Skip to content

Security

Incident Response & Ransomware Recovery

If you think something is wrong right now, stop reading and call. Everything below is worth knowing before that day arrives — but on the day, minutes of containment are worth more than hours of analysis.

The problem

The instinct is to clean it up, and that destroys the evidence

The first reaction to a compromised account is usually to change the password and carry on. That locks the attacker out of the front door while leaving the mail rules, the OAuth app consent and the recovery method they added still in place — so they come back. It also overwrites the log data that would have shown what they read and what they sent. By the time somebody asks whether client data left the building, the answer is no longer recoverable.

Our approach

Contain, then establish what actually happened

Containment first: revoke sessions, reset credentials, remove attacker persistence, and stop the bleeding. Then reconstruct the timeline from the logs while they still exist — what was accessed, what was sent, whether anything left. You get a written account you can hand to your insurer, your lawyer, or a regulator, rather than a reassurance nobody can stand behind.

What you get

Included as standard

Not an upsell list. These are the things that make the difference between a service you pay for and a service that works.

  • Containment of a compromised Microsoft 365 or Entra ID account
  • Removal of attacker persistence — mail rules, app consents, added MFA methods
  • Timeline reconstruction from audit and sign-in logs while retention allows
  • Assessment of what data was accessible and what was actually touched
  • Business email compromise: tracing forged invoices and redirected payments
  • Ransomware: scoping the encryption, assessing backups, planning recovery
  • A written incident report suitable for insurers and counsel
  • Hardening afterwards, so the same route does not work twice

How we work

What actually happens

  1. 1

    Contain

    Revoke active sessions, reset credentials, remove the persistence the attacker left behind. First, and fast.

  2. 2

    Preserve

    Capture logs before retention windows close. Microsoft 365 audit data does not wait for anyone to get around to it.

  3. 3

    Establish scope

    What was accessed, what was sent, what left. Stated with the evidence, and stated plainly where the evidence does not exist.

  4. 4

    Recover and harden

    Restore what can be restored, then close the route that was used — because an incident you do not learn from is one you repeat.

Technologies

What we build on

Vendor-neutral where it matters. We will tell you when the cheaper option is the right one.

  • Microsoft 365 unified audit log
  • Entra ID sign-in and risk detections
  • Microsoft Defender
  • Mail flow and transport rule review
  • OAuth application consent review
  • Backup integrity verification

Questions

Incident Response questions

Can you guarantee you will recover our data after ransomware?

No, and be wary of anyone who says otherwise. Recovery depends on what your backups actually contain, whether they were reachable from the compromised network, and which variant is involved. What we can commit to is establishing quickly and honestly what is recoverable, so you are making decisions on facts rather than hope.

Our Microsoft 365 account was hacked but we already changed the password. Are we fine?

Not necessarily, and this is the most common mistake. A password change does not remove a forwarding rule, an OAuth app the attacker consented to, or an authenticator they registered. Any of those is enough to walk straight back in. The account needs its sessions revoked and its persistence cleared, not just a new password.

Do we have to report this to anyone?

That depends on what data was involved and what sector you are in — HIPAA, state breach notification law and your own contracts can all apply, and the clocks are short. We are not lawyers and will not pretend to be. What we provide is the factual timeline your counsel needs in order to advise you.

Should we pay the ransom?

That is a business and legal decision, not a technical one, and it involves sanctions exposure your counsel needs to weigh. Our part is telling you accurately what is encrypted, what your backups can restore, and how long recovery would take — which is usually the information the decision actually turns on.

We are not a client. Will you still help?

Yes. Incident work is taken on for businesses we have never worked with before, and most of it is. There is no expectation you become a managed client afterwards.

Ready to secure your business?

A free assessment: we review your network, backups, Microsoft 365 settings and exposure, then hand you the findings in writing — whether or not you hire us.

Call nowFree assessment