Skip to main content
Incidents Handled Annually — 15-20 active engagements per year across ransomware, data breaches, and targeted attacks

Under Attack? We Contain First, Investigate in Parallel.

Security Brigade delivers 24/7 incident response and digital forensics for enterprises across India. From ransomware recovery to CERT-In 6-hour notification compliance, our DFIR team shuts down active threats while preserving forensic evidence for root cause analysis and regulatory reporting.

6,700+
Assessments
1,000+
Clients
150+
Team
2006
Founded

Trusted by India's leading enterprises

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

The first day

What happens between your call and the first written answer

The order matters. Containment that destroys evidence buys an afternoon and costs the investigation, and a regulatory clock is running through all of it.

01 Hour zero

The call

What happens
Triage with whoever is available on your side, establishing what is known, what is affected and what has already been done. We maintain 24/7 capacity for active incidents, so this conversation does not wait for business hours.
What we ask you not to do
Do not rebuild, reimage or power down affected systems before we have spoken. Every one of those destroys the evidence that answers how far the intrusion reached.
02 Hours one to six

Contain and preserve, together

What happens
Isolation that stops the spread while preserving state: memory and disk imaging before changes, log collection before rotation, and access revocation sequenced so it does not tip off an active intruder.
The clock
CERT-In directions require cyber incidents to be reported within six hours of being noticed. We prepare that notification in parallel with containment, because the deadline does not pause while you investigate.
03 Days one to five

Investigate

What happens
Forensic analysis establishing entry point, dwell time, lateral movement, what was accessed and what left. Our L1 forensic analysts work the evidence, an L2 senior DFIR consultant reviews the reconstruction, and an L3 architect validates the conclusions.
Why the review layers
An incident report is read by people who were not there and may be read by a regulator or a court. A conclusion that one analyst reached alone is a conclusion nobody has tested.
04 After

Close it properly

What happens
Eradication verified instead of assumed, a hardening plan against the specific path that was used, and a written report covering the timeline, the evidence and the outstanding risk.
The part that is skipped
Verification that the access is actually gone. Reinfection through a persistence mechanism nobody found is the second incident, and it is the same incident.

Before it happens

Four things that decide how the first day goes

Four things that decide how the first day goes
StateWhat it meansWhat follows
Someone can declare an incident A named person with the authority to say this is an incident, reachable out of hours, without needing a meeting first. The single highest-value item on this list. Most of the delay we see in the first six hours is not technical; it is nobody being sure they are allowed to start.
Logs exist and reach back far enough Authentication, network, endpoint and application logs retained long enough to cover a dwell time you do not yet know. Determines whether the investigation can answer what was accessed. Where retention is short, the honest report says the question cannot be answered, which is a worse conversation than the cost of storage.
Someone can authorise isolation A decision path for disconnecting a production system at 3am that does not require assembling the board. Containment delayed for authorisation is the most expensive delay in the sequence, because the intruder is still working while it is resolved.
The notification path is rehearsed Who files with CERT-In, what the submission contains, who signs it, and who tells customers. A six-hour clock is decided before hour one. Invented under pressure it consumes exactly the people who should be running the response.
Key
  • Buys you hours
  • Decides what can be answered
  • Costs the deadline

Being straight about scope

What we do, and what we will tell you to get elsewhere

We investigate and we respond. That means live incident work with 24/7 capacity for active incidents, forensic analysis with its own review layers, containment and eradication guidance, regulatory notification support, and the hardening that stops a repeat. It does not mean we run your security monitoring, and it does not mean we operate your disaster recovery. Those are standing operational functions, they belong with a provider who holds them continuously, and a firm that claims everything in this space is usually describing a partner network. Saying so plainly costs us a line on a capability matrix and saves you the discovery during an incident, which is the worst possible moment to find out what your vendor does not do. The same honesty applies inside the engagement. Where the evidence cannot support a conclusion, the report says so. An incident report that asserts a clean answer on thin evidence reads better and is worth less, and it is the version that fails when a regulator, an insurer or a counterparty asks how the conclusion was reached.

What you receive

Written for the people who will have to use it

For your team

A technical forensic report

Timeline, entry point, dwell time, lateral movement, what was accessed and what left, with the evidence each conclusion rests on and an explicit note where the evidence does not support one.

For the board

An executive account

What happened, what it means, what has been done and what remains open, in language that survives being forwarded.

The clock

Regulatory notification support

Preparation of the CERT-In submission inside the six-hour window, and support for the sectoral notifications that follow depending on who regulates you.

After

A hardening plan against this path

Specific to the route that was actually used, prioritised by what would have stopped it, so the follow-up work is defensible to whoever approves the budget.

Methodology

What happens between kickoff and the report

Every engagement follows this process through Lemon, our proprietary audit management platform.

Discovery
01

Triage and Rapid Mobilisation

Within the first hour of engagement, our IR lead conducts a triage call to assess the nature, scope, and severity of the incident. We establish secure communication channels, identify key stakeholders, and mobilise the response team. ShadowMap is immediately deployed against the organisation's external footprint to identify exposed assets, leaked credentials, and dark web chatter that may be related to the incident.

02

Immediate Containment

We close likely entry points early based on initial triage findings, even before the full attack path is reconstructed. This includes isolating compromised systems, revoking compromised credentials, blocking malicious IPs and domains, and deploying emergency firewall rules. The goal is to stop active data exfiltration and prevent lateral movement while preserving forensic evidence.

