Data Breach: Incident Response & Digital Forensics

Close the data leak and create clarity with digital forensics.

Hacked? We stop the data leak and clarify what is affected.

Acting fast is crucial. We support you around the clock to stop the attack and secure your data.

To help you as quickly as possible, please have the following information ready:

  • Symptoms: What did you observe?
  • Time: When was the incident discovered?
  • Scope: Which systems are affected?
  • Actions: What steps have been taken so far?
Get help now

Fast and professional help!

You have signs of a hacker attack but are not sure whether data has leaked. If so, it remains unclear which data it is, whether personal data or trade secrets. The forensic analysis resolves exactly this uncertainty.

aramido first stops the further data leak so that nothing worse happens. The forensic analysis then provides clarity about the scope of the incident. It forms the basis for a correct notification under GDPR and NIS-2 or the decision not to report deliberately.

A stopwatch as a metaphor for immediate intervention

Immediate intervention

You reach us directly with no waiting. The sooner we intervene, the sooner we stop the data leak and secure the traces.

A padlock as a metaphor for discretion

Discrete support

As a discreet partner, we treat all information confidentially. We act professionally and keep the situation under control.

A microscope as a metaphor for forensic excellence

Forensic excellence

We quantify the data leak and secure evidence in a court-proof manner. This creates a reliable basis for authorities and insurers.

Structured handling of the consequences of a data breach

When does a data breach exist?

After an attack, it is often only known that the attacker was in the network. Whether data has leaked is initially unclear. A data breach exists when data has left your company without authorization or has fallen into the wrong hands. For you this means a data loss that usually cannot be reversed. Such an incident often begins with a phishing attack or a ransomware infection. The distinction between infiltration and exfiltration is decisive: an attacker can be in the network without having taken data. aramido clarifies this through a forensic analysis.

  • 1
    Rapid analysis of the affected scope and prioritization of the systems to identify the most critical areas immediately.
  • 2
    Immediate isolation of affected systems and blocking of attacker communication to stop further data leakage.
  • 3
    In-depth analysis of memory, storage media and network protocols. We reconstruct the attack path and create a list of the affected data.
  • 4
    Removal of backdoors, hidden accounts and malware. We permanently close the original security vulnerability.
  • 5
    Step-by-step restoration of your critical business processes to ensure a safe and stable return to normal operations.
  • 6
    Final review of the incident and derivation of strategic measures to make your infrastructure resilient against future attacks.

Data breach? Request immediate help now!

Tell us briefly what happened. Name the affected systems, the point in time and what you have already done. We help you stop the further data leak and prepare the notification. In urgent cases, reach us directly on the emergency hotline: +49 721 451 99 112.

Status

Please enable JavaScript to use the form.

The 72-hour deadline and the risk of over-reporting

The 72-hour deadline under Art. 33 GDPR is familiar to many companies. In addition, further reporting systems apply, such as NIS-2, DORA or sector-specific requirements. What they all have in common: the notification must be based on verifiable facts. aramido provides this basis. The forensic analysis clarifies whether and which data has leaked and whether personal data or trade secrets are affected.

On this basis, your legal department or data protection officer decides to report precisely or deliberately not to report. This way you avoid an overly broad notification that draws unnecessary attention from the authorities. As a forensics and incident response partner, we provide the reliable facts that your management needs for the right decision.

Frequently asked questions about data breaches and GDPR reporting

Our aramido Response Team (aRT) is available 365 days a year, during core hours from 8 AM to 6 PM via hotline and email. Existing customers with a framework agreement receive first assistance within a maximum of 4 hours during core hours. Containment usually takes one to three days; the final report follows as a rule one to two weeks after the incident.
A reporting obligation under Art. 33 GDPR arises as soon as you become aware of a breach of the protection of personal data that is likely to result in a risk to the rights and freedoms of the affected individuals. The notification to the supervisory authority must be made without undue delay, at the latest within 72 hours. aramido provides the technical facts that your legal department needs for the notification.
Yes. The 72-hour deadline of the GDPR concerns personal data and is addressed to the data protection supervisory authority. In addition, other reporting systems may apply, which can also be triggered without a data leak. Those affected by NIS-2 report significant security incidents to the BSI, with an early warning within 24 hours and an incident notification within 72 hours. Banks report significant ICT incidents under DORA to the BaFin, with an initial notification within 4 hours. Depending on the sector, further reporting systems apply, such as the German BSI Act or the TKG. aramido checks in parallel which systems apply to you and provides the forensic facts so that your notification meets the respective deadlines.
Infiltration means that an attacker has access to your network. Exfiltration means that they have removed data from your network. For the GDPR reporting obligation, only exfiltration is decisive. Not every intruder has taken data. aramido clarifies through log and network analysis whether and which data have actually left the company.
The reporting obligation under Art. 33 GDPR concerns personal data. If only trade secrets are affected, there is no GDPR reporting obligation, although other obligations such as under NIS-2 may apply. Whether personal data is affected is clarified by the forensic analysis. It thus prevents an unnecessary notification and protects your reputation.
Yes. We collect the data according to recognized industry standards such as ISO/IEC 27037 and maintain an unbroken chain of custody. Our reports are forensically reliable and withstand scrutiny by lawyers, regulatory authorities or insurers.
During a thorough eradication phase, we remove backdoors that attackers may have left behind, for example hidden user accounts or automated system tasks. At the same time, we permanently close the original security vulnerability. To protect your systems in the long term, we set up monitoring that would immediately inform us of renewed access attempts.
You briefly describe the situation, which systems are affected and since when you suspect the data leak. We help you stop the spread, secure first traces and jointly develop the next steps. We take over the coordination with authorities and insurers for you.

This is how we determine the scope of the data breach

After an attack, your company wants to know quickly what the incident means. aramido gains this clarity from the traces in your systems and in the data traffic. Exfiltration tools, unusual accesses and prepared archives indicate a leak. The evaluation of access and mail logs also reveals mass downloads and secretly configured forwarding.

In addition, we compare published content with darknet and leak sites to prove whether your data appears outside. An extortion message is also a clear sign of a leak. We secure the results according to standards such as ISO/IEC 27037 and maintain the chain of custody unbroken. This establishes whether and how you must report under GDPR or deliberately not report.