Incident response

Something has happened. Start here.

Reach a responder now. The steps below matter in the first hour, whether you talk to us or not.

In India the clock is six hours. CERT-In Directions, 2022 under s.70B of the IT Act require reporting inside six hours of noticing an incident — not of confirming it. The DPDP Act, 2023 separately requires notifying the Data Protection Board and the affected people. If personal data is involved, both apply.

What to do in the first hour

  1. 01

    Do not wipe or rebuild yet

    Rebuilding destroys the evidence that establishes what was taken and when — which is what both the regulator and any later prosecution will ask for. Isolate instead of erasing.

  2. 02

    Isolate, do not power off

    Pull the affected host off the network, but leave it running. Memory holds the live session, the running process and the connection you will want to trace.

  3. 03

    Revoke sessions and rotate keys

    Invalidate active sessions, rotate API keys, tokens and service credentials, and force re-auth for privileged accounts. Assume anything reachable from the compromised host is compromised.

  4. 04

    Start a timeline now

    Note what you saw, when you saw it, and every action you take from here, in one place. The notification clock runs from when you noticed — so when you noticed is a fact worth recording precisely.

  5. 05

    Preserve logs before they roll

    Auth, application, firewall and cloud audit logs are usually on short retention. Copy them out before the window closes.

Or send us the details

If it is not urgent enough for WhatsApp. Everything here is what a responder needs before the first call.