Our incident response timeline

Four stages with defined times, from your call to stabilization.

Your call, at any hour

You report the incident on our 24/7 line and an incident manager takes your case right away, day or night. On that first call we define the scope of the work and the cost before we start.

Activation in under 2 hours

We open secure remote access to your environment and containment begins: we isolate compromised systems and cut off the attacker's access from the first session.

Diagnosis and isolation

We map the real scope of the incident: which systems the attacker touched, how they got in and what information was at risk. Your leadership gets a status update at every step.

Stabilization in under 48 hours

We contain the threat, remove persistence and get recovery underway with your IT team. These are typical times and vary with the scope of the incident.

An incident response team on call 24 hours a day

We work as your on-demand CSIRT: each specialist steps in at their stage.

Incident managers

They coordinate the response end to end and keep your leadership informed at every step of the case.

Digital forensics specialists (DFIR)

They preserve the evidence and rebuild the full timeline of the attack for the report.

Threat analysts

They identify the attacker, their tools and the entry point they used.

Recovery specialists

They guide the restoration of systems and data to get your operation back to normal as soon as possible.

What our incident response service includes

Immediate containment

We isolate compromised systems and cut off the attacker's access from the first remote session.

Full eradication

We remove malware, persistent access and compromised accounts until the way in is closed.

Guided recovery

We support the restoration of systems and data, coordinating with your IT team at every step.

Forensics included

We investigate the origin, path and scope of the attack, and preserve the evidence for every finding.

Negotiation advisory

If there's a ransom involved, we advise you during the negotiation; the decision and any payment stay in your hands.

Per incident or on retainer

Activate the service when you need it, with the cost defined before we start. If you prefer, set up an incident response retainer in advance.

You close with a digital forensics and incident response (DFIR) report

Digital forensics answers your leadership's three questions: what happened, how the attacker got in and how to keep it from happening again.

◉ Executive report

A document for leadership, in business language:

  • What happened and what it meant for operations.
  • Key incident times and critical decisions made.
  • Evidence preserved for audits, insurance or legal proceedings.
  • Recovery path by phase, with owners.

◉ Technical report

A document for your IT team, with what they need to close the gaps:

  • Root cause and entry point of the attack.
  • Technical timeline mapped to the MITRE ATT&CK framework.
  • Indicators of compromise (IOCs) to block across the rest of the environment.
  • Prioritized hardening recommendations.

We respond alongside your IT team

One manager leading the case

One person coordinates the response and reports progress to you, so you never have to chase updates.

ISO 27001 certified

Our practices are aligned with international standards and audited every year.

Our own 24/7 operations

Our security operations center monitors and responds around the clock from Mexico, for companies in the United States and Latin America.

The knowledge stays with you

We document every decision in the case and deliver the recommendations your team needs to close the gaps.

TECNETONE CERTIFICATIONS

Certified backing in every engagement

Your incident is handled by certified engineers at an ISO 27001-certified company.

ISO-27001--blanco-1-1
TecnetOne Wazuh partner
10
Logos certificaciones-1
12
18
8-1
Logos certificaciones
Acronis partner
Neo, TecnetOne assistant

NEO answers common questions about incident response

Incident response is the work of a team of outside cybersecurity specialists who step in when a company suffers a cyberattack (ransomware, an intrusion or data theft) to contain the threat and remove it from the network. When the case closes, they deliver a forensic analysis of what happened, with the root cause and the attack timeline. At TecnetOne it's activated 24/7, remotely, with or without a retainer.

Disconnect the affected devices from the network without shutting them down, so the evidence isn't lost, and don't negotiate on your own. Call our 24/7 line (+52 55 7579 3869): remote containment starts in under 2 hours, and if you decide to negotiate, we advise you through the process.

Each incident is quoted based on the size and criticality of the affected environment. We work with defined scopes and transparent pricing, so you know the cost before the work starts. If you'd rather have the response ready in advance, you can also set up an incident response retainer with us.

It can support them. We preserve the evidence of the attack and deliver a technical report with the timeline and root cause, useful for audits, cyber insurance claims or legal proceedings. We work with your cyber insurer when your policy requires it, and if your case needs a formal expert report, we guide you on the next steps.

Yes, and that's ideal. Your team knows the infrastructure and we bring the incident expertise. We coordinate every action with your IT leads, and the knowledge gained during the case stays with your company.

It depends on how much was encrypted and what backups are available. Containment and initial stabilization take under 48 hours; full recovery can take from days to weeks. Having immutable backups shortens that time considerably.

You don't need to be a customer. The service can start without a prior contract: we define the scope on the first call and remote response begins the same day, for companies in the United States and Latin America. After the incident, many companies continue with TecnetSOC, our SOC as a Service that monitors and responds to threats 24/7.

Take back control of your operation

Tell us what's happening and an incident manager will review your case right away.

Or call us now: +52 55 7579 3869 · Pay per incident, or set up a retainer.