NIS2 checkContact

Incident response

Call us now

Our European incident response team is reachable 24 hours a day, weekends included. If your organisation falls under NIS2, the reporting deadline may have started the moment you became aware of the incident. For an urgent situation, use the phone.

Before you call

What you can do straight away

The following steps help to limit further damage and preserve information for the investigation.

01

Disconnect a suspect device, but do not switch it off

Remove the network cable or switch off the wireless. Leaving the device running keeps the data in memory available for investigation. That is often where the evidence of how the attacker got in actually lives.

02

Use a separate communication channel

Use the phone or another platform you can reasonably assume is unaffected. Do not discuss the response inside a possibly compromised email or chat environment, because that tells the attacker exactly what you are doing.

03

Record events and times

Note when you discovered the problem, what you saw, which systems appear to be involved and which actions have already been taken. A rough note made now is worth more than a reconstruction later, and the 72-hour notification asks for exactly this.

04

Do not negotiate or pay on your own

Payment does not reliably restore data, may breach sanctions law, and changes your position with your insurer. If there is a ransom demand, contact your insurer, your legal adviser and an incident response specialist first.

What happens when you call

What happens after your call

The SOC provides the technical assessment and response. Your organisation remains responsible for approving formal notifications and external communication.

01

First assessment

Not a ticket queue and not a callback form. A responder discusses what you are seeing, when it started, which systems are involved and whether the incident still appears active. From that point we keep a timeline.

02

Assess

Severity, blast radius and whether it is still active. Within the first hour you have a plain answer to "how bad is this".

03

Contain

Engineers isolate, revoke and block. Containment is prioritised over investigation, because the two compete and one of them is reversible.

04

Notify

We draft the 24-hour early warning with you. Nothing is filed without your approval, and it goes to the right authority for the right country.

05

Recovery and closure

We investigate the cause, verify the recovery and produce an overview of the impact, the actions taken and the improvements we recommend. The final report follows within a month. Then the honest conversation about what would stop it happening again.

Whether you are already a client

You do not have to be a client

Even if you are not yet a client, we will go through the situation with you. An incident is a bad moment to discover that your provider only answers for contracted customers.

If we do not know you yet
  • We still take the call and still triage it
  • Emergency response is quoted before work starts, not after
  • We will tell you plainly if someone else is a better fit for this one
  • Nothing obliges you to become a client afterwards

Before we carry out any chargeable work, you receive an order confirmation or emergency proposal setting out the rates and conditions. You are under no obligation to take other services once the incident is handled.

For SmartCyber clients
  • The SOC has usually already seen it and is already working
  • Your environment, your entities and your countries are already documented
  • The reporting templates for your member states are already prepared
  • Your named CISO leads and your board hears one story

The difference is not who answers, but how much has to be discovered first. The duty analyst starts the technical assessment. The named CISO is involved when organisational decisions, external communication or statutory notifications are needed.

Not urgent, but worrying

Are you unsure whether this is really an incident?

Get in touch as well for strange sign-ins, unexpected log entries, a sharp rise in phishing or a report from a supplier that has been breached. We assess whether immediate incident response is needed or whether additional monitoring is enough.

Describe what you are seeing

If it is urgent, call instead, this reaches a mailbox, not a pager.

This reaches our European mailbox directly. For anything time-critical, please call.