Saltar al contenido principal

Incident Response that contains the breach, preserves the evidence, and closes the gap the attacker walked through.

Breach containment, disk and memory forensics, CERT-In and GDPR notification support, and post-incident hardening. Retainer and on-call options.

Our incident response retainer clients cut dwell time, not just alert noise metrics

Two recent incident response engagements, from first alert to lessons learned. Breach details stay under MNDA; a full walkthrough on your scoping call.

Cybersecurity and Compliance engagement

Cybersecurity and Compliance engagement,
Incident response and digital forensics lead

Dcrayon handled our breach like a drill they had rehearsed. They isolated the affected hosts, preserved forensic images with chain of custody, and gave us a containment timeline the board could follow.

MNDA

Mean time to contain, shared on scoping call

90 days

Dwell time from intrusion to containment

Incident Response engagement: NIST 800-61 playbook, EDR host isolation, forensic imaging with documented chain of custody, and a post-incident review that closed the entry points attackers used.

Read Cybersecurity and Compliance engagement's Case Study
Mid-market cybersecurity and compliance brand

Mid-market cybersecurity and compliance brand,
Incident response and detection lead

Our incident response plan was a PDF nobody had tested. Dcrayon ran a tabletop, rewrote the escalation playbooks, and had our team practiced before the next real alert landed.

MNDA

Breach scope and reinfection rate on scoping call

90 days

Time from alert to analyst triage

Incident Response engagement paired with threat monitoring so alerts reached an on-call analyst. A tabletop exercise in the first week exposed the escalation gaps to fix first.

Read Mid-market cybersecurity and compliance brand's Case Study

HOW DCRAYON HANDLES A LIVE INCIDENT

How Dcrayon runs the SANS six-step response

How Dcrayon runs the SANS six-step response
A short walkthrough of a Dcrayon incident engagement, from the first triage call through containment and eradication to the written lessons-learned report.

Response capabilities we bring to every incident

What comes standard on a Dcrayon incident retainer

Each capability below is run by the named DFIR lead assigned to your account, not handed to a rotating on-call queue.
  • Forensically sound evidence

    Forensically sound evidence

    Every action follows chain of custody: forensic disk images, memory captures, and a timestamped timeline that stands up for an auditor, a court, or a cyber-insurance claim.

  • AI-assisted threat hunting

    AI-assisted threat hunting

    Dcrayon AI correlates SIEM and EDR telemetry to surface indicators of compromise, map lateral movement, and flag persistence a manual sweep can miss.

  • Ransomware and extortion playbooks

    Ransomware and extortion playbooks

    Decision support for ransom demands, negotiation, and crypto-tracing partners, plus backup-recovery validation before payment is ever considered.

  • Regulatory notification support

    Regulatory notification support

    We prepare the CERT-In six-hour report, the GDPR 72-hour breach notice, and the incident documentation your regulators and insurer will ask for.

How a Dcrayon incident retainer works

Three habits that make every response calmer than the last: rehearse, respond, review.

Step 1: Assess

A no-cost readiness review of how you would handle a live breach today. We map your detection coverage, log gaps, and containment steps, then hand you a prioritized fix list scored 0 to 100. No follow-on commitment.

Step 2: Contain

A written response plan built around a metric you pick, like mean time to contain. A senior DFIR lead owns the runbooks and playbooks. Month to month, no annual lock-in, and either side can end it at day 90.

Step 3: Harden

Weekly check-ins with your DFIR lead plus a plain monthly summary your finance team can read. The work builds on itself: tabletop drills sharpen detection, tuned alerts cut false positives, then SOAR playbooks automate first-line containment.

Google Reviews
0
Reviews
Clutch
0
Reviews
Fiverr
0
Reviews

The readiness review is free. The response plan is yours to keep.

Across our 60+ active solutions retainers, the 12-month cost we measure for teams with no incident response plan, counting downtime, breach cleanup, and lost data, lands in the Rs 6L to Rs 90L band. Book the scoping call to size yours.

No-cost response-readiness review scoring your detection and recovery gaps

Written response plan and runbooks tuned to your environment

On-call or full-retainer options, no annual lock-in
A named forensics lead on the account from the first call
The readiness review is free. The response plan is yours to keep.

Incident Response FAQs

Onboarding maps your systems, sets escalation contacts, and arranges log and EDR access, so when an alert fires we act from a known baseline rather than a cold start.

Both. Some clients keep us as their full incident response company; others keep us on retainer as the senior escalation their internal SOC calls the moment a breach hits. We scope per account.

Most retainers start at Rs 4 to 8 lakhs per month in India, or USD 6 to 15 thousand per month globally. Readiness reviews and tabletop-only engagements start lower.

Yes. Every proposal call includes a no-cost response-readiness review with a single score and your top gaps. No follow-on commitment required.