Scholarships are available for economically weaker and PWD students. Learn more at edu@saralgroups.com Explore programmes
Incident Response & Forensics (DFIR)

Contain the Breach, Preserve Evidence, and Get the Business Back

When ransomware, BEC, or a stolen laptop becomes a bad week, you need specialists who can isolate, image, and brief leadership the same day. Saral Cyber Team DFIR is on-call for containment, malware analysis, and recovery.

1 hr

Sev-1 Engage

24/7

Hotline

Chain

Of Custody

What Saral Cyber Team Delivers

Integrated outcomes — monitoring, response, and proof — not a pile of disconnected tools.

Emergency Containment

Isolate hosts, revoke tokens, block C2, and freeze identity. The first hour is for bleeding, not forensics essays.

Forensics & Malware Analysis

Disk/memory imaging, timeline, and malware family ID with chain of custody if you may litigate or claim insurance.

BEC & Email Compromise

Mailbox audit, forwarding rules, OAuth apps, and vendor-payment freeze playbooks.

Ransomware Recovery

Scope of encryption, clean restore vs. rebuild, and negotiation support only if leadership chooses that path.

Regulatory & Insurance Pack

CERT-In clocks, DPDP/GDPR notice drafts, and insurer questionnaires with facts — not speculation.

Retainer or On-Demand

Pre-authorized access and a hotline if you want sub-hour engagement; on-demand if you accept a longer ramp.

Case Studies & Outcomes

What changed when teams stopped buying isolated products and started buying a cyber program.

Case Study

Ransomware: Plant IT Restored in 52 Hours

Problem: A mid-size manufacturer found encrypted file servers on a Monday. Backup admin console was also hit.

Solution: Contained remaining endpoints, identified the initial phishing + RDP path, restored from offline backups that still existed, rebuilt the backup plane.

Result: Core operations resumed in 52 hours. Insurance claim accepted with our timeline. CERT-In notified in window.

52 hrs

To Core Ops

Claim

Accepted
"They talked to the plant, the insurer, and the board without three different stories."— MD — Coimbatore
Case Study

BEC: ₹1.8 Cr Payment Recalled

Problem: Finance paid a 'vendor bank change' email. The real vendor invoiced a week later.

Solution: Mailbox forensics, freeze with the sending bank, vendor comms, and MFA + approval dual-control on master-data changes.

Result: Majority of funds recalled. Two additional compromised mailboxes found. Playbook now part of monthly finance training.

₹1.8 Cr

Attempted

2

Mailboxes
"Forensics paid for itself before the report was finished."— CFO — Gurugram

How We Engage

A repeatable path from coverage map to measurable risk reduction.

1

Triage

What is on fire, what is rumoured, who is the exec sponsor. We set a single incident commander.

2

Contain

Identity, endpoint, email, cloud. Preserve volatile evidence as we go — not after.

3

Eradicate & Recover

Clean rebuild vs. restore decisions with business owners. No 'just decrypt and hope'.

4

Learn

Root cause, control gaps, CERT-In/DPDP/insurance pack, and a 30-day hardening plan.

Why Saral Cyber Team

Enterprise-grade security, built for the mid-market teams who actually have to run it.

Speed With Discipline

Containment first, but we do not wipe the only evidence of how they got in.

Legal-Ready Handling

Chain of custody, named handlers, and language that counsel can use.

One Story for Everyone

Plant, board, insurer, regulator — briefed from the same timeline.

We Also Do the Boring Part

Retainers include tabletop and access pre-staging so the first hour is not spent on VPN tickets.

Client Testimonials

Security leaders, IT owners, and operators we sit with in the war room.

★★★★★

"They did not freeze the whole factory 'to be safe'. Containment was surgical."

Harish P.
Harish P.Plant Director — Aurangabad
★★★★★

"The timeline matched what we filed. That is rarer than it should be."

Leela G.
Leela G.General Counsel — Mumbai
★★★★★

"Retainer drills made the real call boring — which is the goal."

Nikhil R.
Nikhil R.CISO — Hyderabad

Ready to close this gap?

Book a free consultation with Saral Cyber Team. No product dump — a coverage map and the first controls that pay off.

Schedule Free Consultation → 📞 +91 79883 75156

Expert Insights

Practical notes from the people who run these programs.

Ransomware

Offline Backups Are a Control, Not a Slogan

The restore test we insist on before we ever talk about 'resilience'.

BEC

Vendor Bank Changes Need Dual Control

A finance-process fix that stops the most expensive email in the company.

CERT-In

The Six-Hour Clock: What to Log Before You Need It

How to fail a reporting deadline without noticing.

Frequently Asked Questions

How fast can you be on a live incident? + Retainer clients: Sev-1 engagement target is one hour, 24/7. On-demand depends on analyst availability; we still try to be on a bridge the same day for ransomware and BEC.
Do you pay ransoms or negotiate? + We do not recommend paying as default. If leadership and counsel choose that path, we can coordinate with specialist negotiators and help you not get scammed twice. Decision stays with you.
Will you work with our insurer and lawyer? + Yes. Privilege, evidence handling, and claim forms are part of DFIR. We fit into the counsel-led structure when one exists.
Can you investigate without disrupting production? + Often. We image and isolate the minimum. Some ransomware and AD events require wider containment — we explain trade-offs to the incident commander before pulling plugs.
Do you help with CERT-In and DPDP notifications? + We prepare factual timelines and impact scope. Legal owns the notice. We will not invent certainty where logs do not support it.
north
Pop Up

Free Service Demo