INCIDENTRESPONSE
If your files are encrypted, your server is compromised, or something simply looks wrong: stop, don't shut the machines down, and call us. You don't need to be a customer.
Incident response is the planned work of removing an attacker from your systems, stopping the spread, preserving evidence intact and bringing the business safely back up — starting the moment an attack is discovered.
The first hours decide the outcome. Shutting servers down in panic, deleting files or reformatting immediately usually destroys the chance of recovery and the evidence at the same time. The first move is isolation, not cleanup.
WHAT WE DO
IN THE · FIRST HOUR
- 01First Contact & Triage
We establish the picture on the phone: what's encrypted, which systems are affected, whether backups exist, whether the attack is still live — and tell you exactly what to do next.
- 02Isolation
Affected machines come off the network, remote access is closed, compromised accounts are suspended. The goal is to stop the spread — not to delete.
- 03Evidence Capture
Before systems change, we take disk and memory images and preserve logs. This is where the evidence for forensics and any legal process is created.
- 04Root Cause Analysis
Where did they get in, how long were they inside, what data did they touch. Restoring before answering this means leaving the same door open.
- 05Recovery & Validation
Restore from clean backup, bring systems back in stages, and verify there is no reinfection. Where no backup exists, we assess the remaining options.
- 06Report & Hardening
What happened, how, what we did and what's needed so it doesn't recur — including the technical report you need if a KVKK breach notification applies.
WHEN
TO & CALL US
Ransomware
File extensions changed, nothing opens, a ransom note left behind. Encryption may still be running — call before powering anything off.
Hacked Server or Website
Unknown pages or redirects on your site, or processes on your server you don't recognise.
Compromised Email
Fake invoices sent in your name, or rogue forwarding rules set up in a mailbox (BEC / fraud).
Suspected Data Breach
Your data seen in third-party hands, or a suspicion of bulk export.
Unauthorised Access
Leaked credentials, logins from unfamiliar locations, or new administrator accounts appearing.
KVKK Breach Notification
If a notification duty arises, we support the technical determination and reporting side.
CALL FIRST
DON'T · PAY
Paying a ransom is no guarantee your files come back — and a significant share of organisations that pay are targeted again by the same group.
The decision is yours, but there are things to know before making it: is a restore possible, does the attacker actually hold the key, and has a copy of your data already left the building. A payment made without those answers is often loss on top of loss.
Some ransomware families have free decryptors; in other cases recovery is possible from shadow copies or backups the attacker never reached. We check those first.
Payment also carries legal and financial consequences. We give you a clear technical picture so the decision is made with information — we don't make it for you.
Related reading: backup and restore testing · how security monitoring works · managed security so it doesn't happen twice.
CALL NOW: +90 549 904 46 80 ↗FREQUENTLY
ASKED · QUESTIONS
- 01Ransomware just hit us — what do we do first?
Disconnect affected machines from the network but do not power them off; shutting down destroys memory evidence and sometimes the chance of decryption. Keep the ransom note and a sample encrypted file, don't touch your backups, and call us.
- 02Can encrypted files be recovered?
It depends. Some ransomware families have free decryptors; in other cases shadow copies or backups the attacker couldn't reach make recovery possible. We identify the family first and give you realistic options in writing.
- 03Should we pay the ransom?
Payment doesn't guarantee your files return, and many organisations that pay are hit again. Before that decision we clarify whether a restore is possible, whether data was exfiltrated, and what technical alternatives exist.
- 04How fast do you respond?
The emergency line is open 24/7 and triage starts on the call itself — you'll be applying containment steps during the first conversation. Remote response is typically same-day, with onsite work across İstanbul and the surrounding region where needed.
- 05We're not your customer — will you still help?
Yes. Incident response is available to companies that aren't existing clients. We work case-based, and you're under no obligation to move to an ongoing service afterwards.
- 06Do we need to file a KVKK breach notification?
If personal data is involved a notification duty may arise, and the window is short. We technically establish what was affected and prepare the report you need; the legal assessment is made with your lawyer.
"THE FIRST HOUR AFTER AN ATTACK DECIDES THE NEXT SIX MONTHS."