Working out what happened
Logs, systems and timelines, read to establish what actually occurred rather than what the first alert suggested. The first story is wrong more often than not.
Alcyon
Information Security
Home/Services/Incident support
Help working out what happened, how far it reached, and what to close first. Calm hands on a bad day, and a straight account afterwards of how it started.
Logs, systems and timelines, read to establish what actually occurred rather than what the first alert suggested. The first story is wrong more often than not.
Which accounts, which systems, which data. The question that decides both your next move and, frequently, what you are legally obliged to report.
Containment in an order that does not destroy the evidence you need, and does not tip off someone still inside before you are ready.
A written account of how it started and what would have caught it earlier. Aimed at the people who have to prevent the next one, not at assigning blame for this one.
Tell me what you are seeing. We work out in that conversation whether you need me, someone with a different specialism, or nobody at all.
Agree what to preserve before anything is rebuilt, and what to shut down now. Evidence is easy to destroy in the first hour by accident.
Reconstruct the sequence and the reach from what the systems actually recorded, separating what is known from what is inferred.
A written account: what happened, what it reached, what was done, and what would have caught it earlier.
Get in touch, and in the meantime do not rebuild anything yet. Reimaging the affected machine is the most common way the answer to "how did they get in" is destroyed in the first hour.
Preserve logs, write down what you have already changed and when, and keep that record going.
PERSONALISE: answer this one plainly. Availability is what people are really asking about, and a vague answer here costs you the engagement.
Check your policy before you engage anyone. Cyber policies often name an approved response provider, and using someone else can affect the claim.
If your policy has that condition, follow it. I would rather you kept your cover.
Sometimes. It depends entirely on what your systems recorded, which is usually decided long before the incident.
Where the evidence does not support a conclusion, I will say so rather than produce a comfortable one. "No evidence of exfiltration" and "no exfiltration" are different sentences, and only one of them is usually true.
That happens, and it is a good outcome. You get a short written account of what it actually was, which is worth having the next time the same alert fires.
Start a conversation
Replies within one working day. Dutch or English.