Solutions / The situation
If you are in an incident, call now. Read afterwards.
Systems are behaving strangely, a ransom note appeared, an employee clicked something, or a customer told you your data is somewhere it should not be. The first hours decide how bad this gets: what gets contained, what evidence survives, and whether the notification you owe your customers and the regulator is made correctly and on time.
You are in the window where every decision compounds. Wiping the wrong machine destroys the evidence you will need. Paying without analysis funds nothing useful. Staying quiet past a notification deadline turns an incident into a regulatory matter on top of a technical one.
What it is costing you
- Evidence disappears within hours if the wrong containment step is taken first.
- Amendment 13 and GDPR both carry breach notification duties with clocks that started when you became aware, not when you finished investigating.
- Your cyber insurance policy has notification and cooperation conditions; missing them can cost you the claim.
- Customers find out from someone other than you, and the commercial damage outlives the technical one.
What we do
Call the incident line
You reach a responder, not a ticket queue. First guidance on containment and evidence preservation comes on that call, before anyone touches a keyboard.
Contain without destroying evidence
Isolate, preserve, capture. We keep the forensic record intact while stopping the spread. The two goals conflict, and the order matters.
Establish what actually happened
Scope, entry point, dwell time, what data was accessed or taken. Notification obligations and customer conversations both depend on facts, and speculation in either direction is dangerous.
Handle the notifications and the disclosure
Regulatory notification, customer communication, insurer notification, on the clocks that apply, with regulatory advisory alongside the technical work.
Recover, and close the door behind you
Restore, verify, remove the access path, and produce the incident report: the document your customers, your insurer and your board are going to ask for.
What should we do in the first hour of a suspected breach?
Do not wipe, rebuild or reimage anything: that destroys the evidence you will need for notification, insurance and investigation. Isolate affected systems from the network but leave them powered on where possible, preserve logs before retention windows expire, restrict discussion to a small group, notify your cyber insurer as your policy requires, and get a responder on the phone. Containment and evidence preservation conflict with each other, and the order in which you do them matters.
Do we have to report a data breach in Israel?
Yes, in defined circumstances. Israel's Privacy Protection Law, as amended by Amendment 13, imposes notification obligations on database holders following a severe security incident: to the Privacy Protection Authority and, where required, to affected individuals. If EU personal data is involved, GDPR's 72-hour notification clock also applies, and it starts when you become aware of the breach, not when you finish investigating it. Determining scope and determining obligations must therefore run in parallel.
Should we pay a ransomware demand?
Not as a first move, and not without analysis. Payment does not guarantee decryption, does not prevent publication of stolen data, does not remove the attacker's access, and may carry sanctions and legal exposure depending on the group involved. The decision must follow, never precede, an assessment of what backups are viable, what data was actually taken, what your insurance policy says, and what regulatory duties are already running.