Skip to main content
CERT-In Empanelled — Since 2008 — among India's earliest empanelled auditors

Under Ransomware Attack? We Handle Everything.

One call activates a full-spectrum ransomware response team: containment, CERT-In 6-hour notification, decryption assessment, data recovery, and post-incident hardening. 24/7 availability. One team from crisis to closure.

6,700+
Assessments
1,000+
Clients
150+
Team
2006
Founded

Trusted by India's leading enterprises

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

The first decision

Four positions, and the one you are in decides everything

Ransomware engagements diverge almost immediately depending on what is still intact. This is the assessment we make in the first hours.

Four positions, and the one you are in decides everything
StateWhat it meansWhat follows
Backups intact and verified offline Recent backups exist, are known-good, and were not reachable from the compromised network. The strongest position available. The engagement becomes containment, investigation and a clean rebuild, and the pressure to consider payment largely lifts.
Backups exist but were reachable Backups are present and were accessible from the environment the attacker controlled, so their integrity is unknown until tested. The commonest position and the one that decides most of the first day. Validating backup integrity becomes the priority task, because everything downstream depends on the answer.
Encryption still spreading The attack is live and systems are continuing to fall. Containment overrides everything, sequenced to preserve the evidence that the investigation will need. Isolation done carelessly costs the answer to what was taken.
Data exfiltration claimed The attacker asserts data was taken before encryption, with or without proof. Changes the problem from availability to disclosure, and brings regulatory notification and customer communication forward. Verifying the claim against your own evidence is urgent, because the attacker’s account is not evidence.
Key
  • Rebuild is the path
  • Decides the first day
  • Widens the incident

How it runs

Parallel, because the clocks do not wait for each other

01 Immediate

Contain

What happens
Stop the spread and preserve state at the same time: isolation, imaging before changes, log capture before rotation, and credential revocation sequenced against an intruder who may still be watching.
02 First hours

Assess

Variant and decryption
Identify the specific variant and its known behaviours, and assess decryption viability including whether a public decryptor or a known implementation flaw applies. This is an assessment and never a promise.
Backups
Validate what is actually restorable, which is a different question from what the backup console reports.
03 Within six hours

Notify

What happens
Prepare the CERT-In notification inside the six-hour window and the sectoral notifications that follow. Where personal data is implicated the DPDP breach duty applies with its own path to the Board and to affected individuals.
04 Days

Recover and harden

What happens
Restoration sequenced so that recovered systems are not returned to a network the attacker still holds, verification that persistence is gone, and hardening against the specific route that was used.

What we provide

One team from the first call to closure

Availability

24/7 emergency capacity

Round-the-clock availability for active ransomware incidents, with leadership reachable. The first triage call does not wait for office hours.

The answers

Forensic investigation

Entry point, dwell time, lateral movement and what left, reviewed through L1, L2 and L3 before anything is asserted. The exfiltration question is answered from your evidence, not from the attacker’s claim.

Assessed, not promised

Decryption assessment

Variant identification, known behaviours, and whether a public decryptor or a known flaw in the implementation offers a path. Where it does not, we say so immediately instead of spending your week on it.

Where you ask for it

Negotiation assistance

Advice and support where you choose to engage, including on what the counterparty’s claims can and cannot be verified against. The decision is yours and is a legal and commercial one; we make sure it is taken with accurate information.

The clock

Regulatory notification

The CERT-In submission inside six hours, and the sectoral and data-protection notifications that follow.

Closure

Recovery and hardening

Restoration sequencing, verification that persistence is eradicated, and a hardening plan against the route that was actually used.

What we will not tell you

Nobody can promise your data back

Any firm guaranteeing recovery before it has seen your environment is selling you something it cannot control. Decryption viability depends on the variant, on whether a flaw exists in that particular implementation, and on whether anyone has published a decryptor; none of those is within a vendor’s gift. Restoration depends on backups whose integrity is unknown until tested. What can be committed to is the process: that we will be available when it happens, that containment will not be done in a way that destroys the investigation, that the decryption assessment will be given to you straight and quickly including when the answer is that there is no path, that the regulatory clock will be handled in parallel instead of after, and that recovery will be sequenced so restored systems are not returned into a network the attacker still holds. The single most useful thing you can do before any of this is to hold a backup that the production network cannot reach, and to have restored from it once to prove it works. Organisations with that are in the first position on this page. Organisations that assume it are usually in the second.

Methodology

What happens between kickoff and the report

Every engagement follows this process through Lemon, our proprietary audit management platform.

Discovery
01

Emergency Triage and Containment (Hours 0-6)

Senior incident responder conducts initial assessment via phone. Containment guidance issued immediately to stop encryption spread. Systems isolated at network level. Ransomware strain identified. CERT-In 6-hour notification drafted and filed on your behalf. Emergency communication plan established with your leadership team.

