Reactive engagement / 05

Digital Forensics and

Incident Response.

Where the hard cases land. Reconstruct what happened even when the evidence is cold, then contain, eradicate and recover.

During an incident the questions are simple and the answers are not. What got in, how far did it go, what did it take, and is it still here. Answering them takes evidence, and evidence degrades from the moment the incident starts.

When another team has already closed a case, this is often the second call, and the one that resolves it.

We take incident response engagements from Switzerland, across Europe and the Gulf, and the first call is with the person who will do the work.

40-80h Live incident, excluding the report
16h Final report, shaped to your questions
32h+ Post-mortem investigation, report included
Daily Technical updates during an engagement
[ HOW TO HOLD IT ]

Call us now, or agree the terms first.

Both routes reach the same team in Zug and the same standard of work. The difference is how much has to be negotiated on the day something happens.

A

Emergency response

Emergency incident response, for when something is happening now. Rapid deployment, containment, forensic analysis and guided recovery for ransomware, insider activity, data breach and targeted intrusion. If something is happening now, call rather than write.

What it assumes
Scope, access and communication protocols are established at the start of the engagement, while the incident is running.
B

Incident Response Retainer

Secures priority access to incident response before you need it, with the environment already understood and the communication protocols agreed in advance. Retainer hours not consumed by incidents are not lost. They convert to other consulting work.

What it assumes
A scoping conversation now, so that on the day of an incident the only open question is the incident itself.

What the work covers

The work, in the order that limits damage.

Containment and evidence preservation pull against each other. Deciding that trade-off correctly, under time pressure, is most of the job.

01

Incident Commander

One person accountable for the whole response, with the authority to gate it. Workstreams run in parallel, decisions are logged, and the executive briefing comes from a single voice.

Large incidents fail on coordination more often than on technique. Where several teams and vendors are on site, the work is keeping investigation, recovery, monitoring and hardening from pulling against each other, and holding the gate that stops a system being restored before it has been cleared.

02

Rapid containment

Immediate action to stop the incident spreading: isolating affected systems, disabling compromised accounts and applying emergency measures.

The order matters. Pulling a machine off the network destroys volatile evidence that may be the only record of how the attacker got in, so containment steps are sequenced against what still needs to be captured.

03

Forensic analysis

Disk, memory and cloud evidence collected and analyzed to establish root cause, attack vectors and the true extent of the compromise, then assembled into one sequence of events across the estate.

A list of findings is not an account of an incident. Each step carries the artifact that supports it and a stated confidence level, including where the evidence is partial, degraded or was written off as unrecoverable. Evidence others consider unusable is regularly where the answer is found.

04

Recovery and hardening

A remediation plan executed to eradicate the threat and return operations to a secure state, followed by a review that turns the incident into improvement.

Recovery without eradication returns you to the same position with less evidence. The route that was used is closed before systems come back, and the review says what to change so it stays closed.

How an engagement runs

Five phases, from the call to the review.

Read it left to right: two steps in sequence, four streams in parallel, a coordinated eviction, then the review. The clock above them is the evidence, and it starts running before we do.

EVIDENCE AVAILABILITY falling from the first minute of the incident MEMORY DFIR ARTIFACTS CHANGE LOGS ROTATE FREE SPACE REUSED INCIDENT RESPONSE PHASES sequential where it has to be, parallel everywhere else PHASE 01 Activation and triage scope, severity PHASE 02 Initial containment stop the damage, not the actor PHASE 03 · A Enhanced threat detection see re-entry PHASE 03 · B Hardening of the environment clean ground for recovery PHASE 03 · C Forensic analysis what happened PHASE 03 · D Coordination of initial recovery restore only clean PHASE 04 · A Full containment every path at once PHASE 04 · B Eradication and full recovery remove and verify PHASE 05 Post-incident review close the path Modern incident response runs on efficiency and pragmatism. The standard IR phases in order work only for simple incidents. Efficiency because the actor is still working. Pragmatism because restoring business operations cannot wait for the full picture.
PHASE 01

Activation and triage

On notification the response activates and a rapid triage establishes the scope and severity of the incident.

Effort goes where it changes the outcome.

PHASE 02

Initial containment

Stop the bleeding. Enough action to halt active damage, balanced against the evidence the investigation still depends on.

Where damage is already running, speed wins. Where an actor has been quiet for months, it does not, and containment waits.

PHASE 03 · IN PARALLEL

Four streams, one command

Enhanced threat detection. Hardening of the environment. Forensic analysis. Coordination of initial recovery.

