Forensic triage
From Rp 30 million
- Rapid assessment of an active incident
- Initial scope of compromise and indicators of attack
- High-priority containment recommendations
Digital forensics
When an incident happens, the speed and accuracy of the investigation decide how much damage it does. We help your team contain the threat, secure evidence, understand the attack timeline and plan a measured recovery.
01
Each engagement is shaped by the type of incident and the systems affected.
01
Establish the extent of the compromise and the priority containment steps so the damage does not spread.
02
Evidence is collected with hash verification and a chain-of-custody record so its integrity can be relied on.
03
Logs, endpoint artefacts and network traces are analysed to reconstruct what the attacker did.
04
Entry point, lateral movement and affected assets are mapped.
05
Recommendations to strengthen controls so a similar incident does not recur.
06
A technical report and an executive summary for management, auditors or legal proceedings.
02
From Rp 30 million
From Rp 85 million
By proposal
Final prices are confirmed after scoping and depend on the number of systems, log sources and the depth of analysis.
03
We collect what is known about the incident, the affected systems and any constraints.
Immediate steps to stop the spread without destroying evidence.
Evidence is collected and hash-verified; every transfer is recorded in the chain of custody.
The timeline is rebuilt from logs, endpoint artefacts and network traffic.
Findings are presented to technical staff and management, with a recovery and prevention plan.
04
05
When there are signs of compromise, a data leak, ransomware or internal fraud, or when the organisation needs an objective, evidence-based account of what happened.
Incident response focuses on containment, eradication and recovery so services return to normal quickly. Digital forensics focuses on collecting, validating and analysing evidence to understand the root cause and support audits or legal proceedings.
Yes. Every acquisition is documented and hash-verified so the integrity of the evidence is preserved.
It depends on the scope: the complexity of the environment, the number of endpoints and log sources, and the depth of analysis needed. We give a time estimate after scoping.
06
For an incident in progress, call our main number and choose “Security incident” on the form. We will help you decide the fastest containment and recovery steps.
Report an incident