Cyber Incident Recovery and Disaster Recovery
We contain the incident, preserve evidence for forensic analysis, remove malicious code, remediate identified vulnerabilities, and restore services from verified backups. Once the environment is stable, we strengthen security, configure reliable backups, and implement disaster recovery procedures.
We’ll start by assessing the incident and agreeing on a safe course of action.
Who It’s For
Corporate websites, online stores, web services, and companies with business-critical server infrastructure affected by a security breach, malware infection, data loss, or system outage.
Outcome
Restoration of services within an agreed scope, remediation of identified attack-related damage, strengthened security, and a documented plan for further action.
When Emergency Assistance Is Needed
Signs of Compromise Have Been Detected
Unknown files, third-party scripts, web shells, backdoors, or unauthorised user accounts have appeared on the server.
The Website or Server Has Been Blocked
The hosting provider has restricted the service, search engines or browsers display security warnings, or the domain or IP address has been added to a blocklist.
Abnormal Activity Is Occurring
CPU, memory, or network usage increases without an obvious cause, while unknown processes, redirects, or suspicious outbound traffic appear.
Data Has Been Damaged or Encrypted
Files and databases are unavailable, altered, or encrypted, disrupting the operation of critical services.
The Incident Keeps Recurring
Malicious files or unknown activity reappear after cleanup, indicating that the original cause of the compromise may not have been eliminated.
What We Do
Incident Containment
We identify affected systems and services, limit the spread of the threat, and agree on the next course of action.
System State Preservation and Analysis
We preserve the data required for analysis and examine system logs, application logs, and changes to files and configurations. We identify indicators of compromise and the likely attack vector.
Malware Analysis and Removal
We identify and remove malicious code, web shells, backdoors, third-party scripts, and unauthorised user accounts.
Vulnerability Remediation
We update vulnerable components, correct insecure configurations, rotate compromised credentials, and restrict excessive permissions.
Controlled Recovery
We restore files, databases, and services from available verified backups. Before returning systems to production, we verify their operation and check for known indicators of compromise.
Security Hardening
We configure baseline firewall rules, access controls, logging, monitoring, and alerts. Where necessary, we also deploy a WAF and additional security measures.
Domain Reputation Recovery
We investigate the causes of security warnings and blocklisting. Where required, we submit review requests through Google Search Console, Yandex Webmaster, hosting providers, and other relevant platforms.
Report and Recommendations
We document the affected systems, identified issues, completed work, and recommendations for reducing the risk of another incident.
Disaster Recovery and Contingency Planning
Disaster Recovery is a predefined process for restoring IT infrastructure after a major cyberattack, system failure, hardware damage, or data loss.
Critical Services and Dependencies
We identify which systems must be restored first and the components on which their operation depends.
Recovery Sequence
We document the order in which servers, databases, applications, network services, and integrations must be restored.
Recovery Objectives
We agree on acceptable downtime and potential data loss by defining Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).
Failover and Fallback Procedures
We prepare procedures for switching to backup infrastructure and returning to the primary environment after the incident has been resolved.
Backup Verification
We review backup coverage, schedules, retention periods, isolation, and the ability to restore data successfully.
Procedure Testing
We perform test recoveries, document the results, and update the technical documentation.
Well-prepared recovery procedures and contingency plans reduce recovery time after a cyberattack, system failure, or other major incident.
Response Process
Initial Assessment
We review the signs of the incident, affected systems, backup availability, and potential constraints. We then define the immediate priority actions.
Containment and Data Collection
We limit the spread of the threat, preserve the current state of the systems, and collect the data required for analysis.
Root Cause Analysis and Remediation
We identify malicious changes, the likely attack vector, and vulnerable components. We remove malicious code and remediate the vulnerabilities discovered.
Recovery and Validation
We restore services, verify data integrity and the availability of key functions, and confirm infrastructure stability.
Security Hardening and Monitoring
We update security configurations, rotate compromised credentials, and enable logging, monitoring, and alerts.
Documentation and Handover
We provide a report on the work completed, recommendations, and a plan for further recovery or security improvements.
Engagement
Models
Emergency Recovery
We respond to signs of a security breach, malware infection, blocklisting, or the unavailability of critical services. The priority and start time are agreed following an initial assessment of the incident.
Infrastructure Audit and Security Hardening
We assess servers, services, access controls, and security configurations, resolve critical issues, and prepare a plan for further improvements.
Disaster Recovery Project
We analyse critical systems, define RTO and RPO targets, verify backups, and develop documented recovery procedures.
Ongoing Managed Support
We monitor infrastructure health, perform scheduled maintenance, verify backups and recovery readiness, respond to incidents, and provide regular reporting.
Restore Operations and Reduce the Risk of Another Incident
Tell us what happened and which services have been affected. We will ask a few initial questions, identify the priority actions, and recommend a safe recovery process.
The response timeframe and engagement model will be agreed following an initial assessment of the incident.