Skip to main content

The first hour after an incident

Ransomware and breach response, forensics and response drills

Most of the damage from ransomware and intrusions happens in the first hours after discovery. We provide emergency response, digital forensics and evidence preservation, TTP retrospectives and attribution, and before that, playbooks, tabletop and live-fire exercises, so the response does not depend on improvisation.

Our approach

One team scopes, executes and retests; conclusions are delivered as evidence, not checklists.

01

Remote within 2 hours, on site within 24

Response teams are based in Hefei, Shanghai and Shenzhen, covering East, South and Central China. Once connected remotely, isolation and evidence preservation begin before on-site staff arrive.

02

Forensics and remediation in parallel; the evidence chain holds up for regulators and courts

Images and logs are preserved to ISO/IEC 27037 with hashes and an operation timeline. The forensic package meets regulatory filing and judicial appraisal requirements, so you do not have to choose between restoring service and keeping evidence.

03

The retrospective produces verifiable remediation items

The report describes attacker techniques in ATT&CK terms and identifies the exploited weaknesses and detection gaps. Each remediation item can be verified by penetration testing or managed operations, closing the loop.

Deliverables

01

Incident report

Timeline, intrusion path, impact and containment measures, ready for internal briefing and regulatory filing.

02

Forensic package

Chain of custody, images and hash records that meet compliance and legal requirements; preservation before remediation.

03

Playbooks

One per incident type, with drill records and role assignments, updated after every exercise.

How we deliver

Four stages, each with defined inputs, outputs and a client sign-off.

010–2 hours

Connect and contain

Connect remotely, establish impact, isolate affected hosts, preserve volatile evidence.

022–48 hours

Investigate and preserve

Locate initial access and lateral path, extract samples, fix the evidence chain, assess data impact.

031–5 days

Eradicate and recover

Remove persistence, restore systems by priority, verify the security state after recovery.

04Within 2 weeks of recovery

Retrospective and hardening

Deliver the retrospective and remediation list, update playbooks, run a tabletop exercise.

Case

Chinese EV manufacturer — ransomware incident response

Several servers on the production network were encrypted and the line was at risk of stopping. We connected remotely within 2 hours, isolated and imaged first, then traced the initial entry and lateral path, and restored core systems within 48 hours. The retrospective identified the techniques and weak points, verified afterwards by penetration testing.

Frequently asked questions

Notes on scope, execution and delivery standards. Contact us for anything not covered here.

After a report via the emergency line or mailbox, the duty engineer calls back within 30 minutes to confirm incident type and impact, and remote access with containment begins within 2 hours. Clients with an annual agreement are dispatched first under its terms; others are billed per incident under the same procedure.

Start from where you stand

Security, data and AI each start with a review of where you stand. The report and its findings are yours, whether or not the engagement continues.