OMNIVERSE Facing a cyber incident?Incident?

Incident Response and Digital Forensics (DFIR)

If you are dealing with an active cyber incident, the first hours are critical. Our incident response team scopes the attack, stops its spread, removes the attacker from your environment and establishes what happened while preserving evidence integrity: where did the attacker get in, what did they access, are they still inside? We then help you bring your systems back safely and prevent the same incident from happening again.

We take the first steps together

When you call us, we assess the incident with you and plan the first containment steps together.

Evidence integrity

Investigations preserve the chain of custody; findings can be used in legal proceedings and insurance claims.

With you end to end

From containment to recovery, from KVKK notification to post-incident improvements, we manage the process together.

First steps during an incident

  1. Do not power off affected systems; isolate them from the network: evidence in memory is preserved and the spread of the attack is stopped.
  2. Preserve evidence: do not delete logs, suspicious files or ransom notes; get expert advice before rebuilding systems.
  3. Plan credential changes: change administrator and service account passwords in a coordinated way once the attacker’s access is understood.
  4. Do not rush the ransom decision: first assess the scope of the incident and whether the data can actually be recovered.
  5. Manage communication from a single point: involve management, legal and corporate communications early.

Which incidents do we respond to?

Ransomware and destructive attacks

Data encryption, attacks on backups, wiper malware and double-extortion attacks that threaten to publish data.

Data breaches and leaks

Theft of customer and employee data, source code or trade secret leaks, and your data appearing on underground forums or leak sites.

Identity and account compromise

Compromise of Active Directory, Microsoft 365 / Entra ID and cloud administrator accounts, MFA bypass and session hijacking attacks.

Email and payment fraud

Business email compromise (BEC), fake invoices and payment redirection, and accounts taken over after phishing emails.

Cloud and SaaS breaches

Unauthorised access to AWS, Azure and GCP accounts, exposed storage, unauthorised resource use (crypto mining), Microsoft 365 and Google Workspace incidents.

Web, application and server breaches

Web shells and backdoors, malicious code injection, card skimming on payment pages and website defacement.

Malware and persistent threats

Remote access trojans (RATs), infostealers, command and control traffic and attackers who have stayed inside undetected for a long time.

Supply chain and third parties

Attacks through suppliers, service providers or remote support connections, and compromised software components.

Insider threats

Abuse of privileges, departing employees taking data and suspected internal sabotage.

Where we investigate

If in doubt, do not wait

Not every incident starts with a ransom note. Administrator sign-ins at unusual hours, unexplained new accounts or mailbox forwarding rules, EDR alerts, unexpected outbound connections, fraud reports from customers or news that your data has been shared on a forum can all be the first signs of a breach. If you are not sure, call us and we will verify the suspicion together. Even without symptoms, we can investigate whether a hidden breach exists in your environment with a compromise assessment.

Our response process

We run our engagements according to the NIST SP 800-61 incident response lifecycle:

  1. Initial assessment: the type of incident, affected systems and urgency are established; a response plan and communication channel are set up.
  2. Containment: the attacker’s access is cut and the spread is stopped; systems critical to business continuity are prioritised.
  3. Forensic investigation: disk, memory, log and cloud records are examined with the chain of custody preserved; the attack path and timeline are reconstructed.
  4. Eradication: persistence mechanisms, malware and backdoors are removed; compromised accounts are secured.
  5. Recovery: systems are safely brought back into service and closely monitored for any return of the attacker.
  6. Post-incident review: the root cause, lessons learned and lasting improvements are reported.

What sets us apart

KVKK breach notification

Under Turkey’s Personal Data Protection Law (KVKK), when personal data is obtained by unauthorised parties, the data controller must notify the Personal Data Protection Board as soon as possible and within 72 hours at the latest. During the incident we identify the affected data categories and number of people and prepare the technical information needed for the notification together with your legal team.

What you receive

Incident readiness

The best response is one that was prepared in advance. We prepare your organisation for a potential incident with incident response plans and playbooks, tabletop exercises, executive-level crisis simulations, logging and forensic readiness assessments, and compromise assessments.

Frequently asked questions

We have been hit by ransomware. What should we do?

Isolate affected systems from the network without powering them off, do not delete logs or suspicious files, and do not rush the decision to pay a ransom. Call us right away; our team will scope the incident and plan the containment steps with you.

Do we have to report a cyber incident to the KVKK?

When personal data is obtained by unauthorised parties, the data controller must notify the Personal Data Protection Board as soon as possible and within 72 hours at the latest. We prepare the technical information needed for the notification together with your legal team.

Why is a forensic investigation important?

A forensic investigation reveals how the attacker got in, what data they accessed and whether they are still inside. An investigation that preserves the chain of custody can also be used in legal proceedings and insurance claims.

How can we reach your incident response team?

For an active incident, call us on +90 212 993 66 64. For non-urgent requests, please use the contact form.

We are not sure whether there has been a breach. Should we still call?

Yes. We assess signs such as a suspicious alert, an unusual sign-in or a fraud report with you and verify whether there is a real incident. Even without symptoms, we can investigate whether a hidden breach exists with a compromise assessment.

Let’s define your scope together

Tell us what you need and we will prepare a tailored proposal.

Related services