In the event of a security incident, rapid and expert action is required: whether it is a DDoS attack or an infection by a encryption trojan (ransomware), we support you with incident management and digital forensics.
The best protection against emergencies resulting from the ever-increasing attacks on IT systems is sound prevention. Let us examine your IT systems to derive important protective measures.
Together with you, we develop solid emergency management according to recognized BSI standards and ensure protection against malware, defacements, or DoS attacks.
| 1 | After an initial assessment of the situation, it is decided how far the investigation should go in this incident and immediate measures for damage limitation are taken. For example, in the case of an infection with an encryption trojan, it must be decided whether a ransom is paid. |
| 2 | Digital traces are collected for evidence preservation and system copies are created for forensic analysis. Digital forensics then provides important insights into the incident. |
| 3 | A possibly gradual restoration of the system should enable a rapid availability of the systems. |
| 4 | Through lessons learned, measures are derived to prevent a renewed attack. If necessary, certain bodies must be informed about the incident in accordance with the IT Security Act or data protection regulations. |
After detection of the incident, the situation must be assessed quickly and expertly. Various questions must be answered, for example, which systems were compromised, whether data was stolen or manipulated and whether this is personal or security-critical data. If the perpetrators of the incident are to be identified, all actions must consider evidence preservation. Finally, immediate measures for damage limitation are taken. See here the example of a crisis plan in the event of a ransomware infection.
Depending on the situation, various forensic analyses are created from the secured evidence data, such as a live or post-mortem analysis, evaluations of log data or also honeypots and honeydata. The goal of the investigation is a legally admissible documentation and the reconstruction of the incident, in order to subsequently take measures to exclude a renewed incident.
The most important goal of incident response is the restoration of systems to avert further economic damage. Since both evidence preservation and restoration processes may take longer, services may have to be reactivated gradually, also via workarounds. The disaster recovery measures are part of the Business Continuity Management.
Through forensic investigations, the cause can be identified in most cases and the course of the incident reconstructed. This is used to define measures so that a renewed incident can be excluded. In addition, a security audit should take place to design systems and processes securely as a whole.
Do you need help after an IT security incident? We provide expert assistance and ensure the rapid restoration of your systems.
The consultants from aramido convinced me with their extensive expertise and concrete recommendations for measures.
— Dr. Herzig, CEO SearchHaus GmbH