Kiel · Schleswig-Holstein · Germany-wide Mon–Fri 9–17 CET
+49 15778716239 info@tsbsec.de

Incident Response & Digital Forensics

When it happens, every minute counts. We help with ransomware, data exfiltration and system compromise – fast and structured.

When an attack is already under way you do not need a consultant, you need a rehearsed procedure: contain, analyse, eradicate, recover. We preserve evidence in a court-proof manner, support communication with authorities, insurers and customers, and stay with you until secure normal operations are restored – including the reporting duties under GDPR and NIS2.

Who is this for?Any company can be hit. An incident response retainer agreed in advance makes sense – so that no time is lost on contract negotiations when it matters.

What to do right now

  1. Disconnect affected systems from the network – but do not power them off, or volatile evidence is lost.
  2. Lock compromised accounts and change the passwords of central accounts.
  3. Do not delete anything, do not reinstall, do not respond to ransom demands.
  4. Call us or write with the subject “URGENT” – we get back to you immediately.

Emergency hotline +49 15778716239

First response to incidents within 2 hours (weekdays 9–17), outside these hours on the next working day.

Process

How we work together

1

First contact & immediate actions

Reach us by phone or e-mail. Within minutes you receive first instructions to prevent further damage.

2

Containment

We isolate affected systems, lock compromised accounts and preserve volatile evidence – remotely or on site.

3

Analysis & clean-up

Forensic investigation: how did the attacker get in, what was touched, are they still there? Then we clean up and restore securely.

4

Follow-up

Incident report, support with notifications to authorities and insurers, lessons-learned workshop and hardening against recurrence.

FAQ

Questions about this service

Should we pay the ransom?

In the vast majority of cases we advise against it: paying guarantees neither decryption nor deletion of stolen data, and it funds further attacks. We first check whether backups, decryption tools or recovery are possible – and support you in every decision.

What are our reporting obligations after an attack?

If personal data is affected, the supervisory authority must be notified within 72 hours (Art. 33 GDPR). NIS2 entities report significant incidents to the BSI within 24 hours. We prepare the notifications with you.

What is the benefit of an incident response retainer?

Guaranteed response times, agreed terms and a team that already knows your environment. In an emergency you lose no time on contract negotiations and onboarding – every hour counts.

Let's talk about your needs.

In a free initial consultation we clarify scope, approach and cost – no obligation, on equal terms.

Book an initial consultation

Related services

Penetration Testing & Vulnerability Assessment

We attack your systems in a controlled way before criminals do – and show you exactly where action is needed.

Learn more

Security Audits & Compliance

ISO 27001, NIS2, GDPR, BSI IT-Grundschutz: we bring your security organisation to an auditable level.

Learn more

Managed Security & Monitoring

Around the clock: we monitor your systems, detect attacks early and respond before damage occurs.

Learn more