Emergency Response

Something already happened

If you think an account has been taken over, a payment has been redirected, files have been encrypted, or someone gained remote access to an office computer — the first hour matters more than everything after it.

Before you call anyone, if you can

  • Disconnect the affected machine from the network. Don’t wipe it, don’t reinstall, don’t “clean it up.” What’s on it is evidence.
  • Don’t delete the suspicious emails. Those are evidence too.
  • Stop any pending payment or wire directly with the bank, by phone, using a number you already had — not one from an email.
  • Change passwords from a different, known-clean device.
  • Write down the timeline while it’s fresh: what happened, when, and who noticed.

What DriveTech does

  1. Containment. Stop the access before anything else.
  2. Scope. Which accounts, which machines, what was reachable.
  3. Restore operations. Get the office working again.
  4. Close the path. Fix what was used to get in, so it isn’t used again next month.
  5. Documentation. A written record of the incident and the response, for your insurer, your counsel, and any notification obligation.

What DriveTech is not

DriveTech is not a law firm and does not advise on breach notification obligations, and does not negotiate with attackers. If the incident involves patient information, client funds, or regulated data, involve your counsel and your insurance carrier early — most cyber policies require prompt notification and some require using an approved response vendor.

Business hours: Monday–Friday, 9:00 AM–6:00 PM.

Call 212-249-4091Request Service