Suspect a Cyber Incident? Get Immediate DFIR Guidance.

You don't need to confirm a breach before reaching out. If something feels off, it's worth getting expert eyes on the situation before taking action that could increase risk or destroy evidence.

Call +1 (888) 966-7228

a human answers 24/7/365

If you think an incident is happening right now:

  • Don't delete suspicious files or emails - they're evidence
  • Don't wipe or reimage anything yet
  • Don't pay, reply to, or negotiate with anyone before getting guidance
  • Do disconnect affected machines from the network instead of powering them down - volatile evidence is lost on shutdown, so pull the network cable or Wi-Fi, not the power, unless disconnecting isn't possible
  • Do write down what you noticed and when you noticed it
  • Do communicate by phone or a known-clean device - not the possibly-compromised email system

Call +1 (888) 966-7228 before taking further action. A human answers 24/7/365.

The information provided here is for educational purposes only and should not be considered legal advice. Requirements change and applicability depends on your specific circumstances - for specific compliance concerns, consult a qualified legal professional.

Get calm, expert direction to assess, contain, and respond to a potential cyber incident - without panic, guesswork, or unnecessary disruption.

When something feels wrong - suspicious activity, locked files, unusual alerts, or unexplained access - the first hours matter most. Our Digital Forensics & Incident Response (DFIR) consultation helps you quickly understand what may be happening, what systems could be impacted, and what actions to take next to protect your business, preserve evidence, and reduce damage.

  • Rapid incident triage & initial assessment
  • Threat containment and isolation guidance
  • Forensic evidence preservation strategy
  • Impact analysis across systems and data
  • Executive-level response recommendations
  • Clear next steps for recovery and remediation

What a DFIR Consultation Actually Does

Incident response isn't about panic - and it isn't about guessing.

We don't jump to conclusions or push unnecessary services. DFIR is a structured, evidence-driven process that helps you understand what happened, contain active threats, and recover operations safely while preserving the information required for legal, insurance, and compliance purposes.

Our DFIR consultation evaluates the situation at a high level and determines the safest, fastest path forward based on facts - not assumptions.

  • Incident scope & initial impact assessment
  • Threat containment strategy
  • Affected system identification
  • Evidence preservation planning
  • Malware or intrusion indicators
  • Data exposure risk evaluation
  • Executive & stakeholder communication clarity
  • Recovery and stabilization guidance

We help you understand what's actually happening - and what actions reduce risk instead of increasing it.

What Happens When You Contact Us

  1. You call or submit. A human answers 24/7/365 - nights, weekends, and holidays. You get first-hour stabilization guidance on that call, and a DFIR specialist engages within 24 hours.
  2. We gather information. We establish what you're seeing, what systems are involved, and what's already been done.
  3. We assess. We determine what's actually happening and the safest path forward - containment, preservation, and what not to touch.
  4. We report. You get findings, impact, and clear next steps for recovery and remediation.

Initial guidance comes on the first call. A full forensic investigation typically runs 2 to 4 weeks. The exact duration depends on scope and complexity - not on how long you wait for help, which is measured in minutes, not weeks.

Signs You May Have an Incident

Any one of these is reason enough to call. You don't need two, and you don't need proof.

  • Files renamed or unopenable, or a ransom note present
  • Staff reporting they can't access shared drives
  • Unfamiliar logins, or logins from unexpected locations
  • Antivirus or endpoint alerts nobody has investigated
  • A vendor, customer, or bank notifying you of suspicious activity
  • Emails going out from your domain that nobody sent
  • Systems slow, rebooting, or behaving oddly without explanation

What does it cost?

Every incident is different, so the engagement is scoped to what actually happened - how many systems are involved, how much data is in scope, and what you need to prove afterward for insurance, legal, or compliance purposes.

The first conversation costs nothing. We'll tell you what we think you're dealing with and what it takes to resolve it before you commit to anything.

Frequently Asked Questions

What should I do first if I think we've been hacked?
Don't delete anything, don't wipe or reimage anything, and don't pay or reply to anyone. Disconnect affected machines from the network instead of powering them down, write down what you noticed and when, and communicate by phone or a known-clean device. Then call +1 (888) 966-7228 before taking further action - the full first-hour checklist is at the top of this page.
How fast can you respond?
A human answers the moment you call, 24/7/365. You get first-hour stabilization guidance on that call, and a DFIR specialist engages within 24 hours.
Do you work outside business hours?
Yes. The line is answered by a human 24/7/365 - nights, weekends, and holidays. Incidents don't keep business hours, so neither does intake.
What does a DFIR engagement cost?
It's scoped to what actually happened: how many systems, how much data, and what you need to prove afterward. The first conversation costs nothing, and you'll know the scope and the number before you commit to anything.
How long does an investigation take?
Initial guidance comes on the first call. A full forensic investigation typically runs 2 to 4 weeks, depending on scope and complexity.
Do I need to confirm a breach before calling?
No. If something feels off, that's enough. Getting expert eyes on the situation early is exactly what prevents a suspicion from becoming a disaster - or rules one out.
Will this disrupt my operations?
The consultation itself doesn't - it's a structured conversation about what you're seeing. If containment steps are needed, we recommend the safest option that keeps you operating, and we tell you the tradeoffs before anything is touched.
Do you work with our cyber insurance carrier?
We preserve evidence in a form your carrier and counsel can use. That's the part policyholders get wrong most often - well-meaning cleanup that destroys the documentation a claim depends on. Following forensic process from the first hour protects your claim as well as your systems.
What if we already have an IT provider?
You don't have to replace anyone. Our co-managed approach adds cyber risk oversight, security depth, and compliance structure alongside what already works - without replacing or disrupting it. No turf wars. No duplication. Just clearer risk management and stronger outcomes.
Do we have to report this? To whom?
It depends on what data was involved and who you answer to. Florida's breach notification law sets specific deadlines - see the requirements below - and sector rules like HIPAA can add their own. Establishing the facts those notifications depend on is part of what the investigation is for.
What if it turns out to be nothing?
Then you've had a good day, and it cost you nothing. A false alarm resolved by experts is a cheap outcome - far cheaper than a real incident ignored because someone feared looking foolish. Nobody here will make you feel that way for calling.

Florida Breach Notification Requirements

If a breach involving Floridians' personal information is confirmed, the Florida Information Protection Act (F.S. 501.171) sets the clock. Its deadlines run from when you determine a breach occurred - or have reason to believe one did.

  • Affected individuals: notice within 30 days of determining the breach, as expeditiously as practicable and without unreasonable delay.
  • Florida Department of Legal Affairs: required when 500 or more Floridians are affected, within the same 30 days. A 15-day extension is available for good cause, requested in writing within the 30-day window.
  • Third-party agents: a vendor that suffers a breach of data it holds for you must notify you within 10 days of determining the breach.
  • Consumer reporting agencies: required when more than 1,000 individuals are affected at a single time, without unreasonable delay.

Sector rules can add obligations on top - HIPAA for healthcare, GLBA for financial services, contract clauses for everyone. Part of a DFIR engagement is establishing the facts every notification depends on: what data, how many people, and when the clock started.

The information provided here is for educational purposes only and should not be considered legal advice. Requirements change and applicability depends on your specific circumstances - for specific compliance concerns, consult a qualified legal professional.

Start My DFIR Consultation

Talk to an Incident Response Advisor Today

What happens next: A human answers 24/7/365. You'll get first-hour guidance on the call, and a DFIR specialist engages within 24 hours.