Skip to content

How we handle a cybersecurity incident

When you call SecDesk, a senior incident responder picks up. Not a sales representative. Not a triage desk. Here is what happens from that first call to the moment we hand you back a clean environment and a written report.

  1. 01

    The first call

    You call 088 SECDESK (7323375). We ask three things: what happened, when you noticed it, and what systems are involved. We do not ask you to fill in a web form. We do not schedule a callback for the next business day.

    Most clients call with limited information: 'I think we have been hacked' or 'someone reported a suspicious email from our CEO.' That is enough to start. Within the first 30 minutes, we determine the type of incident and where to look first.

  2. 02

    Containment (first two to four hours)

    The priority is to stop the attacker from doing more damage. For email compromise, this means disabling the affected account, revoking all active sessions and refresh tokens, and auditing mailbox rules. Attackers almost always set up forwarding rules to keep receiving copies of incoming mail even after the password is changed. We catch those.

    For broader incidents, containment might involve isolating servers, blocking IP ranges, revoking OAuth application consents, or disabling compromised service accounts. We explain every step before we take it.

    We also start preserving evidence. Audit logs, sign-in records, email headers, and file access logs are exported and secured. This matters for the investigation and for any regulatory reporting under the AVG.

  3. 03

    Investigation

    Once containment is in place, we trace the full attack. How did the attacker get in? Phishing, credential stuffing, token theft, or an exploited vulnerability? What accounts and systems were accessed? Was data read, copied, or exfiltrated? What persistence mechanisms were set up?

    We check places most internal IT teams do not monitor: OAuth consent grants, Azure AD audit logs, Exchange transport rules, Power Automate flows, SharePoint sharing settings, and connected third-party applications.

    For Microsoft 365 environments, we review the Unified Audit Log, Azure AD sign-in logs, mailbox audit logs, and admin activity logs. We look for impossible travel patterns, suspicious token usage, and anomalous application consent.

  4. 04

    Remediation

    Remediation goes beyond resetting passwords. We remove every artifact the attacker left: forwarding rules, auto-delete rules, OAuth application grants, MFA devices the attacker registered, and Azure AD conditional access exclusions.

    We reset credentials with a full session revocation. We verify the attacker has no remaining access by checking active tokens, registered devices, and application permissions. Then we harden the environment: modern authentication enforcement, conditional access policies, anti-phishing protections, and monitoring alerts.

  5. 05

    Reporting

    Every incident gets a written report covering the attack timeline, the attack vector, the scope of compromise, actions taken, and specific recommendations.

    The report is written in plain language. Your board can read it. Your legal team can use it for AVG assessment. If you need to report a data breach to the Autoriteit Persoonsgegevens, the report contains the required information: nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken.

    Every recommendation is specific to your environment and the incident you experienced.

  6. 06

    After the incident

    After we deliver the report, we schedule a lessons-learned call. This is not a sales conversation. It is an honest discussion about what let the attacker in and what would have stopped or detected the attack earlier. Sometimes that means MFA enforcement. Sometimes monitoring. Sometimes a process change in how your finance team handles payment requests.

    The incident engagement is complete once the report is delivered and the lessons-learned call is done. No lock-in, no mandatory follow-up contract.

Talk to a senior responder

No active incident, but want to talk? Schedule a call at a time that works.

Loading scheduler…
Incident response

Need incident response?

088 SECDESK (7323375)

Call us. A senior responder picks up.

  • Two-hour SLA
  • Dutch senior responders

Emergency form

Two-hour response.

Is this urgent? Call us.

088 SECDESK (7323375)

Cannot wait? Call 088 SECDESK (7323375) now

Emergency line088 SECDESK
Call now