Skip to content
Client access

Service

Incident Response & Forensics

We contain the incident, identify the root cause and guide recovery following NIST SP 800-61.

Automation
If your organization uses Kynapt, the asset inventory and previous findings are already in the portal, which shortens the initial analysis.
Human validation
Our team leads containment and preserves evidence with chain of custody.

The challenge

During an incident, every uncontrolled hour multiplies the impact

Ransomware, a compromised privileged account or a data leak demand fast decisions with incomplete information: what to isolate, what to preserve, whom to notify and when to resume operations.

Acting without a method can destroy evidence, tip off the attacker or reintroduce the threat during recovery. Acting too late can mean weeks of downtime.

Our team supports your organization from the first call: we contain the threat, determine what happened and guide a safe recovery, following the NIST incident handling lifecycle.

What we do

Before, during and after the incident

Response is most effective when it is prepared in advance. We support you at all three stages.

Incident response

Immediate support to contain the attack, coordinate technical teams and make informed decisions in the first hours.

Digital forensics

Acquisition and analysis of evidence from endpoints, servers, memory and logs, preserving chain of custody.

Threat hunting

Proactive search for indicators of compromise and persistence across your network to confirm the attacker is gone.

Incident response plan

Design or update of your plan: roles, escalation criteria, communications and playbooks by incident type.

Simulation exercises

Tabletop exercises with leadership and technical teams, based on realistic scenarios for your industry.

Incident response retainer

A pre-agreed availability arrangement so you do not lose time on procurement when an incident strikes. [PLACEHOLDER: confirm the terms and response times offered]

How we work

An orderly process under pressure

01

Initial assessment

We understand what was observed, which systems are affected and which urgent decisions must be made.

02

Containment

We isolate compromised systems and accounts to stop the spread, while preserving the evidence needed.

03

Investigation

We rebuild the attack timeline: entry vector, lateral movement, affected data and persistence.

04

Eradication

We remove the attacker’s access, tools and persistence mechanisms, and fix the exploited weakness.

05

Recovery

We guide a safe, monitored return to operations to detect any attempt to regain access.

06

Lessons learned

We document root cause and improvements, and help you prepare information for regulators and stakeholders.

Deliverables

Clarity on what happened and what comes next

Reference frameworks

  • NIST SP 800-61
  • ISO/IEC 27035
  • ISO/IEC 27037
  • MITRE ATT&CK
  • Executive incident reportWhat happened, business impact, actions taken and current status, written for leadership.
  • Technical forensic reportDetailed timeline, entry vector, attacker techniques and indicators of compromise.
  • Indicators of compromiseAn IOC list ready to load into your monitoring and blocking tools.
  • Evidence with chain of custodyPreserved and documented evidence, suitable for legal action or requests from authorities.
  • Improvement planPrioritized recommendations to prevent a similar incident from happening again.
  • Notification supportTechnical information to back the communications your organization must send to regulators or affected parties.

Frequently asked questions

What clients usually ask

We think we have an incident in progress. What do we do now?

Contact us immediately at +51 940-458-631 or contacto@kamayasecure.com. In the meantime, avoid shutting down or reinstalling affected machines: disconnect them from the network if possible and keep the logs, so valuable evidence is not lost.

Can you work remotely?

Yes. Much of the containment and analysis can be done remotely, and we travel to your facilities when the investigation requires it.

What happens to the evidence if we want to take legal action?

We acquire and document evidence following chain-of-custody good practices (ISO/IEC 27037), so it can be presented to the authorities.

Do we need to report the incident to an authority?

It depends on your sector and the data affected: for example, SBS-supervised entities and cases involving personal data under Law No. 29733 may have reporting obligations. We provide the technical support; the legal assessment belongs to your legal team.

How do we prepare before it happens?

With an up-to-date response plan, regular simulation exercises and a retainer that guarantees availability when you need it most.

Other services

A comprehensive view of your security

Compliance & Risk Management

We prepare your organization for ISO 27001, SBS Resolution No. 504-2021, PCI DSS and Law No. 29733, with controls that work in practice.

CISO as a Service

Outsourced security leadership: strategy, roadmap and board reporting, without the cost of a full-time executive.

Zero Trust

Consulting to design and adopt a zero trust model: identity, segmentation and continuous verification.

Kamaya Secure logo on an office wall

Let’s define the right scope for your organization

Tell us about your objectives and constraints. We will send you a proposal with scope, rules of engagement, timeline and deliverables.

Chat on WhatsApp (opens in a new tab)