Skip to main content

Cybersecurity Insights & Guides

Expert insights on cybersecurity, vulnerability management, and digital defence strategies.

Business email compromise — the money left this morning

A payment went to an account that was not your supplier's. The instinct is to chase the money, and that is right — but a BEC is a mailbox intrusion first and a fraud second, and the two run on different clocks. What to do in the first hours, in what order, and why the mailbox investigation cannot wait for the recovery attempt.

02 Sept 2026

How they got in — and why your logs decide whether you can answer

The morning after, the question is how. A short list of entry classes, each confirmed from a different record — and every one of those records is a log with a retention window set by whoever runs the infrastructure. Where that window is shorter than the intrusion, the honest finding is 'root cause undetermined' — and this is how to write one.

02 Sept 2026

Website defacement, or a Google warning on your site: the first hour

A replaced homepage, or a Chrome warning on your site. What to copy before you touch the server, and the CERT-In clause that puts a defaced site on a six-hour clock.

02 Sept 2026

What the ransom decision actually turns on

By the time the question reaches you it is usually framed as pay or don't. It is really five separate findings, and four of them can be established in the first two days: which strain it is, whether a decryptor already exists, whether your backups actually restore, and whether data left the building. The six-hour CERT-In filing is due either way.

02 Sept 2026

Preserve it before you rebuild

Powering the machine off, restoring from backup, re-imaging, and quietly cleaning up: four reasonable instincts, each of which destroys something no technique recovers afterwards. What each one takes with it, and a preservation sequence a system owner can work through with what they already have — before anyone with a forensics kit arrives.

02 Sept 2026

The six-hour report: what actually gets sent, and who else you owe

You noticed at 09:40. CERT-In is due by 15:40. What goes in the six-hour report, who sends it, and which other regulators are owed a filing too.

02 Sept 2026

The first hour, and the first seventy-two

The order to work in from the moment you find out: what to stop doing, what to preserve, who to call, and what CERT-In's Direction (ii) of 28 April 2022 requires within six hours of noticing an incident or being brought to notice about it. Preservation comes before remediation — a rebuilt server is an answer nobody can reconstruct.

02 Sept 2026

Have a question this did not answer?

Our team answers regulatory and testing questions directly — no discovery call required to get a straight answer.

Talk to our team