Security
Incident Response & Ransomware Recovery
If you think something is wrong right now, stop reading and call. Everything below is worth knowing before that day arrives — but on the day, minutes of containment are worth more than hours of analysis.
The problem
The instinct is to clean it up, and that destroys the evidence
The first reaction to a compromised account is usually to change the password and carry on. That locks the attacker out of the front door while leaving the mail rules, the OAuth app consent and the recovery method they added still in place — so they come back. It also overwrites the log data that would have shown what they read and what they sent. By the time somebody asks whether client data left the building, the answer is no longer recoverable.
Our approach
Contain, then establish what actually happened
Containment first: revoke sessions, reset credentials, remove attacker persistence, and stop the bleeding. Then reconstruct the timeline from the logs while they still exist — what was accessed, what was sent, whether anything left. You get a written account you can hand to your insurer, your lawyer, or a regulator, rather than a reassurance nobody can stand behind.
What you get
Included as standard
Not an upsell list. These are the things that make the difference between a service you pay for and a service that works.
- Containment of a compromised Microsoft 365 or Entra ID account
- Removal of attacker persistence — mail rules, app consents, added MFA methods
- Timeline reconstruction from audit and sign-in logs while retention allows
- Assessment of what data was accessible and what was actually touched
- Business email compromise: tracing forged invoices and redirected payments
- Ransomware: scoping the encryption, assessing backups, planning recovery
- A written incident report suitable for insurers and counsel
- Hardening afterwards, so the same route does not work twice
How we work
What actually happens
- 1
Contain
Revoke active sessions, reset credentials, remove the persistence the attacker left behind. First, and fast.
- 2
Preserve
Capture logs before retention windows close. Microsoft 365 audit data does not wait for anyone to get around to it.
- 3
Establish scope
What was accessed, what was sent, what left. Stated with the evidence, and stated plainly where the evidence does not exist.
- 4
Recover and harden
Restore what can be restored, then close the route that was used — because an incident you do not learn from is one you repeat.
Technologies
What we build on
Vendor-neutral where it matters. We will tell you when the cheaper option is the right one.
- Microsoft 365 unified audit log
- Entra ID sign-in and risk detections
- Microsoft Defender
- Mail flow and transport rule review
- OAuth application consent review
- Backup integrity verification
Questions
Incident Response questions
Can you guarantee you will recover our data after ransomware?
No, and be wary of anyone who says otherwise. Recovery depends on what your backups actually contain, whether they were reachable from the compromised network, and which variant is involved. What we can commit to is establishing quickly and honestly what is recoverable, so you are making decisions on facts rather than hope.
Our Microsoft 365 account was hacked but we already changed the password. Are we fine?
Not necessarily, and this is the most common mistake. A password change does not remove a forwarding rule, an OAuth app the attacker consented to, or an authenticator they registered. Any of those is enough to walk straight back in. The account needs its sessions revoked and its persistence cleared, not just a new password.
Do we have to report this to anyone?
That depends on what data was involved and what sector you are in — HIPAA, state breach notification law and your own contracts can all apply, and the clocks are short. We are not lawyers and will not pretend to be. What we provide is the factual timeline your counsel needs in order to advise you.
Should we pay the ransom?
That is a business and legal decision, not a technical one, and it involves sanctions exposure your counsel needs to weigh. Our part is telling you accurately what is encrypted, what your backups can restore, and how long recovery would take — which is usually the information the decision actually turns on.
We are not a client. Will you still help?
Yes. Incident work is taken on for businesses we have never worked with before, and most of it is. There is no expectation you become a managed client afterwards.
Related
Often paired with
Cybersecurity Services
Layered defence built around how small businesses actually get breached: email, credentials and unpatched endpoints.
Learn moreMicrosoft 365 Management
Licensing, hardening and day-to-day administration of Microsoft 365 — including the security settings that ship switched off.
Learn moreBackup & Disaster Recovery
Backups that are tested on a schedule, with a recovery time you have actually seen demonstrated — not assumed.
Learn more
Ready to secure your business?
A free assessment: we review your network, backups, Microsoft 365 settings and exposure, then hand you the findings in writing — whether or not you hire us.