Incident response
Something has happened. Start here.
Reach a responder now. The steps below matter in the first hour, whether you talk to us or not.
In India the clock is six hours. CERT-In Directions, 2022 under s.70B of the IT Act require reporting inside six hours of noticing an incident — not of confirming it. The DPDP Act, 2023 separately requires notifying the Data Protection Board and the affected people. If personal data is involved, both apply.
What to do in the first hour
- 01
Do not wipe or rebuild yet
Rebuilding destroys the evidence that establishes what was taken and when — which is what both the regulator and any later prosecution will ask for. Isolate instead of erasing.
- 02
Isolate, do not power off
Pull the affected host off the network, but leave it running. Memory holds the live session, the running process and the connection you will want to trace.
- 03
Revoke sessions and rotate keys
Invalidate active sessions, rotate API keys, tokens and service credentials, and force re-auth for privileged accounts. Assume anything reachable from the compromised host is compromised.
- 04
Start a timeline now
Note what you saw, when you saw it, and every action you take from here, in one place. The notification clock runs from when you noticed — so when you noticed is a fact worth recording precisely.
- 05
Preserve logs before they roll
Auth, application, firewall and cloud audit logs are usually on short retention. Copy them out before the window closes.
Or send us the details
If it is not urgent enough for WhatsApp. Everything here is what a responder needs before the first call.