Identifying the bad email or the infected laptop is the first hour. We take the incident from that first alert to its root cause: what ran, what it touched, how far it spread, how the attackers got in, and the report your insurer, your attorneys and the Information Regulator will ask for.
Each stage can be engaged on its own. In a real incident they run as one sequence, and the findings of each feed the next.
1
Triage
Phishing triage, end to end
We do not stop at "that email was phishing". We analyse the full headers and authentication results, detonate the attachment or link in an isolated sandbox, extract the indicators of compromise — sending infrastructure, URLs, file hashes — find everyone else who received it, and close it with a formal incident report and the containment actions taken.
You receive
An incident report: what the email was, who received it, who clicked, what was contained, and what to block.
Tooling
ANY.RUN sandbox, VirusTotal, header and authentication analysis
What it means for you
One reported email becomes a closed incident, not a guess about whether anyone else was caught.
2
Forensics
Memory forensics investigation
We capture a live memory image from a compromised machine before it is switched off, then identify injected processes, extract its network connections and recover the commands the attacker ran. YARA rules built from what we find sweep the rest of your machines for the same threat.
You receive
What ran on the machine, what it communicated with, and whether the same threat is present anywhere else.
Tooling
Volatility 3, strings, YARA
What it means for you
Attacks that never touch the disk are found, including the ones antivirus and disk checks miss.
3
Detection
SIEM alert triage & timeline reconstruction
We work your log sources together — Windows event logs, firewall, authentication and cloud audit logs — to reconstruct the attack from initial access to data leaving the network. Then we write the detection rule that would have flagged it before the data left, and put it into your monitoring.
You receive
A dated timeline of the attack, the data it reached, and working detection rules for next time.
Tooling
Splunk or Elastic, or the SIEM you already run
What it means for you
You know what happened, in order, and the same attack is caught earlier if it comes back.
4
Evidence
Endpoint forensics on a disk image
We take a forensic image of the affected machine, verified by hash, and work on the copy. We recover deleted artefacts, trace the persistence mechanisms the attacker left behind, and document the chain of custody from the moment of collection, so the findings can be relied on later.
You receive
A findings report written to be handed to your attorneys and your insurer, with the chain of custody attached.
Tooling
FTK Imager, Autopsy
What it means for you
Evidence handled properly under pressure, rather than a laptop that was wiped and reinstalled.
Whether evidence is admitted is for your attorneys and the court. Where a matter needs expert testimony, a named forensic specialist joins the engagement.
5
Full lifecycle
Ransomware response
We contain the active outbreak and isolate endpoints, identify patient zero, map the lateral movement, determine the initial access vector, and recover. It closes with a post-incident report giving the root cause and the lessons learned, and with your POPIA section 22 notification assessed and supported.
You receive
Containment, recovery, a root-cause report and the notification decisions documented.
Tooling
Velociraptor across your endpoints, with your SIEM
What it means for you
The whole incident is run to its end, not handled as a string of tickets.
Three ways to engage us
Before an incident, during one, or after one. The disciplines are the same; the urgency is not.
If personal information may have been accessed, the Information Regulator and the affected people must be notified as soon as reasonably possible. The investigation is what tells you whether that duty applies and what to say.
Cybercrimes Act section 54
Electronic communications service providers and financial institutions have 72 hours to report cyber offences to SAPS, and must preserve the evidence.
Scope of our work
We examine systems you own or are authorised in writing to have examined. We do not investigate individuals, conduct surveillance or run background checks.
What is the difference between data breach response and incident response?
Data breach response is the emergency: containing a live incident and meeting the notification duties. Incident response and forensics is the whole lifecycle around it: triaging the first alert, investigating memory, logs and disks, reconstructing the timeline, preserving evidence, and writing the report with root cause and the detection that would catch it next time.
Should we switch off an infected computer?
Disconnect it from the network first and leave it on if you can. Switching off wipes what is held in memory, which is where much of the evidence of an attack lives. CISA's ransomware guidance is to isolate affected systems and to power them down only if they cannot be disconnected.
Will the evidence stand up if the matter goes to court or to our insurer?
Evidence is collected with hash verification and a documented chain of custody from the first step, and the findings report is written for attorneys and insurers. Whether it is admitted is a matter for your attorneys and the court. Where a matter needs expert testimony, we bring in a named forensic specialist.
Do we have to report the incident?
If personal information may have been accessed, POPIA section 22 requires notice to the Information Regulator and affected people as soon as reasonably possible. Electronic communications service providers and financial institutions also have 72 hours under section 54 of the Cybercrimes Act to report cyber offences to SAPS. General information, not legal advice.
Can you investigate an employee or another person?
No. We investigate systems you own or are authorised in writing to have examined, to establish what happened to them. We do not investigate individuals, conduct surveillance or run background checks.
Plan for the incident before it happens.
Most of what decides how an incident ends is in place before it starts: the logs that exist, the backups that restore, and who is allowed to decide what. A readiness call tells you where you stand.