Skip to main content
ThreatHunt and ThreatContain revealed.See the announcements
Active incident

Breached, or think you might be?

Call us. Our SOC is staffed 24/7 by people in the United States, and the fastest way to get an incident responder engaged is the phone.

+1 (954) 334-9988

24 hours a day, every day US-based SOC · SOC 2 Type 2 · ISO 27001

Not urgent? The normal contact form is the better route.

Or have a responder call you.

Leave an address we can reach you on and we’ll come to you. One field is required — everything else helps us arrive already knowing something, but none of it should slow you down.

Use any address you can actually read right now, including a personal one. If your corporate mail is part of the incident, don’t use it.

Monitored 24/7. The phone is still faster.

While you wait for us

Six things that help and won’t destroy evidence. If any of them conflicts with advice from your insurer or counsel, follow theirs.

01

Isolate, don’t power off

Disconnect affected machines from the network — pull the cable or disable Wi-Fi. Shutting them down destroys memory-resident evidence a responder may need.

02

Stop deleting things

Leave logs, mailboxes and files as they are, including the malicious ones. Preserve backups and don’t overwrite them.

03

Don’t engage the attacker

No replies, no negotiation, no payment decisions yet. That call belongs with your legal counsel and insurer, once someone has scoped the incident.

04

Start a timeline

Note what you saw and when, in plain text somewhere off the affected systems. It saves hours later and is often the first thing an insurer asks for.

05

Use an out-of-band channel

Assume email and chat may be readable by the attacker. Coordinate by phone or a fresh channel until you know otherwise.

06

Notify your insurer early

Most cyber policies require prompt notification and many specify approved responders. Calling late can affect a claim.

If this is an active incident, stop reading and call +1 (954) 334-9988.