CRA full compliance required 453 days left What it means for you
THZ Networks Under attack? SOS — incident response, any hour of any day

INCIDENT RESPONSE · 24/7

Call us. We answer at any hour.

+386 51 249 533

You do not need to be a customer, and you do not need to know what has happened yet. Tell us what you are seeing and we will tell you what to do in the next ten minutes.

While you wait for us

Most of what an incident ends up costing is added in the first hour, by people trying to help. This is the short version of what helps and what does not.

Do

  • Disconnect affected machines from the network — pull the cable or drop the Wi-Fi.
  • Leave them switched on. Memory holds evidence that a shutdown destroys.
  • Write down times: when it was noticed, by whom, and what was done since.
  • Preserve logs — firewall, VPN, mail, domain controller — before anything rotates them.
  • Check whether your backups are reachable from the compromised network. If they are, isolate them now.
  • Tell your management. Under ZInfV-1 the 24-hour clock starts when you notice, not when you finish investigating.

Do not

  • Do not reboot or shut down. It destroys volatile evidence and can trigger encryption.
  • Do not wipe and reinstall before an image is taken. You cannot un-delete the answer.
  • Do not pay a ransom before taking advice. Payment is sometimes a sanctions offence and rarely the fastest route back.
  • Do not email about it from the compromised mail system. Assume the attacker is reading it.
  • Do not announce it publicly before you know the scope. A correction later is worse than a delay now.
  • Do not let a well-meaning engineer "have a look" on the live system. Every login overwrites something.

Or send the details

If it is not active right now — a suspicious email, something you found in the logs, a supplier who has told you they were breached — this reaches the on-call team directly.