Contact us

Incident Response - Experiencing a security breach?

If you believe your organization is the victim of a cyberattack, NOXMON emergency responders can help — 24/7, U.S.-based, and ready to engage in minutes.

Every minute counts.

During an active incident, the decisions made in the first hours determine how much data is lost, how long operations are disrupted, and whether evidence survives. Our incident responders help you contain the attack, preserve what investigators need, and get your business back online.

Recommended Actions

If you believe you’ve experienced a security breach, we recommend you take the following actions:

STEP 0

Engage an Expert

Call us for 24/7 immediate incident response support at (212) 913-9184. The sooner an experienced responder is involved, the more options you have for containing the incident and preserving evidence.

STEP 1

Make a Plan

Actions taken at the beginning of a breach have a significant effect on the outcome. At this point you have two priorities: prevent or minimize impact to normal operations, and ensure that sensitive data is protected.

Identify what systems and data are at risk and how the attacker’s actions can be blocked. Be aware that containment actions can destroy or compromise evidence, limiting your ability to determine how the compromise occurred or what data was impacted. Start by creating several lists:

  • What systems are impacted?
  • What data is impacted?
  • What methods can you use to contain the situation?
  • What impact will those methods have on normal business operations, preventing exfiltration of data, and preservation of evidence?

These lists become part of the incident documentation and should be updated as the incident progresses.

STEP 2

Document Everything

Maintain a record of all actions taken and the time they occurred. This is especially important when taking actions that may impact evidence, and useful when restoring systems and determining which systems may still be at risk. Keep records on systems the attacker cannot access.

STEP 3

Make Copies

Back up production systems and data before changes are made — this especially applies to malware. Even if anti-virus software identifies a file, malicious files often contain additional intelligence such as command-and-control addresses, links to other payloads, and timeline data. Preserve them for forensic analysis rather than deleting them.

STEP 4

Identify Systems at Risk

Beyond the systems immediately affected, consider how those systems interact with the rest of the network, what information is on them, and how that information could let an attacker pivot — from trust relationships, credentials, and APIs to network diagrams and organization charts.

In our experience, organizations usually under-estimate the extent of systems and data at risk. A complete forensic examination is needed to determine what the attacker had access to; until then, it is safer to assume the worst.

STEP 5

Implement Containment

Once you know which systems are at risk, determine the most effective way to protect your systems and data. Containment is a short-term approach designed to stop the bleeding while more comprehensive solutions are put in place. Common containment actions include:

  • Removing compromised systems from the network — keep them powered on (unless data is actively being destroyed) so memory and other volatile data can be collected.
  • Updating firewall rules to block suspicious systems, while continuing to log attempted connections.
  • Disabling accounts and updating passwords for any user or application accounts that are compromised or at risk.

STEP 6

Communicate Carefully

Assume the attacker can read email and chat on compromised systems. Move incident communications to out-of-band channels, limit details to the people who need them, and involve legal counsel early — regulatory notification requirements may apply depending on the data involved.

Under attack right now?

Don’t work through this alone. Call NOXMON incident response and get an experienced responder on the line.