Under cyber attack? Tap to call incident response.

Under cyber attack right now? Call our incident response team at +1 877-509-2673.

Get incident help

Security · Incident Response

Incident Response and Ransomware Recovery

Dealing with an attack right now?

Call +1 877-509-2673 and tell us what you're seeing. We'll help you contain it, recover and get back to running your business.

When ransomware, an identity compromise or an account takeover hits your organization, our specialists help you contain it, take back control and get running again.

Not yet an InnerCore customer? You don't need to be. Tell us what you're seeing, and an incident response specialist will talk it through with you.

First steps while you reach us

Dealing with an attack now? Here's what to do first

General guidance while you reach us. Every incident is different, so treat these as a starting point, not a checklist.

  • Bring in experienced help early.

    Talk to an incident response specialist before you make changes you can't undo.

  • Keep the evidence.

    Don't wipe, reset or rebuild affected systems yet. What's on them shows how the attacker got in.

  • Disconnect, don't power off.

    Where you can, take affected devices off the network and leave them running.

  • Talk on a clean channel.

    If email or chat may be compromised, move conversations to a device and account you trust.

  • Bring in your insurer and legal counsel early.

    Many cyber policies set out who to call and when. Check yours.

  • Don't pay or negotiate alone.

    Get expert advice before you respond to any demand.

  • Write things down.

    Note what you saw, when, and who has done what since.

What we handle

  • Ransomware recovery

    Encrypted systems and a demand on the screen. We help you contain the spread, take back control and restore in the order your business needs.

  • Identity compromise

    An attacker holding admin accounts or your identity directory. We take those back first, because everything else depends on them.

  • Email account takeover

    A mailbox sending messages it shouldn't, or forwarding rules nobody set. We secure the account and find out what was touched.

  • Business email compromise and payment fraud

    Fake invoices or changed bank details sent from a real or lookalike account. We find how the message got there and close the gap.

  • Activity you can't explain

    Unknown admin accounts, unexpected sign-ins or systems behaving oddly. We investigate and tell you plainly what's happening.

How we respond

How we respond, in six steps: contain, make sure they're gone, take back control, restore, harden and review.
  1. Contain: We size up the incident and work with your team and vendors to contain it.

  2. Make sure they're gone: Before anything is restored, we look for attacker access that's still in place, such as hidden accounts, changed settings or remote-access tools, and remove it.

  3. Take back control: We regain control of your identity systems, admin accounts and policies.

  4. Restore: We bring critical systems back from backup in the order you agree, and check them before they return to service.

  5. Harden: We patch, fix and close the way the attacker got in.

  6. Review: We deliver a post-incident review covering what happened, why, and what to do next.

Why identity comes first

Most modern attacks end up in the same place: the accounts that control everything else. If an attacker still holds an admin account or your identity directory, restoring servers just hands them back. So we recover identity first: your Microsoft 365 sign-ins, your on-premises directory and every privileged account, then rebuild trust from there. It's the difference between getting running again and getting running again safely.

Back to business safely

  • A clean restore point

    We find a backup taken before the attacker arrived, not just the most recent one.

  • Restored in business order

    The systems that keep you trading come back first, as you decide.

  • Checked before reconnecting

    Restored systems and data are checked before they rejoin your network.

  • The way in, closed

    The weakness that let the attacker in is fixed before you're back to normal.

Working with your insurer, legal counsel and others

An incident rarely involves one company. Your cyber insurer, your legal counsel and your own vendors may all have a part to play, and many policies set out who to call and when. We work alongside the people you bring in and keep the technical side clear for them. Specialized forensics, legal privilege and breach notification may involve specialist third parties.

EXAMPLE scenario

EXAMPLE: illustrative only, not a real customer.

Problem

A professional services firm, not yet an InnerCore customer, arrived one morning to encrypted file servers and an attacker holding a domain admin account.

What we did

We worked with the firm's team to contain the spread, removed the attacker's hidden accounts, took back their identity systems, restored from a clean backup in the order the partners set, and closed the remote-access gap that let the attacker in.

Outcome

The firm was back at work on systems checked as clean, with a written post-incident review and a plan for ongoing protection.

After recovery, stay protected.

Getting running again is the first goal. Staying that way is the next. Once the incident is closed, the same specialists can talk with you about ongoing protection: defense in depth across email, devices, identities and data, 24/7 Monitoring, Detection and Response, and resilience built in, with immutable, ransomware-protected backups. There's no obligation, and no forced bundle. Our specialists recommend what your environment really needs.

What changes for you

  • Control of your identity systems back in your hands.
  • Critical systems restored in the order your business needs.
  • The gaps that let the attacker in, identified and closed.
  • A written record of what happened and what to do next.

FAQs

Can you help if we're not an InnerCore customer?

Yes. This service is built for organizations facing an incident before they work with us. Tell us what you're seeing, and a specialist will talk it through with you.

Should we call our insurer or lawyer first?

Check your policy. Many insurers want to hear early and may have their own process. We work alongside the people you bring in. Specialized forensics, legal privilege and breach notification may involve specialist third parties.

How long will recovery take?

Every incident is different, so we don't publish timings. Once we understand what's affected, we'll give you an honest picture of the work ahead and agree the restore order with you.

Should we pay the ransom?

Don't decide alone. Get expert advice, and involve your insurer and legal counsel, before you respond to any demand. Our first focus is containing the incident and finding a clean way back.

How do backups fit in?

Backups make recovery possible. Recovery is the plan for using them, starting with a clean restore point taken before the attacker arrived.

What happens after the incident?

You get a post-incident review. If you'd like ongoing protection, we can talk about 24/7 Monitoring, Detection and Response and resilience built in, with immutable, ransomware-protected backups.

Talk to an incident response specialist.

Tell us what you're seeing. We'll help you contain it, take back control and get running again, then close the way in and help you stay protected.

This site uses analytics cookies only if you accept. Privacy policy