Restoring systems does not close an incident. Without establishing the entry vector, how long they were inside and what they took before encrypting, the organisation returns to production with the door open and no idea whether it has a data breach to report. Reinfection within weeks is a known pattern.
Your obligations run on a clock
NIS2: early warning within 24 hours, notification within 72 hours and a final report within one month.
DORA: initial notification of major incidents on very short deadlines from detection.
GDPR: 72 hours to notify the supervisory authority if personal data was accessed.
Answering those questions with any foundation requires forensic analysis, not an estimate.
What we do
Evidence preservation. First, before it is lost: forensic images, memory dumps and logs, with chain of custody from minute one.
Incident reconstruction. Entry vector, lateral movement, privilege escalation, persistence and a full timeline from first access.
Exfiltration determination. Which data left and which did not. That is the difference between reporting a breach and being able to evidence there was none.
Actor and technique identification, mapped to MITRE ATT&CK, so you know what will be tried again.
Verified eradication. Confirming no persistence remains before reconnecting. It is the step almost nobody takes and the one that prevents reinfection.
Reporting for third parties: management, insurer, supervisory authority and clients demanding answers.
How we work
1
Containment and preservation
Isolate without destroying. Powering off or rebuilding a machine erases exactly what is needed to establish what happened.
2
Forensic analysis
Disks, memory and logs. Timeline reconstruction with timestamps cross-checked across sources.
3
Breach scope
Which systems, which data and which individuals affected, with the level of certainty documented.
4
Eradication
Locating all persistence and verifying its removal before returning to production.
5
Report and notifications
A technical document and an authority-facing document, written for the deadline that applies to you.
6
Hardening
What to change so the same chain does not work again, prioritised.
What you get
Forensic report with the full timeline and the evidence.
Scope determination of affected data, with its level of certainty.
Report for the supervisory authority, in the required format and deadline.
Eradication verification before the return to production.
Hardening plan prioritised against the real attack chain.
Executive report for management, board and insurer.
Who does the work. The same team that audits, not an account manager. Governance, risk and compliance: CISSP, CISM, ISO 27001 Lead Auditor, ENS and Risk Analysis (CCN), certified DPO, CCSP and CDPP (ISMS Forum) and PMP (PMI). On the technical side: OSCP, CRTO II and eWPTX, ranked in the top 1% of the CCN-CERT Atenea platform. We have run compliance projects for crypto exchanges, universities and public administrations.
Questions we get asked
We are in the middle of the incident. What do I do?
Isolate, do not power off and do not rebuild. Call us on +34 686 250 244. Every extra hour destroys evidence and narrows what can later be evidenced.
We have already restored from backup. Is it still worth it?
Yes. Logs, telemetry, perimeter systems and the backups themselves allow much of what happened to be reconstructed. The scope will be narrower, but you rarely start from nothing.
Should we pay the ransom?
We do not advise on paying. We give you the technical facts so the decision is made with information: what was encrypted, what can be recovered without the key and what data left, which is usually the real extortion lever.
Do you work with our insurer?
Yes. The report is written with the detail and traceability the insurer will require to process the claim.
If it is happening now, call
+34 686 250 244 · Mon-Fri, 9:00 to 18:00 CET. Do not power off the affected machines and do not rebuild them until we have spoken.
Phone: +34 686 250 244 (Mon-Fri, 9:00 to 18:00 CET) · Email: info@jaymonsecurity.com
We reply within 2 working hours.

