Cyber Security & Risk Advisory

Forensic Audit and Advisory

When a breach happens, the first 48 hours matter most.

What This Is

Investigation built for evidence, not just answers

When a breach or suspected cyber incident happens, the priority is containment first, understanding second — but both have to be done in a way that preserves evidence, in case the matter needs to go further, to a regulator, an insurer, or a court.

We investigate the technical root cause while documenting everything to a standard that holds up, whoever ends up needing to see it.

Report a Suspected Incident
Incident Severity Levels

Every incident is triaged and classified on this scale from the first hour.

Critical (P1)
High (P2)
Medium (P3)
Low (P4)
Informational
Coverage

What we investigate

Technical investigation matched to the kind of incident you're facing.

root_cause.sh

Breach Root-Cause Analysis

Tracing exactly how an attacker gained access and what they did once inside.

malware_analysis.sh

Malware & Ransomware Analysis

Understanding what the malicious software actually did, and how it spread.

data_exfil.sh

Data Exfiltration Tracing

Determining whether, and what, data actually left your environment.

log_forensics.sh

Log & Network Forensics

Reconstructing the timeline of an incident from logs and network traffic.

insider_threat.sh

Insider Threat Investigation

Investigating suspected misuse of access by employees or contractors.

evidence.sh

Evidence Preservation

Handling evidence to a standard suitable for legal or regulatory use.

What You'll Receive

What an incident finding looks like

Every finding is documented with a timeline, technical evidence, and impact assessment.

Below is an illustrative example of how a single finding is presented.

Unauthorised Access via Exposed RDP Port Critical
Severity
9.2 / 10
Description

An internet-facing Remote Desktop Protocol port was left exposed with weak credentials, providing the initial point of unauthorised access.

Illustrative example only — for demonstration of report format, not an actual finding from a client engagement.

How We Work

Our incident response methodology

The same disciplined sequence, from the first hour of an incident.

01

Containment

Stop the incident from spreading further while investigation begins.

02

Evidence Collection

Preserve logs, images and artefacts before they can be lost or altered.

03

Root-Cause Analysis

Determine exactly how the incident happened and what was affected.

04

Impact Assessment

Assess what data or systems were actually compromised.

05

Report & Remediation

Deliver findings and a remediation plan to prevent recurrence.

Compliance Mapping

Frameworks we align with

Investigations are documented to standards suitable for these contexts.

CERT-In Reporting ISO 27037 SEBI CSCRF GDPR Breach Notification RBI Cyber Framework
Common Questions

Frequently asked questions

We think we've had a breach — what should we do first?

Don't shut down affected systems before speaking with us if possible — that can destroy evidence needed for investigation. Contact us immediately and we'll guide the first steps.

Do you handle CERT-In reporting requirements?

Yes — we help determine whether an incident triggers mandatory reporting and support the reporting process itself.

Can your findings be used in legal proceedings?

Evidence is preserved and documented with that possibility in mind, though admissibility ultimately depends on the specific matter and your legal counsel's guidance.

How quickly can you respond to an active incident?

We prioritise active incidents and mobilise as quickly as possible — reach out immediately rather than waiting.

Do you also help prevent future incidents, not just investigate?

Yes — every investigation ends with a remediation plan specifically aimed at preventing the same root cause from recurring.

Dealing with a suspected security incident?

Contact us immediately — early containment makes the biggest difference.

Get in Touch
← Back to

Cyber Security & Risk Advisory

See all offerings — VAPT, information system audit, risk advisory and forensic audit.