The first hour after an incident
Ransomware and breach response, forensics and response drills
Most of the damage from ransomware and intrusions happens in the first hours after discovery. We provide emergency response, digital forensics and evidence preservation, TTP retrospectives and attribution, and before that, playbooks, tabletop and live-fire exercises, so the response does not depend on improvisation.
Our approach
One team scopes, executes and retests; conclusions are delivered as evidence, not checklists.
Remote within 2 hours, on site within 24
Response teams are based in Hefei, Shanghai and Shenzhen, covering East, South and Central China. Once connected remotely, isolation and evidence preservation begin before on-site staff arrive.
Forensics and remediation in parallel; the evidence chain holds up for regulators and courts
Images and logs are preserved to ISO/IEC 27037 with hashes and an operation timeline. The forensic package meets regulatory filing and judicial appraisal requirements, so you do not have to choose between restoring service and keeping evidence.
The retrospective produces verifiable remediation items
The report describes attacker techniques in ATT&CK terms and identifies the exploited weaknesses and detection gaps. Each remediation item can be verified by penetration testing or managed operations, closing the loop.
Deliverables
Incident report
Timeline, intrusion path, impact and containment measures, ready for internal briefing and regulatory filing.
Forensic package
Chain of custody, images and hash records that meet compliance and legal requirements; preservation before remediation.
Playbooks
One per incident type, with drill records and role assignments, updated after every exercise.
How we deliver
Four stages, each with defined inputs, outputs and a client sign-off.
Connect and contain
Connect remotely, establish impact, isolate affected hosts, preserve volatile evidence.
Investigate and preserve
Locate initial access and lateral path, extract samples, fix the evidence chain, assess data impact.
Eradicate and recover
Remove persistence, restore systems by priority, verify the security state after recovery.
Retrospective and hardening
Deliver the retrospective and remediation list, update playbooks, run a tabletop exercise.
Case
Chinese EV manufacturer — ransomware incident response
Several servers on the production network were encrypted and the line was at risk of stopping. We connected remotely within 2 hours, isolated and imaged first, then traced the initial entry and lateral path, and restored core systems within 48 hours. The retrospective identified the techniques and weak points, verified afterwards by penetration testing.
Frequently asked questions
Notes on scope, execution and delivery standards. Contact us for anything not covered here.
After a report via the emergency line or mailbox, the duty engineer calls back within 30 minutes to confirm incident type and impact, and remote access with containment begins within 2 hours. Clients with an annual agreement are dispatched first under its terms; others are billed per incident under the same procedure.
Start from where you stand
Security, data and AI each start with a review of where you stand. The report and its findings are yours, whether or not the engagement continues.