Ransomware, intrusion & malware investigations
Understand the path and impact of an intrusion while your teams work to restore operations. We correlate endpoint, identity, network and cloud evidence to support containment, recovery and a clearer account of the incident.
Discuss your requirements
Establish priorities with the response team
An active incident combines operational urgency with evidence that may disappear. We agree an incident lead, critical services, available telemetry, decision authority and communication channels. Investigation tasks are prioritised alongside containment and recovery. Actions that change systems are coordinated with the responsible team and recorded, so the later timeline distinguishes response activity from the intrusion.
Build the intrusion timeline
The analysis connects endpoint detections, operating-system artefacts, identity events, remote access, network records and cloud logs where available. We examine the earliest supported activity, changes in privilege, movement between systems and signs of persistence. The earliest observed event may not be the initial entry point. We identify this distinction and explain how coverage gaps affect the estimated incident window.
Examine malware and volatile evidence
Relevant suspicious files, scripts and configuration can be analysed in an isolated environment to understand behaviour and identify useful indicators. Where feasible and authorised, memory evidence may help explain active processes, sessions or injected code. The method depends on system condition, operational constraints and collection timing. Malware names or shared indicators do not by themselves prove who carried out an attack.
Separate encryption, access and data theft
Ransomware impact is more than the files that were encrypted. We assess potentially affected systems, access to sensitive repositories and evidence of staging or transfer. An attacker’s claim of stolen data is treated as a claim until supported. The exposure assessment distinguishes confirmed observations, plausible scenarios and questions that cannot be resolved from the available evidence. This helps management and advisers make decisions with an explicit account of uncertainty.
Support a defensible return to service
Recovery planning should address the access paths and affected identities identified by the investigation. We help define checks for restored systems, residual access, security configuration and monitoring, while business owners approve operational restoration. The closing report includes a supported chronology, scope, root-cause findings where established and prioritised improvements. Lessons feed into monitoring and incident readiness rather than ending with the technical report.
Identify the entry point and subsequent movement
An investigation can examine the relationship between the initial access, affected identities and later activity across systems. The goal is to develop an evidence-supported sequence that informs containment and remediation. Where sources are missing, the chronology should show the gap rather than imply complete visibility. Different business services may have different exposure and recovery requirements.
Assess data theft separately from encryption
Encrypted files demonstrate an effect on availability, but questions about access to information or transfer outside the environment need their own evidence. We examine the available records relevant to those questions and identify what they can establish. Threat-actor statements and material supplied by third parties are recorded as claims unless independently corroborated within the investigation.
Validate recovery decisions with the response team
Rebuilding an affected device does not resolve every identity, configuration or provider dependency involved in an intrusion. We can help define checks for the agreed recovery scope and track the remaining actions with their owners. The decision to restore a business service should state the evidence reviewed, accepted uncertainty and monitoring or follow-up work still required.
What you receive
- Incident evidence map and collection priorities
- Intrusion timeline and affected-system assessment
- Malware or indicator analysis where in scope
- Data-exposure findings with confidence and limitations
- Recovery validation criteria and lessons-learned report
- Intrusion sequence with evidence gaps and competing explanations
- Recovery validation actions assigned to system and identity owners
Common questions
Can you guarantee the attacker has been completely removed?
No investigation can guarantee the absence of all attacker activity. We define the evidence reviewed, validation performed and remaining monitoring or remediation requirements.
Should systems be shut down immediately?
The right action depends on the incident, safety, business impact and evidence. Contact the responsible incident team for case-specific containment decisions; avoid uncoordinated changes.
Do you negotiate or pay a ransom?
This service covers technical investigation and recovery support. Any separate legal, insurance or negotiation work requires its own appropriately authorised arrangement.
Can you work with our insurer’s incident-response team?
Yes, where the engagement and reporting arrangements permit it. We agree responsibilities, evidence exchange, decision authority and the recipients of findings with the relevant parties.
Can you assess an attacker’s claim that data was stolen?
We can compare the claim with available evidence and document what is supported, contradicted or unresolved. A claim alone is not treated as proof, and limited logs may prevent a definitive answer.
Connected expertise
All services
Incident response & forensics
Investigate incidents with structured evidence collection, clear timelines, and practical recovery recommendations.
Explore service
Email & cloud investigations
Investigations across Microsoft 365, Google Workspace and cloud environments, including business email compromise, access and data sharing.
Explore service
Forensic readiness
Evidence-source mapping, logging and retention review, preservation procedures and scenario exercises for investigation readiness.
Explore service