INCIDENT RESPONSE

When Something Goes Wrong, Act Fast

Ransomware, a hijacked email account, or a strange sign-in can turn a normal day into a crisis. What happens in the first hours decides how bad it gets.

Our Security Operations Center watches every client around the clock and starts containing threats as soon as they are detected. If you are not a client yet, we can still help you stop an attack and get back to work.

Under attack right now?(515) 500-2673Call us directly, day or night. Do not wait on email.
Incident TimelineEXAMPLE
Incident statusACTIVE
  • Threat detected on a front desk computer
  • Computer isolated from the network
  • Malicious process stopped
  • Investigation confirms what was touched
  • Files restored from a clean backup
  • Plain-language report delivered
How We Respond

Five Steps From Detection to All Clear

Every incident follows the same disciplined process, so nothing is missed when the pressure is on.

1
2
3
4
5
Detect

Our 24/7 Security Operations Center spots the threat on a device, in email, or on the network.

Contain

Affected devices are isolated and malicious activity is stopped so the threat cannot spread.

Investigate

We find how it got in, what it touched, and whether anything else is affected.

Recover

Systems are cleaned or rebuilt and data is restored from clean backups where available.

Strengthen

You get a plain-language report and a plan to close the gap that let it happen.

Who We Help

Covered Before, During, and After

Clients are protected around the clock. Everyone else can still call for help.

Every plan

For CyberCore Clients

  • 24/7/365 security monitoring and incident response
  • Automated containment as soon as a threat is detected
  • Ransomware rollback on protected computers
  • Optional pre-approved containment on Advanced and Compliance, so we can isolate a device or disable a compromised account right away, then notify you

Recovery work beyond containment, such as rebuilding systems after an attack, is billed hourly unless your agreement says otherwise.

Emergency help

Not a Client Yet?

  • Call us directly for emergency help
  • We help contain the threat and recover your systems
  • You learn what happened in plain language
  • Ongoing protection, once things are stable

Emergency work for organizations without a plan is billed hourly.

Prepare now

Be Ready Before It Happens

  • A written incident response and breach notification plan, included in our compliance programs
  • Tested backups you can actually recover from
  • Staff trained to spot and report attacks early

We also strongly recommend cyber liability insurance. Get the readiness checklist.

First Steps

What to Do Right Now

If you think something is wrong, these steps help limit the damage while help is on the way.

Disconnect, but do not power off

Unplug the network cable or turn off Wi-Fi on affected computers, but leave them on so evidence is preserved.

Do not pay or reply

Do not contact the attackers, click their links, or pay a ransom before talking with us and your insurer.

Call us

Reach us directly at (515) 500-2673, whether or not you are a client.

Notify your insurer

Many cyber policies require prompt notice and may have their own approved response firms. Check your policy.

Change passwords safely

If an account may be compromised, change its password from a device you trust and confirm multi-factor login is on.

Write down what you saw

Note times, messages, and anything unusual. Do not delete emails, files, or logs.

This is general guidance. Your insurer, attorney, or regulators may have additional requirements.

FAQ

Incident Response Questions

Straight answers for a stressful moment.

Yes. Every plan includes 24/7/365 security monitoring and incident response through our Security Operations Center, including containment. Deeper recovery work, such as rebuilding systems after an attack, is billed hourly unless your agreement says otherwise.

Yes. Call us at (515) 500-2673. Emergency help for organizations without a plan is billed hourly, and we explain what we are doing at every step.

We recommend against paying whenever it can be avoided. Paying does not guarantee you will get your data back, and the FBI does not support paying a ransom. Tested backups are the best way to avoid facing that choice. The final decision involves you, your insurer, and your legal counsel.

It depends on the data involved and the laws that apply to you. Healthcare organizations, for example, have breach notification duties under HIPAA. We help gather the facts, and your attorney advises on notification. CyberCore is not a law firm and does not provide legal advice.

Coverage is always decided by your insurer. Contact them early, because many policies require prompt notice and some assign their own response team.

On Advanced and Compliance, you can authorize our Security Operations Center to isolate a device or disable a compromised account immediately, under a response plan you approve ahead of time. We notify you right after. Without it, our team reviews each containment action before it is taken.

Yes. Our compliance programs include a written incident response and breach notification plan, and every client benefits from tested backups and trained staff. Ask about it during your free security assessment.

Not Sure Which Plan Fits?

Start With a Free Security Assessment