Incident Response & Digital Forensics

When the alert fires, we work the whole incident.

Identifying the bad email or the infected laptop is the first hour. We take the incident from that first alert to its root cause: what ran, what it touched, how far it spread, how the attackers got in, and the report your insurer, your attorneys and the Information Regulator will ask for.

In an incident now? WhatsApp us See how we work an incident

The incident lifecycle

Five disciplines, one incident.

Each stage can be engaged on its own. In a real incident they run as one sequence, and the findings of each feed the next.

1

Triage

Phishing triage, end to end

We do not stop at "that email was phishing". We analyse the full headers and authentication results, detonate the attachment or link in an isolated sandbox, extract the indicators of compromise — sending infrastructure, URLs, file hashes — find everyone else who received it, and close it with a formal incident report and the containment actions taken.

You receive
An incident report: what the email was, who received it, who clicked, what was contained, and what to block.
Tooling
ANY.RUN sandbox, VirusTotal, header and authentication analysis
What it means for you
One reported email becomes a closed incident, not a guess about whether anyone else was caught.

Three ways to engage us

Before an incident, during one, or after one. The disciplines are the same; the urgency is not.

During · Emergency response

Something is happening now

  • Containment without destroying evidence
  • Triage, memory capture and scoping
  • POPIA and Cybercrimes Act notifications assessed
  • Root-cause report when it is over
WhatsApp URGENT
After · Investigation

Something happened and you need to know what

  • Timeline reconstruction from your logs
  • Disk and memory forensics with chain of custody
  • Findings written for attorneys and insurers
  • Detection rules so it is caught next time
Scope an investigation
Before · Readiness simulation

Find out how your team would cope

  • A ransomware scenario run against your team and systems
  • Who decides what, and how fast, tested for real
  • Logging and backups checked against what an investigation needs
  • A written playbook and a gap report
Book a readiness call

The obligations that start the clock

POPIA section 22

If personal information may have been accessed, the Information Regulator and the affected people must be notified as soon as reasonably possible. The investigation is what tells you whether that duty applies and what to say.

Cybercrimes Act section 54

Electronic communications service providers and financial institutions have 72 hours to report cyber offences to SAPS, and must preserve the evidence.

Scope of our work

We examine systems you own or are authorised in writing to have examined. We do not investigate individuals, conduct surveillance or run background checks.

General information, not legal advice. Sources: Information Regulator, section 22 guideline · CISA #StopRansomware guide

Questions

What is the difference between data breach response and incident response?

Data breach response is the emergency: containing a live incident and meeting the notification duties. Incident response and forensics is the whole lifecycle around it: triaging the first alert, investigating memory, logs and disks, reconstructing the timeline, preserving evidence, and writing the report with root cause and the detection that would catch it next time.

Should we switch off an infected computer?

Disconnect it from the network first and leave it on if you can. Switching off wipes what is held in memory, which is where much of the evidence of an attack lives. CISA's ransomware guidance is to isolate affected systems and to power them down only if they cannot be disconnected.

Will the evidence stand up if the matter goes to court or to our insurer?

Evidence is collected with hash verification and a documented chain of custody from the first step, and the findings report is written for attorneys and insurers. Whether it is admitted is a matter for your attorneys and the court. Where a matter needs expert testimony, we bring in a named forensic specialist.

Do we have to report the incident?

If personal information may have been accessed, POPIA section 22 requires notice to the Information Regulator and affected people as soon as reasonably possible. Electronic communications service providers and financial institutions also have 72 hours under section 54 of the Cybercrimes Act to report cyber offences to SAPS. General information, not legal advice.

Can you investigate an employee or another person?

No. We investigate systems you own or are authorised in writing to have examined, to establish what happened to them. We do not investigate individuals, conduct surveillance or run background checks.

Plan for the incident before it happens.

Most of what decides how an incident ends is in place before it starts: the logs that exist, the backups that restore, and who is allowed to decide what. A readiness call tells you where you stand.