Protection

Incident response

We investigate your security incidents and help you regain control of the situation

§ 01 · Overview

What is incident response?

Responding to a security incident means investigating any cyberattack (or suspected attack) to clear up the doubts, understand the situation as well as possible and hand you back control of your information system.

This service lets you react quickly and effectively to minimize the impact of the incident on your operations, your data and the reputation of your organization.

Objectives

Incident response pursues several objectives at once:

  • Contain and isolate the incident

  • Fix the flaws behind the incident

  • Analyze and document the incident

  • Put processes in place so it does not happen again

§ 02 · Approach

The HELX approach

Our senior consultants, specialized and certified in security incident response, have handled many engagements of this kind. Our dual expertise in penetration testing and Red Team exercises is a major asset: we know the methodologies attackers use inside and out.

Once the investigation is over and the incident is under control, you receive a full report. It details everything our teams identified, along with improvement suggestions based on what was found, aimed at minimizing future risk and strengthening your ability to detect and handle an incident.

§ 03 · Methodology

Our forensic methodology

Our incident response process follows a structured cycle, based on recognized standards such as ISO/IEC 27035 and the NIST Cybersecurity Framework.

  1. 01

    Initial assessment

    This first phase, usually very quick, aims to identify the affected systems, data or users by analyzing the artifacts immediately available. These artifacts can take various forms (event logs, malicious files, etc.), and the goal is to confirm the incident and assess its impact.

  2. 02

    Incident containment

    Once the incident is confirmed and its scope defined, the priority is to stop it from spreading and to secure the evidence before the attacker decides to cover their tracks. Containment means isolating the affected systems and blocking the entry points.

  3. 03

    Evidence preservation

    With the incident now contained, preserving the evidence is crucial. Backups or copies of the systems must be made before event logs expire or the files left behind by the attackers get deleted by antivirus software. This evidence will also prove very useful in court or when claiming compensation from a cyber insurance policy.

  4. 04

    Full incident analysis

    Analyzing all the traces reveals the nature and origin of the attack, building a complete timeline of the incident and a list of Indicators of Compromise (IoCs) that can later be used to draw up the exhaustive list of affected systems. You receive a full report with all of these elements, plus targeted recommendations on the improvement areas spotted during the investigation.

  5. 05

    Eradication of all threats

    Using the report from our consultants, you will need to eradicate everything the attackers left behind (files, accounts, backdoors, etc.) and fix the vulnerabilities they exploited. If you have doubts or need assistance during this step, we are here for you as well.

  6. 06

    Rebuilding & improvement

    During the incident response process you will probably have had to isolate some systems, and rebuilding them is sometimes the better option. That is the purpose of this final step. In the months following the incident, you will need to restore your information system while consolidating the improvement areas highlighted in our report. Here too, we can support you and even take an active part in the process where needed.

§ 04 · Forensic analysis areas

A bit of technical detail

Our Computer Hacking Forensic Investigator (CHFI) certified experts investigate by analyzing a wide range of information sources.

  • Disk image analysis
  • System log analysis
  • Network log analysis
  • Search for artifacts in system memory
  • Unusual communications
  • Suspicious or unknown processes
  • Suspicious or malicious files
  • Search for vulnerabilities still present

Our other protection services

FAQ

Frequently asked questions

We are under attack right now: what should we do?

Call us immediately or select "incident response" in the contact form. Do not reboot the affected machines; disconnect them from the network if possible: every minute counts, for the evidence as much as for containment.

Do you intervene without a prior contract?

Yes, subject to availability. The 24/7 coverage contract guarantees a response time (SLA of 2, 12 or 24 hours) and prepaid hours at a preferential rate; without a contract, intervention depends on our availability at the time.

How much does the 24/7 coverage contract cost?

From €2,000 to €10,000 excl. VAT per year depending on the chosen SLA, plus packs of prepaid hours at decreasing rates, from €300/h down to €200/h. The online quote simulator details every combination.

What does the team actually do during an incident?

Assessment and containment first, then forensic investigation (origin, scope, affected data), preservation of court-admissible evidence, eradication and support through recovery. You stay informed at every step, in plain language and without jargon.

Can the collected evidence be used in court?

Yes: our forensic methodology preserves the integrity and chain of custody of the evidence, so it can support a criminal complaint or an insurance claim. Our consultants are CHFI certified.

Tell us about your project.

Let us talk through your needs and expectations and build the right service for you.