Our incident response timeline
Four stages with defined times, from your call to stabilization.
Your call, at any hour
You report the incident on our 24/7 line and an incident manager takes your case right away, day or night. On that first call we define the scope of the work and the cost before we start.
Activation in under 2 hours
We open secure remote access to your environment and containment begins: we isolate compromised systems and cut off the attacker's access from the first session.
Diagnosis and isolation
We map the real scope of the incident: which systems the attacker touched, how they got in and what information was at risk. Your leadership gets a status update at every step.
Stabilization in under 48 hours
We contain the threat, remove persistence and get recovery underway with your IT team. These are typical times and vary with the scope of the incident.
Incident response for every type of attack
From ransomware to zero-day, every scenario has a tested procedure.
Ransomware incident response
Privileged accounts
Data breach response
Advanced persistent threats (APT)
Advanced malware
Zero-day attacks
An incident response team on call 24 hours a day
We work as your on-demand CSIRT: each specialist steps in at their stage.
Incident managers
They coordinate the response end to end and keep your leadership informed at every step of the case.
Digital forensics specialists (DFIR)
They preserve the evidence and rebuild the full timeline of the attack for the report.
Threat analysts
They identify the attacker, their tools and the entry point they used.
Recovery specialists
They guide the restoration of systems and data to get your operation back to normal as soon as possible.
What our incident response service includes
Immediate containment
We isolate compromised systems and cut off the attacker's access from the first remote session.
Full eradication
We remove malware, persistent access and compromised accounts until the way in is closed.
Guided recovery
We support the restoration of systems and data, coordinating with your IT team at every step.
Forensics included
We investigate the origin, path and scope of the attack, and preserve the evidence for every finding.
Negotiation advisory
If there's a ransom involved, we advise you during the negotiation; the decision and any payment stay in your hands.
Per incident or on retainer
Activate the service when you need it, with the cost defined before we start. If you prefer, set up an incident response retainer in advance.
You close with a digital forensics and incident response (DFIR) report
Digital forensics answers your leadership's three questions: what happened, how the attacker got in and how to keep it from happening again.
◉ Executive report
A document for leadership, in business language:
- What happened and what it meant for operations.
- Key incident times and critical decisions made.
- Evidence preserved for audits, insurance or legal proceedings.
- Recovery path by phase, with owners.
◉ Technical report
A document for your IT team, with what they need to close the gaps:
- Root cause and entry point of the attack.
- Technical timeline mapped to the MITRE ATT&CK framework.
- Indicators of compromise (IOCs) to block across the rest of the environment.
- Prioritized hardening recommendations.
We respond alongside your IT team
One manager leading the case
One person coordinates the response and reports progress to you, so you never have to chase updates.
ISO 27001 certified
Our practices are aligned with international standards and audited every year.
Our own 24/7 operations
Our security operations center monitors and responds around the clock from Mexico, for companies in the United States and Latin America.
The knowledge stays with you
We document every decision in the case and deliver the recommendations your team needs to close the gaps.
TECNETONE CERTIFICATIONS
Certified backing in every engagement
Your incident is handled by certified engineers at an ISO 27001-certified company.
NEO answers common questions about incident response
Incident response is the work of a team of outside cybersecurity specialists who step in when a company suffers a cyberattack (ransomware, an intrusion or data theft) to contain the threat and remove it from the network. When the case closes, they deliver a forensic analysis of what happened, with the root cause and the attack timeline. At TecnetOne it's activated 24/7, remotely, with or without a retainer.
Disconnect the affected devices from the network without shutting them down, so the evidence isn't lost, and don't negotiate on your own. Call our 24/7 line (+52 55 7579 3869): remote containment starts in under 2 hours, and if you decide to negotiate, we advise you through the process.
Each incident is quoted based on the size and criticality of the affected environment. We work with defined scopes and transparent pricing, so you know the cost before the work starts. If you'd rather have the response ready in advance, you can also set up an incident response retainer with us.
It can support them. We preserve the evidence of the attack and deliver a technical report with the timeline and root cause, useful for audits, cyber insurance claims or legal proceedings. We work with your cyber insurer when your policy requires it, and if your case needs a formal expert report, we guide you on the next steps.
Yes, and that's ideal. Your team knows the infrastructure and we bring the incident expertise. We coordinate every action with your IT leads, and the knowledge gained during the case stays with your company.
It depends on how much was encrypted and what backups are available. Containment and initial stabilization take under 48 hours; full recovery can take from days to weeks. Having immutable backups shortens that time considerably.
You don't need to be a customer. The service can start without a prior contract: we define the scope on the first call and remote response begins the same day, for companies in the United States and Latin America. After the incident, many companies continue with TecnetSOC, our SOC as a Service that monitors and responds to threats 24/7.
Take back control of your operation
Tell us what's happening and an incident manager will review your case right away.
Or call us now: +52 55 7579 3869 · Pay per incident, or set up a retainer.