02

Investigation and Assessment (Hours 6-48)

Forensic team deploys on-site or remotely. Attack vector identified through log analysis, endpoint forensics, and network traffic review. Compromised accounts and systems catalogued. Data exfiltration scope assessed. Decryption viability evaluated — free decryptors, backup integrity, and recovery options mapped. ShadowMap dark web scan initiated for leaked credentials and data.

Testing
03

Recovery and Restoration (Days 2-7)

Data recovery executed via the most viable path: backup restoration, decryption tools, or forensic recovery methods. Systems rebuilt and hardened before reconnection. Critical business operations prioritised for restoration. Threat actor artefacts and persistence mechanisms removed. Environment validated clean before bringing systems back online.

Delivery
04

Post-Incident Hardening and Monitoring (Weeks 2-4)

B-52 security assessment validates the recovered environment against the attack vectors exploited. Vulnerability remediation and configuration hardening implemented. ShadowMap deployed for continuous dark web monitoring of your organisation's data. Comprehensive forensic report delivered to leadership with root cause analysis, timeline, and strategic recommendations. Board-ready executive summary provided.

"We needed an assessment on a 3-week timeline because of a partner integration deadline. Security Brigade turned it around in 18 days, including the L2 and L3 reviews. The report was regulator-ready — we submitted it to our partner's compliance team unchanged. When speed and credibility both matter, they're the only call we make."
VP Engineering, Retail & Quick Commerce
Vice President — Engineering

Read more client stories →

Industry-Specific Ransomware Response Experience

Every industry has unique regulatory, operational, and data sensitivity requirements during a ransomware incident.

Ransomware does not discriminate by industry, but the response must be tailored to your specific regulatory obligations, operational dependencies, and data sensitivity profile. Security Brigade has handled incidents and security assessments across all major sectors, giving our team the contextual understanding needed to prioritise recovery actions correctly.

Banking and Financial Services

RBI cyber incident reporting, transaction system recovery prioritisation, customer data protection, and regulatory coordination with RBI and CERT-In.

Insurance

IRDAI compliance, policyholder data protection, claims processing system recovery, and actuarial data integrity validation.

Fintech and Payments

Payment aggregator compliance, UPI and gateway restoration, NPCI coordination requirements, and PCI DSS breach notification protocols.

Manufacturing and OT

Production line restoration, OT and SCADA system isolation, supply chain communication, and operational technology recovery.

Healthcare and Pharma

Patient data protection, EMR and EHR system recovery, HIPAA and DPDP compliance, and medical device network isolation.

Technology and SaaS

Customer data breach notification, cloud infrastructure recovery, CI/CD pipeline security validation, and SOC 2 breach reporting.

FAQ

Ransomware response, answered

What happens first, and what can honestly be promised. If encryption is active, call.

Contact us
Encryption is spreading right now. What do we do?+
Call, and do not rebuild or reimage anything yet. Isolate what you can at the network level and leave affected systems powered on where possible, because memory holds evidence that is lost on shutdown. We maintain 24/7 capacity for active incidents, and the first thing we will do is sequence containment so it stops the spread without erasing the answers to how it started and what was taken.
Can you decrypt our files?+
Sometimes, and nobody can tell you before looking. We identify the variant and assess whether a public decryptor or a known flaw in that implementation offers a path. Where one exists we use it; where it does not, we tell you immediately instead of spending your week on it. Any firm guaranteeing recovery before seeing your environment is promising something outside its control.
Do you help with negotiation?+
Yes, where you choose to engage. We advise and assist, including on what the counterparty’s claims about stolen data can and cannot be verified against your own evidence. Whether to engage at all is a legal and commercial decision that is yours to make, and our role is to make sure it is taken with accurate information instead of under the attacker’s framing.
They say they have our data. Is that true?+
It may be, and the attacker’s claim is not evidence. Exfiltration is established from your own telemetry: egress volumes, access patterns, staging artefacts and the timeline. That answer matters well beyond the negotiation, because it changes the incident from an availability problem into a disclosure one and brings regulatory notification and customer communication forward.
How fast must we notify a regulator?+
CERT-In directions require cyber incidents to be reported within six hours of being noticed. We prepare that submission in parallel with containment. Sectoral notifications follow depending on who regulates you, and where personal data is implicated the DPDP breach duty applies as a separate obligation to the Data Protection Board and to affected individuals.
What would have helped most beforehand?+
A backup the production network cannot reach, that you have restored from at least once to prove it works. That single item is the difference between the strongest and the commonest positions we walk into. After it, log retention long enough to answer what was accessed, and a named person who can authorise isolation out of hours.

Stay protected between assessments with ShadowMap

Continuous attack surface monitoring: it discovers new assets, detects credential leaks, and alerts on new exposures the day they appear.

Learn about ShadowMap →

Ransomware Attack in Progress? Call Us Now.

Do not wait for the situation to get worse. One call activates a team that has helped India's largest enterprises recover from ransomware attacks.

24/7 incident response · Call +91 22 4164 2220

Request a Scoping Call