Cyber incident response and NCSC reporting
A hacked website, a data leak, malicious code on the server. We investigate, clean up and prepare the report for the authorities — with evidence, a timeline and an impact assessment.
If an incident is in progress: do not delete files, do not restore from a backup and do not change the server configuration. Those actions destroy the evidence needed for the report, the insurer and finding the gap. Restrict public access to the site and call us — +370 682 88988.
Process
Five stages from the call to the report
The order is not a formality. Clean first and investigate second, and you are left with a tidy system and no answers about how it happened.
- ContainmentWe isolate the affected system from public access and close the active channel while leaving the state intact for the investigation.
- Evidence preservationDisk and database snapshots, server and access logs, file timestamps, hashes — all timestamped with a chain of custody.
- AnalysisWe establish the attack vector, first access time, what the attacker reached, whether personal data left the system and whether the code spread.
- NotificationWe prepare the report for the NCSC and, where applicable, the data protection authority and the EU CSIRT network — facts, timeline, impact assessment and measures taken.
- Recovery and hardeningA clean system, all credentials rotated, gaps closed, monitoring enabled and a final report with recommendations.
Deadlines
NIS2 reporting deadlines
For entities in scope of NIS2 the reporting clock is fixed. We work to that schedule from hour one.
- 24 hours — early warningInitial notification of a significant incident: what happened, whether unlawful action is suspected, whether cross-border impact is possible.
- 72 hours — incident notificationInitial assessment of severity and impact, indicators of compromise, measures applied.
- 1 month — final reportDetailed description, root cause, impact, measures taken and planned.
Specific obligations depend on the entity category. We assess your situation together at the start.
Deliverables
What you receive
- Technical incident reportTimeline, vector, affected systems, indicators of compromise.
- Draft notificationReady text with all required fields — you review and submit.
- Impact assessmentWhether personal data was reached, which categories, how many subjects.
- Remediation planPrioritised: what to do now, what within a month, what to add to internal procedures.
Pricing
A transparent hourly rate
The scope of an incident is unknown in advance, so we work hourly and agree a budget cap before starting. The first conversation and initial assessment are free.
€80 / hour + VAT
- Free initial assessmentWe tell you whether this is an incident and roughly how large.
- Budget cap agreed up frontWe stop at the agreed limit and discuss next steps.
- Report includedDocumentation is not a separate service.
Prevention
Better before the incident
- Scheduled updatesCore, themes and plugins, tested before deployment.
- Hardened configurationSeparated rights, fail2ban, UFW, two-factor authentication for admin access.
- Monitoring and logsChange and login monitoring with alerts on anomalies.
- Verified backupsA backup nobody has ever restored is not a backup.
FAQ
Questions about incidents
What should we do in the first minutes?
Do not delete files and do not restore from a backup. Restrict public access to the site — put it into maintenance mode or block it at server level. Do not change passwords until logs are preserved, unless access is clearly still active. Then contact us.
Do we really have to notify the authorities?
It depends on the entity and the incident. Public sector bodies and entities in scope of NIS2 have a statutory reporting duty. If personal data leaked, the duty to notify the data protection authority — and in some cases the individuals — is assessed separately. We evaluate this with you and prepare the material; the decision is yours.
How long does an investigation take?
A typical WordPress site with a single attack vector takes from a few hours to two days. A server running several systems, or a long undetected presence, takes longer. We give an estimate after the initial assessment.
Do you only work with your own clients?
No. We investigate incidents on sites we did not build or host. We will need server and log access — if it is unavailable, we will say up front what can still be determined.
Can you work alongside our current supplier?
Yes, and that is often how it goes: we investigate and prepare the documents while your existing supplier carries out recovery to our recommendations. It is usually the fastest route.
Suspect an incident?
The first conversation costs nothing and is often enough to tell a technical fault from a breach.