Emergency response line during an attack
Incident Response and ransomware recovery
In the event of a cyber attack or ransomware incident, we isolate the affected systems, analyse the root cause and restore your business continuity as quickly as possible, with minimal damage. Forensic investigation and recovery run on your own infrastructure. Evidence and logs never leave your organization; the response happens on-premise.
What is incident response?
Incident response is the disciplined process followed once a cyber attack is detected, to limit the damage, stop the attack and bring systems back up safely. In ransomware attacks, time is critical: correct isolation and evidence preservation in the first hours determine both the recovery and the legal notification process. Shutting systems down in a panic often destroys evidence held in memory and makes the investigation harder.
C3T is not a product vendor; we are the team that delivers and operates. We deploy the open source response stack on your own infrastructure, manage the incident on-premise and hand over the report in an auditable form.
What should the first step be in a ransomware attack?
The first step is to isolate systems from the network, not to shut them down; powering off can destroy evidence held in memory. C3T runs its incident response workflow in four stages: (1) isolation, disconnecting affected systems from the network; (2) analysis, preserving evidence and identifying the root cause and scope of infection; (3) recovery, safe restoration from clean backups and images without paying a ransom; (4) reporting, an auditable incident report and, where required, support with KVKK breach notification. Autonomous isolation with TheHive and Cortex and forensic investigation with Velociraptor run on your own infrastructure; evidence and logs never leave your organization.
How does emergency incident response work?
We run the response along two tracks: the emergency response workflow that stops the attack and preserves evidence, and clean ransomware recovery afterwards. Both run on-premise and are fully auditable.
Emergency response workflow
We run the entire process end to end, from the first report of an attack until your systems are back up.
- Isolation: disconnecting affected systems from the network
- Evidence preservation and root cause analysis
- Clean recovery and verification
- Hardening to prevent reinfection
- Auditable incident report
Ransomware recovery
We restore business continuity from clean backups and images, without paying a ransom.
- Identifying encrypted systems and the scope of infection
- Safe restoration from clean backups and images
- Removing persistence mechanisms
- Closing the attack vector
- Business continuity and recovery prioritisation
Forensic investigation (on-premise)
We examine how the attack happened, which data was affected and the chain of evidence on your own infrastructure. Disk images, logs and evidence data are never sent outside; the findings are delivered in an auditable report that supports both recovery and KVKK breach notification.
The open source stack we use
Instead of expensive licences, we combine mature open source response tools with AI triage running on your own servers.
Autonomous isolation and incident management
Playbook-driven incident management with TheHive and Cortex; automatic isolation of affected endpoints triggered by Wazuh alerts.
Forensic analysis and malware investigation
Forensic data collection from endpoints with Velociraptor, malware detection with YARA signatures; the investigation runs on your own infrastructure.
Triage with on-premise AI
A local model running on your own servers sifts through large volumes of logs and alerts to prioritise the incident; your data never leaves your organization.
Why C3T?
Not a consultant who writes a report and leaves; the team that delivers, stopping the attack, bringing systems back up and managing the incident on-premise. We speed up triage and log correlation with on-premise AI.
The team that delivers, not a consultant who writes a report and leaves
From isolation through recovery to hardening, we run the response ourselves, bring your systems back up and take responsibility. After the incident, we put permanent measures in place so it does not happen again.
On-premise, with no data leaving
Forensic investigation, log analysis and recovery are carried out on your own infrastructure. Thanks to the open source stack and on-premise AI, sensitive data, evidence and logs are never sent outside.
Compliance
Which compliance obligations does it cover?
Incident response is not only technical recovery; it also ensures you meet your legal notification obligations on time and in a documented way. We report the response in a form that satisfies these obligations.
KVKK data breach notification
Scope determination and an auditable report to meet the 72-hour notification obligation when personal data is affected.
Institutional SOME / USOM procedure
Running incident notification and response in public institutions in line with SOME/USOM requirements.
BİGR incident management
Compliance with the incident logging, response and reporting requirements of BİGR (Turkey’s Information and Communication Security Guide).
Frequently asked questions
What should we do first during an attack?
Isolate the affected systems from the network rather than shutting them down (powering off can destroy evidence held in memory), avoid making any further changes and contact us through the emergency response line. We handle isolation, evidence preservation and root cause analysis together with you.
Should we pay the ransom?
We do not recommend paying; payment does not guarantee your data will be returned, it funds the attacker and can make you a repeat target. Our priority is restoring business continuity through safe recovery from clean backups and images.
Does our data leave our organization during the forensic investigation?
No. Forensic collection and analysis are carried out on your own infrastructure, on-premise (on your own hardware); logs, disk images and evidence data never leave your organization. This keeps you in line with KVKK and data sovereignty requirements.
Are we obliged to report a data breach?
If personal data is affected, KVKK (Turkish Personal Data Protection Law) generally requires notifying the Personal Data Protection Board within 72 hours of becoming aware of the breach; public institutions also follow the institutional SOME/USOM procedures. We determine the scope of the breach, prepare the auditable report and provide technical support throughout the notification process.
How quickly do you respond?
Once we receive a notification through the emergency response line, we engage as quickly as possible; the first step is isolating the affected systems and preserving evidence. The scope and the target response time are agreed in advance as part of the service framework.
Under attack, or want to be prepared?
Contact us now for emergency response; let us isolate the affected systems and bring them back up safely as quickly as possible. For pre-attack preparation, we can also build your incident response plan together.