VITI Security

Services · Incident Response

If something is actively wrong, call first - read second.

A senior responder is on the phone with you within 30 minutes during Indian business hours (within 2 hours overnight). We work the incident with you until it is contained, eradicated, and you have a written post-incident report. Billing is hourly with a transparent rate - no surprise multi-lakh invoices. What follows is how engagements work for teams in crisis, and for teams planning ahead so they are not improvising the day a breach happens.

Two ways to engage

Pick the model that matches your situation.

1. Emergency response (active incident)

Call our emergency line. A senior responder is on the phone with you within 30 minutes. We work the incident with you until it is contained, eradicated, and you have a written post-incident report. Billing is hourly with a transparent rate - no surprise multi-lakh invoices.

2. Retainer (peace of mind)

A retainer agreement guarantees response time and locks in a pre-negotiated hourly rate. You pay a monthly fee whether or not an incident occurs. Most retainer clients use the unused hours for incident readiness work - tabletop drills, runbook updates, threat-hunt sweeps. So the money is not sitting idle.

What incidents we handle

Every incident category we have worked through.

Ransomware

Decryption assessment, containment, recovery planning, ransom-payment guidance (legal + practical), restore-from-backup execution, post-recovery hardening.

Data breach / exfiltration

Scope determination (what was actually accessed), forensics, regulator notification support (CERT-In, DPDP Data Protection Board), customer communication drafting.

Account compromise / takeover

Identifying the entry vector, revoking access, hunting for persistence, locking down identity systems.

Business email compromise (BEC)

Halting fraudulent wire transfers, working with banks, forensic email log analysis, mailbox rule cleanup.

Web application compromise

Identifying the exploited vulnerability, removing webshells/backdoors, code review for similar gaps, recovery without re-introducing the breach.

Insider threat

Quiet investigation, evidence preservation, coordinated termination if needed, legal handover.

Cloud account compromise

AWS / Azure / GCP - credential rotation, IAM hunt, persistence removal, cost-spike investigation.

The response process

Five phases. Each with a clear deliverable + timeline.

01

Phase 1: Triage (first 2 hours)

Initial call. Real incident vs. false alarm. Immediate containment guidance (what NOT to do - common mistakes that destroy evidence). Engagement scope + rate confirmed in writing.

02

Phase 2: Contain (hours 2-24)

Stop the spread: isolate affected systems, revoke compromised credentials, block attacker access. Preserve evidence: memory dumps, disk images, log copies (before logs roll over). Identify scope. Communicate to who needs to know.

03

Phase 3: Eradicate (days 2-7)

Remove attacker presence: backdoors, persistence mechanisms, malicious accounts. Patch the root cause. Hunt for re-entry (attackers often leave multiple footholds). Independent verification that systems are no longer compromised.

04

Phase 4: Recover (days 5-14)

Restore systems and data from clean backups. Bring services back online in a controlled order. Monitor closely for reinfection or re-attack. Communicate completion to stakeholders.

Why VITI for incident response

The specific things that matter when something is on fire.

CERT-In aligned methodology

We follow CERT-In incident-reporting standards (six-hour reporting window, standardized evidence packs). We are not ourselves a CERT-In empanelled firm; if your regulator requires an empanelled signature, you retain one separately.

Indian timezone, fast response

Most US-based IR firms do not pick up the phone in your business hours. We do.

Forensics depth

Memory, disk, network, cloud - we work all the layers. We do not outsource the forensics piece to a third party with a slow turnaround.

Regulator + legal coordination

We have worked with CERT-In notification, DPDP Data Protection Board guidance, and law enforcement coordination. We know the timelines and templates.

Transparent pricing

Hourly rate, billed in 15-minute increments, no minimum hours per call. You see what you are paying for.

No tool-pushing during an incident

The day of a breach is not the day to evaluate new EDR products. We work with what you have and tell you what to change AFTER recovery.

Retainer pricing

Three tiers, plus emergency engagements without a retainer.

Retainer guarantees response time and locks in a pre-negotiated hourly rate. Emergency engagements without retainer: $175-300 per hour depending on responder seniority and incident complexity.

Standby Retainer

Baseline readiness

$299/ month
  • 4-hour response time guarantee
  • Locked hourly rate (10-15% off emergency)
  • 4 hours of monthly readiness work
  • Tabletop drills + runbook reviews
  • Right for: SMBs with no internal IR capability
Discuss Standby retainer
Most popular

Active Retainer

Real readiness

$899/ month
  • 2-hour response time
  • Locked hourly rate (20% off emergency)
  • 16 hours of monthly readiness work
  • Quarterly tabletop exercise
  • Annual incident-response plan review
  • Right for: mid-market, fintech, healthcare
Discuss Active retainer

Dedicated Retainer

For SDFs + regulated

Custom
  • Named responders on call
  • 30-minute response
  • Integrated with your alerting
  • Monthly threat-hunt sweeps
  • For Significant Data Fiduciaries + regulated industries
Discuss Dedicated retainer

Incident response FAQ

Should I pay the ransom?
Almost never our first recommendation, but the answer depends on: do you have working backups, is the ransom amount strategic-business-killing, are the attackers known to deliver decryptors when paid, what are the legal and reputational implications. We help you think through the calculus - and we coordinate with your legal counsel before any payment.
Do we have to notify the regulator?
Breach-notification timelines vary by jurisdiction - GDPR's 72-hour rule, US state breach laws, and sector regulators each set their own. We help you map which obligations apply to you and draft the notifications.
How long until we are back to normal?
Highly dependent on incident type. Ransomware with clean backups: 3-7 days to recovery, 30 days to fully stable. Data breach without operational impact: continuous operation, weeks of forensics. Account takeover: hours to contain, days to clean. We give you a realistic timeline in the first 24 hours.
Will our cyber insurance cover this?
Often yes - if you have a policy and notify the insurer in time. We work with major cyber insurance carriers and can coordinate the claim alongside the response. Critical: notify your insurer in parallel with engaging us, not after.
Can you keep this confidential?
Yes. NDA in place before any engagement. Mandatory regulator notifications are unavoidable, but everything else - including the fact that you engaged us - stays confidential.

Right now: call us.

If you are in an active incident, the call is the fastest way to engage. A senior responder is on the line in 30 minutes or less during Indian business hours, within 2 hours overnight. Use the button to reach our emergency line now.