Contain
- What happens
- Stop the spread and preserve state at the same time: isolation, imaging before changes, log capture before rotation, and credential revocation sequenced against an intruder who may still be watching.
One call activates a full-spectrum ransomware response team: containment, CERT-In 6-hour notification, decryption assessment, data recovery, and post-incident hardening. 24/7 availability. One team from crisis to closure.
Trusted by India's leading enterprises
The first decision
Ransomware engagements diverge almost immediately depending on what is still intact. This is the assessment we make in the first hours.
| State | What it means | What follows |
|---|---|---|
| Backups intact and verified offline | Recent backups exist, are known-good, and were not reachable from the compromised network. | The strongest position available. The engagement becomes containment, investigation and a clean rebuild, and the pressure to consider payment largely lifts. |
| Backups exist but were reachable | Backups are present and were accessible from the environment the attacker controlled, so their integrity is unknown until tested. | The commonest position and the one that decides most of the first day. Validating backup integrity becomes the priority task, because everything downstream depends on the answer. |
| Encryption still spreading | The attack is live and systems are continuing to fall. | Containment overrides everything, sequenced to preserve the evidence that the investigation will need. Isolation done carelessly costs the answer to what was taken. |
| Data exfiltration claimed | The attacker asserts data was taken before encryption, with or without proof. | Changes the problem from availability to disclosure, and brings regulatory notification and customer communication forward. Verifying the claim against your own evidence is urgent, because the attacker’s account is not evidence. |
How it runs
What we provide
Round-the-clock availability for active ransomware incidents, with leadership reachable. The first triage call does not wait for office hours.
Entry point, dwell time, lateral movement and what left, reviewed through L1, L2 and L3 before anything is asserted. The exfiltration question is answered from your evidence, not from the attacker’s claim.
Variant identification, known behaviours, and whether a public decryptor or a known flaw in the implementation offers a path. Where it does not, we say so immediately instead of spending your week on it.
Advice and support where you choose to engage, including on what the counterparty’s claims can and cannot be verified against. The decision is yours and is a legal and commercial one; we make sure it is taken with accurate information.
The CERT-In submission inside six hours, and the sectoral and data-protection notifications that follow.
Restoration sequencing, verification that persistence is eradicated, and a hardening plan against the route that was actually used.
What we will not tell you
Any firm guaranteeing recovery before it has seen your environment is selling you something it cannot control. Decryption viability depends on the variant, on whether a flaw exists in that particular implementation, and on whether anyone has published a decryptor; none of those is within a vendor’s gift. Restoration depends on backups whose integrity is unknown until tested. What can be committed to is the process: that we will be available when it happens, that containment will not be done in a way that destroys the investigation, that the decryption assessment will be given to you straight and quickly including when the answer is that there is no path, that the regulatory clock will be handled in parallel instead of after, and that recovery will be sequenced so restored systems are not returned into a network the attacker still holds. The single most useful thing you can do before any of this is to hold a backup that the production network cannot reach, and to have restored from it once to prove it works. Organisations with that are in the first position on this page. Organisations that assume it are usually in the second.
Methodology
Every engagement follows this process through Lemon, our proprietary audit management platform.
Senior incident responder conducts initial assessment via phone. Containment guidance issued immediately to stop encryption spread. Systems isolated at network level. Ransomware strain identified. CERT-In 6-hour notification drafted and filed on your behalf. Emergency communication plan established with your leadership team.
Forensic team deploys on-site or remotely. Attack vector identified through log analysis, endpoint forensics, and network traffic review. Compromised accounts and systems catalogued. Data exfiltration scope assessed. Decryption viability evaluated — free decryptors, backup integrity, and recovery options mapped. ShadowMap dark web scan initiated for leaked credentials and data.
Data recovery executed via the most viable path: backup restoration, decryption tools, or forensic recovery methods. Systems rebuilt and hardened before reconnection. Critical business operations prioritised for restoration. Threat actor artefacts and persistence mechanisms removed. Environment validated clean before bringing systems back online.
B-52 security assessment validates the recovered environment against the attack vectors exploited. Vulnerability remediation and configuration hardening implemented. ShadowMap deployed for continuous dark web monitoring of your organisation's data. Comprehensive forensic report delivered to leadership with root cause analysis, timeline, and strategic recommendations. Board-ready executive summary provided.
"We needed an assessment on a 3-week timeline because of a partner integration deadline. Security Brigade turned it around in 18 days, including the L2 and L3 reviews. The report was regulator-ready — we submitted it to our partner's compliance team unchanged. When speed and credibility both matter, they're the only call we make."
Every industry has unique regulatory, operational, and data sensitivity requirements during a ransomware incident.
Ransomware does not discriminate by industry, but the response must be tailored to your specific regulatory obligations, operational dependencies, and data sensitivity profile. Security Brigade has handled incidents and security assessments across all major sectors, giving our team the contextual understanding needed to prioritise recovery actions correctly.
RBI cyber incident reporting, transaction system recovery prioritisation, customer data protection, and regulatory coordination with RBI and CERT-In.
IRDAI compliance, policyholder data protection, claims processing system recovery, and actuarial data integrity validation.
Payment aggregator compliance, UPI and gateway restoration, NPCI coordination requirements, and PCI DSS breach notification protocols.
Production line restoration, OT and SCADA system isolation, supply chain communication, and operational technology recovery.
Patient data protection, EMR and EHR system recovery, HIPAA and DPDP compliance, and medical device network isolation.
Customer data breach notification, cloud infrastructure recovery, CI/CD pipeline security validation, and SOC 2 breach reporting.
FAQ
What happens first, and what can honestly be promised. If encryption is active, call.
Contact usStay protected between assessments with ShadowMap
Continuous attack surface monitoring: it discovers new assets, detects credential leaks, and alerts on new exposures the day they appear.
Do not wait for the situation to get worse. One call activates a team that has helped India's largest enterprises recover from ransomware attacks.
24/7 incident response · Call +91 22 4164 2220