03

Evidence Preservation and Collection

Forensic images of affected systems are captured following chain-of-custody protocols. We collect and centralise logs from endpoints, servers, network devices, cloud services, email platforms, and security tools. Evidence handling follows standards acceptable for regulatory submissions and, where necessary, legal proceedings.

Testing
04

Deep Forensic Investigation

Our DFIR team performs timeline reconstruction, malware analysis, log correlation, and attack path mapping. We determine the initial compromise vector, map all attacker activity across the environment, identify all affected systems and data, and establish the complete scope of the breach. ShadowMap intelligence enriches the investigation with external context including dark web exposure, credential leaks, and related threat actor activity.

05

Regulatory Notification and Compliance

Security Brigade takes full ownership of CERT-In 6-hour incident notification requirements. We prepare and submit notifications with accurate technical detail, and concurrently handle RBI and SEBI notifications for regulated entities. Our team has deep experience with Indian regulatory reporting formats and timelines, ensuring your organisation meets all statutory obligations without diverting your internal team from recovery efforts.

Delivery
06

Eradication and Recovery

Once the attack path is fully mapped, we systematically remove all attacker footholds including backdoors, persistence mechanisms, compromised accounts, and malicious code. For ransomware incidents, this includes decryption assessment, negotiation support where appropriate, and backup-based recovery planning. Systems are hardened before being brought back online.

07

Post-Incident Assessment

After containment and recovery, we deliver a comprehensive post-incident assessment — what we call the B-52 assessment. This includes a complete attack narrative, root cause analysis, gap analysis of security controls that failed, specific hardening recommendations, and a prioritised remediation roadmap. The assessment is delivered in both executive and technical formats to serve leadership, IT, and compliance teams.

"I've bought penetration tests from five firms over the last decade. The difference with Security Brigade is that quality isn't dependent on who walks through the door. Their platform enforces the methodology, their senior reviewers catch what juniors miss, and the final report is something you can hand to an enterprise customer's security team without embarrassment. That's rare."
CTO, Enterprise SaaS Company
Chief Technology Officer

Read more client stories →

Industries We Serve During Incidents

Deep sectoral expertise means faster triage, more relevant containment, and accurate regulatory guidance

Incident response is not one-size-fits-all. A ransomware attack on a bank requires different containment priorities, regulatory notifications, and recovery strategies than the same attack on a manufacturing company. Security Brigade's experience across regulated industries means our IR team understands your compliance obligations, system architecture patterns, and business continuity priorities from the first triage call.

Banking and Financial Services

Banks, NBFCs, payment aggregators, and fintech companies with RBI compliance obligations.

Capital Markets and Insurance

Stock brokers, mutual funds, insurance companies with SEBI and IRDAI reporting requirements.

Technology and SaaS

Cloud-native companies, SaaS platforms, and high-growth startups with customer data exposure risk.

Manufacturing and Conglomerates

Large enterprise groups with complex multi-entity IT environments and OT-adjacent systems.

Healthcare and Pharmaceuticals

Hospitals, healthtech platforms, and pharma companies with patient data and HIPAA/DPDP obligations.

E-commerce and Consumer Platforms

High-traffic consumer platforms where breach impact includes massive customer data exposure and brand damage.

FAQ

Incident response, answered

What happens first, and what we do and do not cover. If you have an active incident, call.

Contact us
We think we have an active incident. What should we do first?+
Call, and before you do anything else, do not rebuild, reimage or power down the affected systems. Each of those destroys the evidence that answers how far the intrusion reached and what left. We maintain 24/7 capacity for active incidents and will triage with whoever you have available, then sequence containment so that it stops the spread without erasing the answers.
How fast do we have to report it?+
CERT-In directions require cyber incidents to be reported within six hours of being noticed, and that clock runs while you are still working out what happened. We prepare the notification in parallel with containment for exactly that reason. Depending on who regulates you there are further notifications after it, and if personal data is involved the DPDP breach duty applies as a separate obligation with its own path.
Do you do digital forensics?+
Yes. Forensic analysis is the core of the investigation: entry point, dwell time, lateral movement, what was accessed and what was taken. L1 forensic analysts work the evidence, an L2 senior DFIR consultant reviews the reconstruction, and an L3 architect validates the conclusions, because an incident report may be read by a regulator, an insurer or a court and a conclusion one analyst reached alone is one nobody has tested.
What do you not do?+
We do not run your security monitoring and we do not operate your disaster recovery. Those are standing operational functions that belong with a provider holding them continuously. We would sooner tell you that now than have you discover it during an incident.
What makes the biggest difference before an incident happens?+
A named person with the authority to declare an incident out of hours, without needing a meeting. Most of the delay we see in the first six hours is not technical: it is nobody being certain they are allowed to start. After that, log retention long enough to cover a dwell time you do not yet know, and a decision path for isolating a production system at 3am.

Stay protected between assessments with ShadowMap

Continuous attack surface monitoring: it discovers new assets, detects credential leaks, and alerts on new exposures the day they appear.

Learn about ShadowMap →

Already Recovered? Prevent the Next Incident.

The best incident response engagement is the one you never need again

24/7 incident response · Call +91 22 4164 2220

Request a Scoping Call