An incident right now? Call us: +49 2058 175 566 0
See the first stepsOnce it has happened, every hour counts.
We take the first steps, secure court-admissible evidence, bring operations back in an orderly way and prepare your notifications under NIS2, DORA and GDPR. Best settled before you need it.
The first hours decide it
The four mistakes we see most often — all of them avoidable in advance.
Pulling the plug destroys evidence
The first reflex is to take everything off the network. That loses the contents of memory — and with it, often the only indication of how the attackers got in and what they took with them.
Notification deadlines start at the point of awareness
NIS2 and the GDPR attach to the moment the incident becomes known to you — not the moment you have understood it. Start documenting two days in and half the window is already gone.
The contact chain is missing when it matters
Who decides to halt production? Who speaks to customers, who to the insurer? Without roles named in advance, the most expensive delays are not technical but organisational.
Recovery leads straight back into the same gap
Systems are restored from backup before the root cause is understood. The attackers are then often still inside — or come back in the same way.
What we take on when it counts
From the first report to the final one — technically, organisationally and in regulatory terms.
Emergency hotline
One number where an experienced responder picks up and works through the first steps with you — rather than a ticket that lands in a queue.
Forensics
Evidence collection across endpoints, servers and cloud environments. Timeline reconstruction, characterisation of attacker behaviour, an unbroken chain of custody.
Containment
Orderly containment of accounts, sessions, access tokens and persistence mechanisms — matched to your operations, so containment does not cause more damage than the attack.
Notifications under NIS2 and DORA
We prepare the substance of the initial, interim and final notifications, supply the technical evidence and record the timeline so it can be followed.
Recovery
A structured recovery plan that addresses the root cause — rather than a quick return to precisely the environment that was compromised.
Lessons learned
A workshop after the incident that summarises the findings so they carry in the reporting line to management — and turn into concrete measures.
The phases of an incident
Six steps that build on one another in this order — shortcuts come back to bite later.
Preparation
Settle roles, notification lines and access before anything happens.
Detection
Confirm the incident, bound its scope, preserve volatile traces.
Containment
Stop the spread without destroying evidence.
Eradication
Remove the attackers’ access, persistence and tooling completely.
Recovery
A controlled return to normal operations — with the root cause closed.
Follow-up
Final report, notifications, lessons learned, plan of measures.
Notification duties at a glance
The clock starts when you become aware — not when everything is understood.
| Legal basis | Deadlines |
|---|---|
| NIS2, Article 23 | Early warning within 24 hours, notification within 72 hours, final report within one month |
| GDPR, Article 33 | Notification to the supervisory authority within 72 hours of becoming aware |
| GDPR, Article 34 | Notification of data subjects without undue delay where the risk is high |
| DORA | Staged reporting of major ICT-related incidents to the competent authority |
Which duties apply to you depends on sector, size and the nature of the incident. We work that out with you during the engagement — the legal assessment stays with your legal advisers.
With a retainer or without
We help either way. The difference is what the engagement starts with.
| With a retainer | Without | |
|---|---|---|
| Response time | Contractually assured | Subject to current capacity |
| Contracts and confidentiality | Settled in advance | Negotiated during the incident |
| Knowledge of your environment | Recorded in advance, playbooks agreed | First survey while the incident is running |
| Day rates during an engagement | Reduced | Standard |
| Exercises | Tabletop exercises included in scope | Commissioned separately |
Typical incidents
Three examples from practice — covered in more depth on the emergency page.
Ransomware
Encrypted file servers, halted production, an extortion note. Isolate, preserve forensically, assess the payment question in a structured way, restore in priority order.
Compromised mailboxes
Manipulated forwarding rules, fraudulent payment requests, access through stolen session tokens. Review the mail flow, harden sign-in, secure the payment path.
Data exfiltration
Exfiltration through cloud storage, removable media or interfaces. Assess the nature, extent and sensitivity of the data and prepare the notification to the supervisory authority.
What you get
- A final report that holds up with authorities and insurers
- A reconstructed timeline of the attack
- A list of indicators of compromise for your own follow-up search
- Drafts for communication with authorities, customers and employees
- A prioritised plan of measures with an effort estimate
- A lessons-learned workshop with everyone involved
Frequently asked questions
- We have an incident right now — what should we do?
- Call us: +49 2058 175 566 0. Do not pull affected systems off the network in a hurry, or volatile traces in memory are lost. Instead, write down what you can see and who did what and when. We will work through everything else with you on the phone.
- What is a retainer worth if we have never had an incident?
- It removes the start-up time when it counts. Contracts, the non-disclosure agreement and access arrangements are settled in advance, we already know your environment, and the response time is contractually assured. Without a retainer every engagement begins with contract negotiation and a first survey — time that is particularly expensive during an incident.
- What does an engagement cost?
- The first call, including an initial assessment of the situation, is free. After that we work on day rates against an agreed time budget. Retainer clients pay reduced rates when an engagement starts. Terms on request.
- Who files the NIS2 or GDPR notification?
- You do, as the affected organisation. We prepare the content, the form and the timeline, supply the technical evidence and draft it together with you. Filing it, and the responsibility for doing so, stays with you — that cannot be outsourced.
- Should we pay in a ransomware case?
- We advise working through every alternative first: backups, available decryption tools, legal advice, your insurer’s requirements. Paying guarantees neither recovery nor the attackers’ silence, and it can be difficult under sanctions and tax law. We assess the situation with you in a structured way rather than taking the decision off your hands.
- Do you work with our cyber insurer?
- Yes. Many policies require a particular notification chain and documented steps, otherwise the settlement is reduced. We shape the documentation from the outset so that it can be used with insurers, and coordinate directly with the loss adjuster where needed.
- How do you secure evidence so it can be used later?
- Every forensic step is logged, evidence is preserved to recognised standards and documented through hash values and an unbroken chain of custody. The final report is structured to hold up with supervisory authorities, insurers and, if it comes to it, in proceedings.
In an emergency, the right number is worth its weight in gold.
Put a retainer in place before you need it — and hope you never do.
How we work with you
We treat every engagement as a long-term partnership rather than a one-off delivery. Our approach is organised into four clear phases so that you always know what happens when, who owns which responsibility and which outcomes you can expect.
1. Free initial conversation
We learn about your starting position, your goals and the constraints you operate under. In 30 to 45 minutes we check whether our offering fits your situation, outline possible paths and answer your questions – no obligation attached.
2. Structured assessment
We capture the current state systematically – technically, organisationally and in regulatory terms. You receive a prioritised assessment that clearly names strengths, gaps and action areas and forms the basis for a robust offer.
3. Delivery with a dedicated lead
A senior lead guides you through the delivery with clear milestones, transparent effort and cost planning and a weekly status. All results are documented and remain fully owned by you.
4. Continuous operations & review
After project close, we stay alongside you in operations – via managed-service components, regular reviews, action tracking and proactive recommendations on new threats, regulatory changes or technology shifts.