home  /  contact
contact

Tell us about the incident.

Standard of care, response adequacy, technical causation, or what expertise a matter needs. Describe what you are dealing with and we will tell you plainly what it would take.

Every inquiry is read by a person. If something is time-sensitive, an active incident, a notification clock running, an expert disclosure deadline, or a coverage decision pending, say so and it moves to the front of the queue.

get in touch

Send us the details.

Four fields are required: your name, an address we can reply to, and a description of the matter. The rest helps us respond usefully the first time rather than with a round of questions.

We reply within one business day.

Message received.

Thank you, your message is with the team and someone will respond, usually within one business day. If this concerns a live incident, please act on the preservation steps alongside — they do not wait for us.

Before you reboot anything

The forensic record degrades on three clocks and none of them waits for counsel. Volatile memory holds the running malware, live connections and sometimes decrypted credentials, and it is gone the instant a machine is rebooted. Log retention is commonly thirty days and sometimes seven, so an intrusion discovered weeks after initial access may already have lost the evidence of how it began. And remediation is destructive by design: reimaging a compromised host is correct, and it ends that host’s forensic history. Two things are worth doing right now, before anything else: suspend log rotation, and image before you rebuild. Both take minutes. Neither can be done retrospectively.

incident conciergeorientation · not a security opinion
Happy to help. Tell me roughly what happened and when it was discovered, and whether anything has been rebooted, reimaged or restored. I'll help scope it. I won't assess a live incident or opine on whether the security was reasonable.