If an attack is underway, calling is the fastest path to a responder.

817-973-1397

Emergency

Cyber Incident Response

Ransomware, business email compromise, suspected unauthorized access, or data exposure. DarkBox helps contain it, understand it, and recover from it.

First 60 minutes

What to do right now

01Do not power systems off

Disconnect them from the network instead. Powering down destroys volatile evidence that often identifies how the attacker got in.

02Preserve logs now

Cloud sign-in, mailbox audit, endpoint, and firewall logs frequently have short retention windows and are the backbone of the investigation.

03Move off compromised channels

If email or chat may be affected, coordinate by phone or a separate service until the environment is verified.

04Do not change payment instructions

Hold any pending transfer until it is verified out-of-band with a known contact and phone number.

05Notify counsel and your insurer

Cyber policies commonly carry notification requirements and may direct which providers can be engaged.

06Start a timeline

Write down what was observed, when, and every action taken. It is the most valuable artifact you can hand an investigator.

Intake

Report an incident

Do not submit passwords, authentication codes, sensitive personal information, or other security credentials through this form.

Response workflow

How a DarkBox engagement unfolds

Structured, evidence-preserving, and communicated in language leadership can act on.

  1. PHASE 01

    Contact

    Call the response line or submit intake. We confirm scope, systems affected, and immediate risk.

  2. PHASE 02

    Triage

    Rapid assessment of severity, business impact, and whether the activity is ongoing.

  3. PHASE 03

    Contain

    Isolate affected systems, cut attacker access paths, and protect backups and identity infrastructure.

  4. PHASE 04

    Investigate

    Establish entry point, dwell time, lateral movement, and what data was accessed, preserving evidence throughout.

  5. PHASE 05

    Recover

    Guided restoration to a known-good state, with credential resets and hardened configurations.

  6. PHASE 06

    Strengthen

    Findings turn into controls, monitoring, and an incident response plan so the same path closes permanently.

Before an incident

Organizations with an incident response plan, isolated backups, and a known contact path recover measurably faster. DarkBox builds that readiness in advance so the first call is not the first conversation.

Scope of response

Response scope depends on severity, systems involved, and available evidence. DarkBox assists with containment, investigation, evidence preservation, and recovery guidance, and coordinates with counsel and insurers where required.