Incident response, Sydney

The first hours decide what can be proved later. Most evidence is not destroyed by the attacker. It is destroyed by the clean up that follows.

Covers
Ransomware, intrusion, data theft
Output
Written findings, evidence preserved
Reply
Within one business day

Do this now

Do

Right now, in this order

  • Take the affected machines off the network. Unplug the cable or turn off the wireless.
  • Leave them powered on if you can. Memory holds evidence that a shutdown destroys.
  • Write down the time you noticed, what you saw, and everything anybody has already done.
  • Photograph the screen, and keep the ransom note and the email that started it.
  • Change passwords from a device you know is clean, starting with email and remote access.
  • Tell your bank and your insurer if money, card data or personal records are involved.
  • Protect the logs: firewall, server, mail and any camera recorder on the same network.
Do not

Not yet, whatever anybody says

  • Do not wipe, reimage or rebuild the machine.
  • Do not restore a backup over the top of it. That writes over the evidence.
  • Do not run a virus cleaner or a tune up tool across it.
  • Do not delete the ransom note, the phishing email or the suspicious account.
  • Do not log in to look around. Every session writes to the disk you need.
  • Do not pay anything yet. That is a decision for you, your insurer and your lawyer, and it is easier to make once you know what was taken.

If ransomware is encrypting files in front of you, pulling the power is the smaller loss. Note the time you did it. That note is evidence too.

What happens when you hand it over

The investigation runs on copies. The machines are imaged before anything is examined, and the examination happens on the image so the original stays as it was received.

  1. Preserve

    The affected media is imaged and the image is hashed, so what is examined can be shown later to be what was received.

  2. Scope

    Logs, accounts and machines are read against each other to establish what was reached, from where, and when it started.

  3. Close

    You get the changes that shut the access first, in priority order, for your own people to apply.

  4. Report

    A written account of what the evidence shows, with the log entries and artefacts it rests on, and what could not be established.

What this is not

An investigation says what the evidence shows. It cannot promise a legal, insurance or regulatory outcome, and it cannot recover data that has already been written over. Where logging was switched off before the incident, or the retention window has passed, that period stays dark and the report says so rather than filling the gap.

One person does the work here, and it is not a reseller passing your matter to somebody else. That is also why there is no round the clock callout desk to promise you. Reply within one business day.

Getting a hacked mailbox or a stolen account back is a different job to this one. Bring us the machine, the logs, and the question that has to be answered in writing.

What it costs

Work is quoted per matter before it starts. The rate below is what that quote is built from.

That rate is $1,000 a day. All prices are in AUD, plus GST.

The first stage is preserving the evidence, and it is quoted on its own. What the rest costs depends on how many machines are involved and how much of the logging survived, and neither is knowable until the first stage is done.

See the rate in full

Related work

A breach investigation usually runs into two other jobs: the devices that have to be examined properly, and the audit that finds the way in before somebody else does.

Questions people ask in the first hour

Should I turn the computer off?

Take it off the network first. Leave it powered on if you can, because memory holds evidence that a shutdown destroys. If you can see files being encrypted in front of you, pulling the power is the smaller loss. Either way, write down what you did and when.

Can you tell me what data was taken?

Sometimes. It depends on what was logged. Firewall, server and mail logs can show what left and when. Where logging was off, or the retention window has already passed, that period cannot be reconstructed and the report says so.

We already rebuilt the server. Is it too late?

Often not. Backups, mail logs, firewall records and the other machines on the same network usually survive a rebuild. Tell us what was changed and when, so the report records it rather than treating it as original evidence.

Do you work with our insurer or lawyer?

Yes, if you ask. The report is written so a third party can follow it: what was examined, how it was handled, what it shows, and what it does not. What they do with it is their decision, not ours.

Do you also fix the systems?

The investigation comes first, because a rebuild destroys the evidence of how the intruder got in. Once the evidence is preserved, you get a written list of what to close, rotate and rebuild, in priority order. You can hand that to your own IT people.

How fast do you reply?

Reply within one business day. One person does the work here, so there is no round the clock callout desk to promise you. If speed matters more than evidence, say so and we will tell you honestly whether to call somebody else first.

What does it cost?

Work is quoted per matter before it starts. The rate that quote is built from is $1,000 a day, plus GST. Nothing starts until the scope and the quote are agreed in writing.

Tell us what happened and what has already been touched.