They are not independent tracks. Analysis produces the indicators detection hunts on, detection proves whether hardening held, and neither lets recovery restore a system that is not clean.

PHASE 04 · IN PARALLEL

Full containment, eradication and recovery

The eviction is held back until the four streams have made it safe, then executed as one coordinated action across the estate.

Taken piecemeal it tells the actor what you know and lets them re-enter through the access you have not found yet.

PHASE 05

Post-incident review

Once the incident is resolved, a review establishes what happened, how the response performed, and what to change so the same path is closed.

What you receive

Four documents, written to be used.

Every conclusion states what was observed, what it supports, and how confident we are in it. Where the evidence does not settle a question, that is written down.

Incident report The nature of the incident, the response actions taken and the impact on the organization, with a timeline of events and the evidence supporting it.
Forensic analysis report Where the case requires it, a full forensic account of the evidence, the methods applied and the conclusions drawn, written to withstand external review.
Containment and remediation plan Specific recommendations for addressing the vulnerabilities exploited, recovering systems, and closing the route that was used.
Post-incident recommendations Lessons learned converted into actions that raise the security posture, so the engagement leaves the organization stronger than it found it.

Anonymized case

Three vendors, one destructive attack, and nobody holding the whole picture.

Client, country, sector detail, dates and attribution are removed. The mechanism, the sequence and the decisions are unchanged.

CASE 01

INCIDENT COMMAND

DESTRUCTIVE ATTACK, STATE-LINKED ACTOR

NIST SP 800-61R3 / ICS-214 / ISO 27035

The response was designed to work without the answer it depended on.

A government authority in the Middle East, operator of critical public infrastructure, lost its public-facing services overnight. Wiper malware had been pushed to every domain-joined system through a weaponised Group Policy object. More than fifteen servers were destroyed and over a thousand endpoints were targeted. Hours before the wiper ran, the primary backup appliance had been logged into from a compromised jump server and wiped, so that recovery would fail even if the malware was caught.

Three organizations were already on site. One owned the forensic investigation, one owned recovery, the internal SOC owned monitoring, and none of them were on a shared call. Recovery had begun restoring systems that had never been imaged. The investigation could not confirm the attacker was evicted, and the business could not wait for it to. I was brought in as Incident Commander to make the response work under that uncertainty instead of pausing for it.

Four workstreams, one command. A forensic clearance gate between investigation and recovery, so nothing was restored or rebuilt before imaging on that system was confirmed, and nothing returned to production without EDR reporting to the SOC. Every hardening measure paired with a detection use case, so an attempt to work around a control that had just been closed would surface instead of passing silently. When the intrusion turned out to be an eighteen-month campaign with multiple independent backdoors, the recovery sequence changed repeatedly, and the command structure is what let it change without the response coming apart.

Communications ran on the same discipline. One daily executive briefing, one voice to the board, the regulator and legal counsel, and no technical team speaking to any of them directly. Regulatory notification was carried as a formal decision with a legal clock running against it. Every line of that briefing was marked confirmed, assessed or unknown, and the unknowns stayed visible.

By day seventeen all twenty-eight applications in the two highest-priority tiers were restored, public-facing services among them.

18 months Undetected dwell before detonation
<2h VPN account to Domain Administrator
4 Workstreams under one command
28 / 28 Priority tier 1 and 2 applications restored

Who this is for

Where the call usually comes from.

Active incident Organizations in an active breach that need senior hands on it today.
Unsatisfying closure Teams holding a case that was closed without a satisfying answer.
Board and legal Boards, regulators and legal counsel needing findings that will survive scrutiny.
Crisis management Executives who need one voice to the board, the regulator and the press while the technical response runs.
Ahead of the day Organizations that would rather agree terms and access now than negotiate them during a crisis.

What we need to scope a program

Give us these and we can price it.

Environment size How many endpoints and how many users.
Microsoft 365 Whether it is in use, and for how many users.
Internet-facing applications A count of the web applications exposed to the internet.
Telemetry What logging exists today and how long it is retained.

The method, in the open

How the evidence in these cases actually works.

Evidence of execution Proving a program ran on Windows, source by source, with what each one contains and what it will support in a report.
NTFS timestamps What file timestamps mean, and where a tool that wrote them leaves a mark the file system would not.
Deleted files What survives a deletion on NTFS, which is most of the reason a case that looks closed usually is not.

NEXT / CAPABILITY

Solutions

The four categories and the eight named engagements inside them.

NEXT / SCOPING

Engage

Describe the situation. If we are the wrong firm for it, we will say so.