If you suspect that someone has access to a company account, server or files, the first hours decide how much you will know later. This page gives the order of containment and evidence preservation. We do not run a continuous monitoring centre: the first-contact target applies on business days.
When a breach is suspected the order is containment, evidence preservation, credential rotation — not cleanup.
What not to do: do not delete logs and messages to “clean” the system, do not reformat the disk before evidence is copied, and do not reply to an extortion message on your own.
With ransomware, the priority is keeping the backups intact and stopping encryption from spreading to shared storage.
Restoring onto a machine that has not been cleaned restores the problem too. Before data goes back, you need to know how the access was obtained.
When a leak is suspected, the first question is which data became accessible and over what period — not how many files exist in total.
Record which accounts and which storage were reachable and what categories of data they hold, especially personal data of customers or staff. Involve your legal counsel and data protection officer early: their decisions carry deadlines.
Do not announce a scope before confirming it. A public statement corrected twice costs more than an accurate one issued slightly later.
Evidence is preserved by copying, not by using: copies of logs, mailboxes and affected disks are stored separately before any remediation begins.
Keep an incident log with times, actions and who performed them. Note how long logs are retained on each system — in many environments the window is days, and what is lost does not come back.
Copies are held on storage outside the compromised environment, with a note of who created them and when.
Articles 33 and 34 of the GDPR set out notification of a personal data breach to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, together with communication to the individuals themselves when the risk to their rights is high.
In Greece the supervisory authority is the Hellenic Data Protection Authority. Whether a specific incident triggers an obligation to notify is decided by your legal counsel or data protection officer, based on the data and the risk.
Our role here is technical: we deliver a timeline, the scope of access and evidence in a form usable in the notification. We do not draft the text sent to the authority and we do not decide whether it is owed.
We take on the technical investigation: containment, analysis of how access was obtained, a record of what was affected, safe restoration, and hardening so the same door does not reopen.
We do not recover encrypted files without a valid backup or a publicly available decryption tool, we do not negotiate with attackers, we do not draft legal documents, and we do not certify that no data left when the logs do not support that.
Response time: first contact is targeted on business days — with no 24/7 cover outside a contract. If you need continuous availability, that is agreed in writing before an incident, not during one.
First contact is targeted on business days. We do not run a continuous monitoring centre, so out-of-hours cover exists only where it was agreed in writing before the incident.
The decision is not technical and is not ours to make. It sits with management and your legal counsel, based on whether a valid backup exists, what data is involved and which restrictions apply. Payment guarantees neither restoration nor deletion of copied data.
Involve your legal counsel early, because notification deadlines run from the moment the breach becomes known. Reporting to law enforcement and notifying the supervisory authority are their decisions, not ours.
One contact point who can approve actions, a description of what was observed and when, a list of affected systems, and access to logs and backups. We do not touch systems without written authorisation.
After containment, the cause is closed with assessment and hardening: vulnerability assessment and hardening after an incident.
If the incident involves a public site or online shop: step-by-step recovery of a compromised website.
Last updated: 2026-09-05