Remote or on-site
Incident Response
When it happens. Incident Response is a methodical process for managing security incidents: from detection and containment through to recovery and analysis. We help you bring the incident under control, limit the damage and regain control of your environment.
Urgent incident? +49 162 867 57 72help@mint-secure.deIncident
Response
Application
Phases
5
Objective
Regain control
In Focus
Reporting deadlines & preservation of evidence
What you should do now
If you’ve landed on this page whilst an incident is underway: these steps will help before one of us arrives. They cost nothing and prevent the mistakes that hurt the most later on.
- Disconnect affected systems from the network, but do not switch them off. Unplug network cables or disable Wi-Fi. Shutting down the system erases traces in the RAM that are crucial for analysis. Exception: If an encryption process is visibly in progress, stopping it takes priority.
- Do not clean up anything or reinstall anything. The instinct to quickly wipe the system is understandable, but it destroys precisely the information that shows how the attackers gained access and whether they are still inside.
- Back up logs. Log rotation and short retention periods often delete evidence before the analysis even begins. Extend the retention period and store copies off-site.
- Check backups and isolate them. Determine which data sets are intact and take them offline before they can be accessed.
- Communicate via a secure channel. If the email system may be compromised, do not coordinate via it. A telephone or a separate messaging app are safer.
- Record times and observations. Who saw what and when; who changed what and when. These notes will be valuable later for analysis, insurance claims and reporting.
- Reset credentials in a coordinated manner. An uncoordinated reset of individual accounts alerts the attacker without locking them out.
- Do not respond to blackmail demands on your own initiative. Every reply provides information about you. Assess the situation first, then decide.
When you should call us
- Files can no longer be opened, and a ransom demand appears.
- A blackmail email claims there has been data leakage and includes a sample.
- There are administrative accounts that nobody has created.
- There are forwarding or move rules in mailboxes that nobody has set up.
- An internet service provider, a customer, a public authority or a security researcher alerts you to suspicious behaviour on your systems.
- Logins are occurring from countries or at times that do not fit with normal operations.
- An account has been compromised and you do not know what has happened in the meantime.
- Your antivirus software flags something that can no longer be found shortly afterwards.
When in doubt, remember: a phone call that turns out to be a false alarm is far cheaper than three days of uncertainty.
How an operation works
Initial Assessment & Triage
We clarify what has been observed, which systems may be affected, and what steps have already been taken. This defines immediate containment measures and determines whether the incident can be resolved remotely or requires on-site deployment.
Containment
Immediate actions to stop lateral movement and cut off attacker access. The priority is to regain operational control without destroying the digital forensics and evidence required for in-depth analysis.
Detection & Forensic Analysis
In-depth investigation of logs, systems, and artifacts: How did the attacker gain entry, dwell time, what data was accessed, and is active persistence still present? Only these answers enable a truly reliable cleanup.
Eradication & Recovery
Removal of malware, sealing the exploited entry vectors, controlled restoration from verified clean backups, and applying essential patches. Order is crucial: restoring before closing the root compromise leads straight to reinfection.
Post-Incident Review
Incident documentation, root-cause evaluation, and a targeted remediation plan to ensure the same attack vector cannot be reused. We can also assist with implementing the recommendations upon request.
Deadlines that are ticking away
Whilst the technical work is underway, the clock is ticking for any necessary reports. We provide the technical findings you need for this and keep a close eye on the deadlines.
- Data protection: If personal data is affected and there is a risk to the data subjects, a report to the supervisory authority is generally required within 72 hours of becoming aware of the incident.
- NIS2: For affected organisations, a multi-stage procedure applies, comprising an early warning, a more detailed report and a final report.
- Contractual obligations: Customer and service provider contracts often contain their own, sometimes shorter, information obligations.
This classification is technical, not legal. Whether and in what form you are required to report will be assessed by your data protection officer and your legal advisers. We provide the basis: what happened, when, to what extent and which data subjects are affected. It is often unclear at the outset whether data has actually been compromised. This is precisely what we work on first, as the report depends on it.
“Every second counts in Incident Response: those who are prepared safeguard assets, trust and control.”
What you’ll take away from this
Prepared for an emergency
Most of the time spent dealing with an incident is not taken up with technical issues, but with organisational matters: who decides, who is authorised to shut down systems, who informs management, and where are the credentials for the backup? These questions should be answered in advance.
- Incident Response Plan – roles, decision-making processes, escalation levels and contact details, documented and also available offline.
- Training – to ensure that anomalies are reported early on, rather than only once the encryption is underway.
- Table-top exercise – a discussed scenario highlights gaps in the plan more quickly than any document.
- Testing under realistic conditions – Ransomware emulation checks how your detection and response to a real encryption attack perform, without causing any damage.
Incident Response
Get in touch with us. No obligation and available at any time.
- Remote or on-site, at short notice
- Containment without destroying evidence
- Preservation of evidence for reporting and insurance purposes
- Keeping an eye on reporting deadlines (GDPR/NIS2)
Frequently Asked Questions
What customers want to know beforehand.
How quickly can you get started?
Give us a call and we’ll let you know straight away what the situation is. For predictable peace of mind, an on-call agreement can be arranged in advance.
Do you work with our IT service provider?
Yes, that’s usually the case. Your service provider knows the environment; we bring the incident response perspective to the table. We do not take over your operations.
Should we pay?
That decision is up to you, in consultation with legal advisers and, where applicable, your insurance provider. From a technical perspective, we can assess how feasible a recovery is without payment. A payment guarantees neither decryption nor the deletion of data that has already been leaked.
Should the police be involved?
It is possible to report the incident to the police, and in many cases this is advisable, particularly when dealing with insurance companies. The decision is yours; we will secure the evidence so that it remains admissible.
How much does a call-out cost?
This depends on the scope and duration of the work and can only be reliably estimated once we have assessed the situation. Following the initial consultation, you will receive a cost estimate.
Can you still help after the event?
Yes. Even if the incident took place some time ago and has already been resolved, it is often still possible to determine whether the point of entry has been sealed off and whether any access points remain.

