Suspect a Cyber Incident? Get Immediate DFIR Guidance.
You don't need to confirm a breach before reaching out. If something feels off, it's worth getting expert eyes on the situation before taking action that could increase risk or destroy evidence.
a human answers 24/7/365
If you think an incident is happening right now:
- Don't delete suspicious files or emails - they're evidence
- Don't wipe or reimage anything yet
- Don't pay, reply to, or negotiate with anyone before getting guidance
- Do disconnect affected machines from the network instead of powering them down - volatile evidence is lost on shutdown, so pull the network cable or Wi-Fi, not the power, unless disconnecting isn't possible
- Do write down what you noticed and when you noticed it
- Do communicate by phone or a known-clean device - not the possibly-compromised email system
Call +1 (888) 966-7228 before taking further action. A human answers 24/7/365.
The information provided here is for educational purposes only and should not be considered legal advice. Requirements change and applicability depends on your specific circumstances - for specific compliance concerns, consult a qualified legal professional.
Get calm, expert direction to assess, contain, and respond to a potential cyber incident - without panic, guesswork, or unnecessary disruption.
When something feels wrong - suspicious activity, locked files, unusual alerts, or unexplained access - the first hours matter most. Our Digital Forensics & Incident Response (DFIR) consultation helps you quickly understand what may be happening, what systems could be impacted, and what actions to take next to protect your business, preserve evidence, and reduce damage.
- Rapid incident triage & initial assessment
- Threat containment and isolation guidance
- Forensic evidence preservation strategy
- Impact analysis across systems and data
- Executive-level response recommendations
- Clear next steps for recovery and remediation
What a DFIR Consultation Actually Does
Incident response isn't about panic - and it isn't about guessing.
We don't jump to conclusions or push unnecessary services. DFIR is a structured, evidence-driven process that helps you understand what happened, contain active threats, and recover operations safely while preserving the information required for legal, insurance, and compliance purposes.
Our DFIR consultation evaluates the situation at a high level and determines the safest, fastest path forward based on facts - not assumptions.
- Incident scope & initial impact assessment
- Threat containment strategy
- Affected system identification
- Evidence preservation planning
- Malware or intrusion indicators
- Data exposure risk evaluation
- Executive & stakeholder communication clarity
- Recovery and stabilization guidance
We help you understand what's actually happening - and what actions reduce risk instead of increasing it.
What Happens When You Contact Us
- You call or submit. A human answers 24/7/365 - nights, weekends, and holidays. You get first-hour stabilization guidance on that call, and a DFIR specialist engages within 24 hours.
- We gather information. We establish what you're seeing, what systems are involved, and what's already been done.
- We assess. We determine what's actually happening and the safest path forward - containment, preservation, and what not to touch.
- We report. You get findings, impact, and clear next steps for recovery and remediation.
Initial guidance comes on the first call. A full forensic investigation typically runs 2 to 4 weeks. The exact duration depends on scope and complexity - not on how long you wait for help, which is measured in minutes, not weeks.
Signs You May Have an Incident
Any one of these is reason enough to call. You don't need two, and you don't need proof.
- Files renamed or unopenable, or a ransom note present
- Staff reporting they can't access shared drives
- Unfamiliar logins, or logins from unexpected locations
- Antivirus or endpoint alerts nobody has investigated
- A vendor, customer, or bank notifying you of suspicious activity
- Emails going out from your domain that nobody sent
- Systems slow, rebooting, or behaving oddly without explanation
What does it cost?
Every incident is different, so the engagement is scoped to what actually happened - how many systems are involved, how much data is in scope, and what you need to prove afterward for insurance, legal, or compliance purposes.
The first conversation costs nothing. We'll tell you what we think you're dealing with and what it takes to resolve it before you commit to anything.
Frequently Asked Questions
What should I do first if I think we've been hacked?
How fast can you respond?
Do you work outside business hours?
What does a DFIR engagement cost?
How long does an investigation take?
Do I need to confirm a breach before calling?
Will this disrupt my operations?
Do you work with our cyber insurance carrier?
What if we already have an IT provider?
Do we have to report this? To whom?
What if it turns out to be nothing?
Florida Breach Notification Requirements
If a breach involving Floridians' personal information is confirmed, the Florida Information Protection Act (F.S. 501.171) sets the clock. Its deadlines run from when you determine a breach occurred - or have reason to believe one did.
- Affected individuals: notice within 30 days of determining the breach, as expeditiously as practicable and without unreasonable delay.
- Florida Department of Legal Affairs: required when 500 or more Floridians are affected, within the same 30 days. A 15-day extension is available for good cause, requested in writing within the 30-day window.
- Third-party agents: a vendor that suffers a breach of data it holds for you must notify you within 10 days of determining the breach.
- Consumer reporting agencies: required when more than 1,000 individuals are affected at a single time, without unreasonable delay.
Sector rules can add obligations on top - HIPAA for healthcare, GLBA for financial services, contract clauses for everyone. Part of a DFIR engagement is establishing the facts every notification depends on: what data, how many people, and when the clock started.
The information provided here is for educational purposes only and should not be considered legal advice. Requirements change and applicability depends on your specific circumstances - for specific compliance concerns, consult a qualified legal professional.
The worst time to look for an incident response team is during an incident.
Know who you'll call, what they'll do, and how fast they respond - before you need them. If something is happening right now, don't wait for a form.
a human answers 24/7/365
No pressure. No jargon. Just clear insights and your best next steps.
