Under attack?
Incident response

Are you under attack?

Call. The rest of this page can wait: it is written to be read while the phone is ringing.

Emergency line

+225 07 07 79 14 49

An on-call engineer answers. If the line is busy, write to [email protected] with URGENT in the subject line: the mailbox is monitored continuously.

You do not need to be a client to call.

The first five minutes

What to do right now

The order matters. An organisation acting out of sequence destroys the traces the investigation will need, and often reopens the very door the attacker came through.

  • Isolate, do not power off. Unplug the network cable or turn off Wi-Fi on the affected machines. A machine that is switched off loses its memory, which often holds the decryption keys and the trace of the intrusion.
  • Cut remote access — VPN, remote desktop, supplier administration accounts — rather than pulling the whole internet connection.
  • Tell your leadership. Incident response involves decisions that are not IT’s alone to make.
  • Open a channel outside the compromised network: personal phones, external mail. Assume your internal mail is being read.
  • Write down the time of every action, on paper if need be. That timeline will be worth its weight in gold later.

What not to do

  • Do not reboot or rebuild the affected machines: you would erase the evidence before knowing how the attacker got in.
  • Do not restore backups before the entry point has been identified. A premature restore gets reinfected within hours.
  • Do not pay the ransom without advice. Payment guarantees neither the return of your data nor its non-publication, and it is legally constrained in several jurisdictions.
  • Do not write to the attacker from a company account.
  • Do not communicate publicly before the facts are established.
To save time

What helps to have at hand

None of this is a prerequisite for calling. But if someone can gather it while you are talking to us, the response starts sooner.

  • What was observed, and at what time
  • How many workstations and servers are affected
  • Whether there is a ransom note, and its text
  • The state of your backups: where they are, how old, and whether they are reachable from the affected network
  • Your open remote access and the suppliers connected to you
  • The name of someone empowered to decide
Reporting obligations

Depending on your sector and the data involved, an incident may have to be reported to an authority — a sector regulator, a data protection authority — within a fixed deadline. We help you identify what applies and document the facts accordingly, but the notification remains your responsibility.

You are not a client yet

That changes nothing about the call. We qualify the emergency first and discuss the contractual side afterwards. An organisation in crisis should not have to negotiate before being helped.

Nothing urgent today?

Then this is the best time to prepare for the day there is. The scoping workshop establishes what is covered, what is not, and where to start.