113SEC  —  INCIDENT RESPONSE
X000Y000
[113SEC]TR
SUPPORT
+
+
[ 08 ] — INCIDENT RESPONSE

INCIDENTRESPONSE

If your files are encrypted, your server is compromised, or something simply looks wrong: stop, don't shut the machines down, and call us. You don't need to be a customer.

LINE24/7 OPEN
FIRST STEPISOLATION
PHONE+90 549 904 46 80

Incident response is the planned work of removing an attacker from your systems, stopping the spread, preserving evidence intact and bringing the business safely back up — starting the moment an attack is discovered.

The first hours decide the outcome. Shutting servers down in panic, deleting files or reformatting immediately usually destroys the chance of recovery and the evidence at the same time. The first move is isolation, not cleanup.

WHAT WE DO
IN THE · FIRST HOUR

  • 01
    First Contact & Triage

    We establish the picture on the phone: what's encrypted, which systems are affected, whether backups exist, whether the attack is still live — and tell you exactly what to do next.

    01
  • 02
    Isolation

    Affected machines come off the network, remote access is closed, compromised accounts are suspended. The goal is to stop the spread — not to delete.

    02
  • 03
    Evidence Capture

    Before systems change, we take disk and memory images and preserve logs. This is where the evidence for forensics and any legal process is created.

    03
  • 04
    Root Cause Analysis

    Where did they get in, how long were they inside, what data did they touch. Restoring before answering this means leaving the same door open.

    04
  • 05
    Recovery & Validation

    Restore from clean backup, bring systems back in stages, and verify there is no reinfection. Where no backup exists, we assess the remaining options.

    05
  • 06
    Report & Hardening

    What happened, how, what we did and what's needed so it doesn't recur — including the technical report you need if a KVKK breach notification applies.

    06
+FIG.01 — RESPONSE CHAIN

WHEN
TO & CALL US

01

Ransomware

File extensions changed, nothing opens, a ransom note left behind. Encryption may still be running — call before powering anything off.

02

Hacked Server or Website

Unknown pages or redirects on your site, or processes on your server you don't recognise.

03

Compromised Email

Fake invoices sent in your name, or rogue forwarding rules set up in a mailbox (BEC / fraud).

04

Suspected Data Breach

Your data seen in third-party hands, or a suspicion of bulk export.

05

Unauthorised Access

Leaked credentials, logins from unfamiliar locations, or new administrator accounts appearing.

06

KVKK Breach Notification

If a notification duty arises, we support the technical determination and reporting side.

24/7 EMERGENCY LINE · RANSOMWARE · ISOLATION · FORENSIC IMAGE · ROOT CAUSE · RECOVERY · KVKK · HARDENING · 
1Isolate first — do not delete or reformat
2Preserve evidence — memory and disk imaged
3No restore before root cause is known
4Recovery validated — reinfection checked

CALL FIRST
DON'T · PAY

++FIG.02 — CASE CONSOLE

Paying a ransom is no guarantee your files come back — and a significant share of organisations that pay are targeted again by the same group.

The decision is yours, but there are things to know before making it: is a restore possible, does the attacker actually hold the key, and has a copy of your data already left the building. A payment made without those answers is often loss on top of loss.

Some ransomware families have free decryptors; in other cases recovery is possible from shadow copies or backups the attacker never reached. We check those first.

Payment also carries legal and financial consequences. We give you a clear technical picture so the decision is made with information — we don't make it for you.

Related reading: backup and restore testing · how security monitoring works · managed security so it doesn't happen twice.

CALL NOW: +90 549 904 46 80 ↗

FREQUENTLY
ASKED · QUESTIONS

  • 01
    Ransomware just hit us — what do we do first?

    Disconnect affected machines from the network but do not power them off; shutting down destroys memory evidence and sometimes the chance of decryption. Keep the ransom note and a sample encrypted file, don't touch your backups, and call us.

  • 02
    Can encrypted files be recovered?

    It depends. Some ransomware families have free decryptors; in other cases shadow copies or backups the attacker couldn't reach make recovery possible. We identify the family first and give you realistic options in writing.

  • 03
    Should we pay the ransom?

    Payment doesn't guarantee your files return, and many organisations that pay are hit again. Before that decision we clarify whether a restore is possible, whether data was exfiltrated, and what technical alternatives exist.

  • 04
    How fast do you respond?

    The emergency line is open 24/7 and triage starts on the call itself — you'll be applying containment steps during the first conversation. Remote response is typically same-day, with onsite work across İstanbul and the surrounding region where needed.

  • 05
    We're not your customer — will you still help?

    Yes. Incident response is available to companies that aren't existing clients. We work case-based, and you're under no obligation to move to an ongoing service afterwards.

  • 06
    Do we need to file a KVKK breach notification?

    If personal data is involved a notification duty may arise, and the window is short. We technically establish what was affected and prepare the report you need; the legal assessment is made with your lawyer.

"THE FIRST HOUR AFTER AN ATTACK DECIDES THE NEXT SIX MONTHS."

UNDER ATTACK
RIGHT NOW?

CALL NOW: +90 549 904 46 80 ⟶