Skip to content

Active incident? Don't wait on a form. Call. The line is staffed 24/7.

cyber emergency - 24/7

If you are mid-incident, the form below is the slow path.

The hotline above is answered by a person, around the clock, and does not require an existing contract with DigitalEra. Use the form only if you genuinely cannot call right now.

Request emergency response

Routes directly to the on-call IR coordinator, day or night. Same assessment, same process as the hotline, just a slower start since it begins with a form instead of a live call.

while you wait for us

The first 10 minutes matter more than the next 10 hours.

Most of the damage we can't undo is damage done by well-meaning people in the first hour. If you do nothing else, do these.

DO THIS NOW

In roughly this order.

  1. Isolate. Don't power off. Disconnect affected machines from the network: pull the cable, disable Wi-Fi, or move them to an isolated VLAN. Shutting down destroys memory evidence that often shows how the attacker got in.
  2. Move the conversation off your network. Assume email and chat may be readable by the attacker. Coordinate on personal phones or a separate service until told otherwise.
  3. Call your cyber insurance carrier. Most policies require early notification, and some restrict which response firms are covered. Calling late can cost you the claim.
  4. Engage legal counsel. They will direct how the investigation is structured and reported.
  5. Preserve the logs. Firewall, VPN, EDR, email and cloud audit logs. Many roll over within days. Stop the rotation before evidence ages out.
  6. Write down the timeline. Who noticed what, and when. Memory degrades fast under pressure and this becomes the backbone of the investigation.

DON'T DO THIS

Each of this has cost organizations we've worked with

  1. Don't wipe or reimage affected systems. It destroys the evidence needed to scope the breach, and you may reinstall straight back into a compromised environment.
  2. Don't restore from backup before scoping. If the attacker is still resident, or the backup is infected, you restore the incident along with the data.
  3. Don't negotiate or pay before counsel, your insurer and law enforcement are involved. There can be sanctions exposure, and payment guarantees neither a working key nor deleted data.
  4. Don't announce anything publicly until scope is known. Early statements that turn out to be wrong create regulatory and legal problems that outlast the incident.
General guidance, not legal advice. If your insurer or counsel instructs you differently, follow them. This checklist exists so you are not guessing in the first 10 minutes.