Incident Response and Digital Forensics (DFIR)
If you are dealing with an active cyber incident, the first hours are critical. Our incident response team scopes the attack, stops its spread, removes the attacker from your environment and establishes what happened while preserving evidence integrity: where did the attacker get in, what did they access, are they still inside? We then help you bring your systems back safely and prevent the same incident from happening again.
We take the first steps together
When you call us, we assess the incident with you and plan the first containment steps together.
Evidence integrity
Investigations preserve the chain of custody; findings can be used in legal proceedings and insurance claims.
With you end to end
From containment to recovery, from KVKK notification to post-incident improvements, we manage the process together.
First steps during an incident
- Do not power off affected systems; isolate them from the network: evidence in memory is preserved and the spread of the attack is stopped.
- Preserve evidence: do not delete logs, suspicious files or ransom notes; get expert advice before rebuilding systems.
- Plan credential changes: change administrator and service account passwords in a coordinated way once the attacker’s access is understood.
- Do not rush the ransom decision: first assess the scope of the incident and whether the data can actually be recovered.
- Manage communication from a single point: involve management, legal and corporate communications early.
Which incidents do we respond to?
Ransomware and destructive attacks
Data encryption, attacks on backups, wiper malware and double-extortion attacks that threaten to publish data.
Data breaches and leaks
Theft of customer and employee data, source code or trade secret leaks, and your data appearing on underground forums or leak sites.
Identity and account compromise
Compromise of Active Directory, Microsoft 365 / Entra ID and cloud administrator accounts, MFA bypass and session hijacking attacks.
Email and payment fraud
Business email compromise (BEC), fake invoices and payment redirection, and accounts taken over after phishing emails.
Cloud and SaaS breaches
Unauthorised access to AWS, Azure and GCP accounts, exposed storage, unauthorised resource use (crypto mining), Microsoft 365 and Google Workspace incidents.
Web, application and server breaches
Web shells and backdoors, malicious code injection, card skimming on payment pages and website defacement.
Malware and persistent threats
Remote access trojans (RATs), infostealers, command and control traffic and attackers who have stayed inside undetected for a long time.
Supply chain and third parties
Attacks through suppliers, service providers or remote support connections, and compromised software components.
Insider threats
Abuse of privileges, departing employees taking data and suspected internal sabotage.
Where we investigate
- Endpoints and servers: Windows, Linux and macOS systems; virtualisation environments; disk and memory images
- Identity infrastructure: logs from Active Directory, Entra ID and other identity providers
- Cloud and SaaS: AWS, Azure and GCP audit logs; Microsoft 365 and Google Workspace logs
- Email: mailbox rules, sign-in history, message traces
- Network and security devices: firewall, VPN, proxy and DNS logs; EDR and SIEM data
If in doubt, do not wait
Not every incident starts with a ransom note. Administrator sign-ins at unusual hours, unexplained new accounts or mailbox forwarding rules, EDR alerts, unexpected outbound connections, fraud reports from customers or news that your data has been shared on a forum can all be the first signs of a breach. If you are not sure, call us and we will verify the suspicion together. Even without symptoms, we can investigate whether a hidden breach exists in your environment with a compromise assessment.
Our response process
We run our engagements according to the NIST SP 800-61 incident response lifecycle:
- Initial assessment: the type of incident, affected systems and urgency are established; a response plan and communication channel are set up.
- Containment: the attacker’s access is cut and the spread is stopped; systems critical to business continuity are prioritised.
- Forensic investigation: disk, memory, log and cloud records are examined with the chain of custody preserved; the attack path and timeline are reconstructed.
- Eradication: persistence mechanisms, malware and backdoors are removed; compromised accounts are secured.
- Recovery: systems are safely brought back into service and closely monitored for any return of the attacker.
- Post-incident review: the root cause, lessons learned and lasting improvements are reported.
What sets us apart
- A team that knows the attacker: our team works on the offensive side in penetration tests and Red Team operations, so they know the path an attacker follows and the traces they leave, which makes scoping faster and more accurate.
- Business continuity comes first: we plan containment and recovery steps with your technical teams, with your critical business processes in mind.
- Coordination with legal and communications: we prepare the technical information needed for KVKK notification, insurance and legal proceedings together with your legal and communications teams.
- Closure is verified by testing: after the incident we verify with a penetration test that the attacker’s paths are closed, and we can place your internet-facing assets under attack surface management.
KVKK breach notification
Under Turkey’s Personal Data Protection Law (KVKK), when personal data is obtained by unauthorised parties, the data controller must notify the Personal Data Protection Board as soon as possible and within 72 hours at the latest. During the incident we identify the affected data categories and number of people and prepare the technical information needed for the notification together with your legal team.
What you receive
- An executive summary for management and an incident report for technical teams
- An attack timeline and attack path analysis
- An indicators of compromise (IOC) list and detection recommendations
- Root cause analysis and prioritised improvement recommendations
- Supporting documentation for legal proceedings, insurance and KVKK notification where needed
Incident readiness
The best response is one that was prepared in advance. We prepare your organisation for a potential incident with incident response plans and playbooks, tabletop exercises, executive-level crisis simulations, logging and forensic readiness assessments, and compromise assessments.
Frequently asked questions
We have been hit by ransomware. What should we do?
Isolate affected systems from the network without powering them off, do not delete logs or suspicious files, and do not rush the decision to pay a ransom. Call us right away; our team will scope the incident and plan the containment steps with you.
Do we have to report a cyber incident to the KVKK?
When personal data is obtained by unauthorised parties, the data controller must notify the Personal Data Protection Board as soon as possible and within 72 hours at the latest. We prepare the technical information needed for the notification together with your legal team.
Why is a forensic investigation important?
A forensic investigation reveals how the attacker got in, what data they accessed and whether they are still inside. An investigation that preserves the chain of custody can also be used in legal proceedings and insurance claims.
How can we reach your incident response team?
For an active incident, call us on +90 212 993 66 64. For non-urgent requests, please use the contact form.
We are not sure whether there has been a breach. Should we still call?
Yes. We assess signs such as a suspicious alert, an unusual sign-in or a fraud report with you and verify whether there is a real incident. Even without symptoms, we can investigate whether a hidden breach exists with a compromise assessment.
Let’s define your scope together
Tell us what you need and we will prepare a tailored proposal.