accounts are affected, any ransom notes or suspicious messages, and what has been done since. Don't worry if you don't have everything.

Is what we tell you kept confidential?

Yes. Incident details are shared only with the responders working on your case.