Services · Incident Response
If something is actively wrong, call first - read second.
A senior responder is on the phone with you within 30 minutes during Indian business hours (within 2 hours overnight). We work the incident with you until it is contained, eradicated, and you have a written post-incident report. Billing is hourly with a transparent rate - no surprise multi-lakh invoices. What follows is how engagements work for teams in crisis, and for teams planning ahead so they are not improvising the day a breach happens.
Two ways to engage
Pick the model that matches your situation.
1. Emergency response (active incident)
Call our emergency line. A senior responder is on the phone with you within 30 minutes. We work the incident with you until it is contained, eradicated, and you have a written post-incident report. Billing is hourly with a transparent rate - no surprise multi-lakh invoices.
2. Retainer (peace of mind)
A retainer agreement guarantees response time and locks in a pre-negotiated hourly rate. You pay a monthly fee whether or not an incident occurs. Most retainer clients use the unused hours for incident readiness work - tabletop drills, runbook updates, threat-hunt sweeps. So the money is not sitting idle.
What incidents we handle
Every incident category we have worked through.
Ransomware
Decryption assessment, containment, recovery planning, ransom-payment guidance (legal + practical), restore-from-backup execution, post-recovery hardening.
Data breach / exfiltration
Scope determination (what was actually accessed), forensics, regulator notification support (CERT-In, DPDP Data Protection Board), customer communication drafting.
Account compromise / takeover
Identifying the entry vector, revoking access, hunting for persistence, locking down identity systems.
Business email compromise (BEC)
Halting fraudulent wire transfers, working with banks, forensic email log analysis, mailbox rule cleanup.
Web application compromise
Identifying the exploited vulnerability, removing webshells/backdoors, code review for similar gaps, recovery without re-introducing the breach.
Insider threat
Quiet investigation, evidence preservation, coordinated termination if needed, legal handover.
Cloud account compromise
AWS / Azure / GCP - credential rotation, IAM hunt, persistence removal, cost-spike investigation.
The response process
Five phases. Each with a clear deliverable + timeline.
Phase 1: Triage (first 2 hours)
Initial call. Real incident vs. false alarm. Immediate containment guidance (what NOT to do - common mistakes that destroy evidence). Engagement scope + rate confirmed in writing.
Phase 2: Contain (hours 2-24)
Stop the spread: isolate affected systems, revoke compromised credentials, block attacker access. Preserve evidence: memory dumps, disk images, log copies (before logs roll over). Identify scope. Communicate to who needs to know.
Phase 3: Eradicate (days 2-7)
Remove attacker presence: backdoors, persistence mechanisms, malicious accounts. Patch the root cause. Hunt for re-entry (attackers often leave multiple footholds). Independent verification that systems are no longer compromised.
Phase 4: Recover (days 5-14)
Restore systems and data from clean backups. Bring services back online in a controlled order. Monitor closely for reinfection or re-attack. Communicate completion to stakeholders.
Why VITI for incident response
The specific things that matter when something is on fire.
CERT-In aligned methodology
We follow CERT-In incident-reporting standards (six-hour reporting window, standardized evidence packs). We are not ourselves a CERT-In empanelled firm; if your regulator requires an empanelled signature, you retain one separately.
Indian timezone, fast response
Most US-based IR firms do not pick up the phone in your business hours. We do.
Forensics depth
Memory, disk, network, cloud - we work all the layers. We do not outsource the forensics piece to a third party with a slow turnaround.
Regulator + legal coordination
We have worked with CERT-In notification, DPDP Data Protection Board guidance, and law enforcement coordination. We know the timelines and templates.
Transparent pricing
Hourly rate, billed in 15-minute increments, no minimum hours per call. You see what you are paying for.
No tool-pushing during an incident
The day of a breach is not the day to evaluate new EDR products. We work with what you have and tell you what to change AFTER recovery.
Retainer pricing
Three tiers, plus emergency engagements without a retainer.
Retainer guarantees response time and locks in a pre-negotiated hourly rate. Emergency engagements without retainer: $175-300 per hour depending on responder seniority and incident complexity.
Standby Retainer
Baseline readiness
- 4-hour response time guarantee
- Locked hourly rate (10-15% off emergency)
- 4 hours of monthly readiness work
- Tabletop drills + runbook reviews
- Right for: SMBs with no internal IR capability
Active Retainer
Real readiness
- 2-hour response time
- Locked hourly rate (20% off emergency)
- 16 hours of monthly readiness work
- Quarterly tabletop exercise
- Annual incident-response plan review
- Right for: mid-market, fintech, healthcare
Dedicated Retainer
For SDFs + regulated
- Named responders on call
- 30-minute response
- Integrated with your alerting
- Monthly threat-hunt sweeps
- For Significant Data Fiduciaries + regulated industries
Incident response FAQ
Should I pay the ransom?
Do we have to notify the regulator?
How long until we are back to normal?
Will our cyber insurance cover this?
Can you keep this confidential?
Right now: call us.
If you are in an active incident, the call is the fastest way to engage. A senior responder is on the line in 30 minutes or less during Indian business hours, within 2 hours overnight. Use the button to reach our emergency line now.

