After an attack, people will ask what happened: your board, your insurer, the ICO and your customers. A forensic investigation gives you answers based on evidence.
Without an investigation, a business often can't say whether personal data was taken, and has to assume the worst when deciding who to tell.
Evidence doesn't last. Logs are overwritten, machines get rebuilt and some evidence is lost when a computer is switched off, so the sooner an investigation starts, the more it can find.
If the attack is still going on, start with emergency incident response: containing it comes first, and the investigation runs alongside.
Businesses that have had an incident and need to know what happened, including those that have already recovered but still need answers for their insurer, the regulator or their customers.
Investigations are carried out by Sophos's digital forensics and incident response team and arranged through us. Tell us what you need to find out, and we'll scope it with them.
Sophos Incident Response Services — Sophos's digital forensics and incident response team, which gained NCSC-assured Cyber Incident Response (Level 2) status in 2024.
Tell us a little about your business and we'll recommend the controls that matter most for it — no obligation, and no jargon.