Compliance & Risk Management
We prepare your organization for ISO 27001, SBS Resolution No. 504-2021, PCI DSS and Law No. 29733, with controls that work in practice.
Service
We contain the incident, identify the root cause and guide recovery following NIST SP 800-61.
The challenge
Ransomware, a compromised privileged account or a data leak demand fast decisions with incomplete information: what to isolate, what to preserve, whom to notify and when to resume operations.
Acting without a method can destroy evidence, tip off the attacker or reintroduce the threat during recovery. Acting too late can mean weeks of downtime.
Our team supports your organization from the first call: we contain the threat, determine what happened and guide a safe recovery, following the NIST incident handling lifecycle.
What we do
Response is most effective when it is prepared in advance. We support you at all three stages.
Immediate support to contain the attack, coordinate technical teams and make informed decisions in the first hours.
Acquisition and analysis of evidence from endpoints, servers, memory and logs, preserving chain of custody.
Proactive search for indicators of compromise and persistence across your network to confirm the attacker is gone.
Design or update of your plan: roles, escalation criteria, communications and playbooks by incident type.
Tabletop exercises with leadership and technical teams, based on realistic scenarios for your industry.
A pre-agreed availability arrangement so you do not lose time on procurement when an incident strikes. [PLACEHOLDER: confirm the terms and response times offered]
How we work
01
We understand what was observed, which systems are affected and which urgent decisions must be made.
02
We isolate compromised systems and accounts to stop the spread, while preserving the evidence needed.
03
We rebuild the attack timeline: entry vector, lateral movement, affected data and persistence.
04
We remove the attacker’s access, tools and persistence mechanisms, and fix the exploited weakness.
05
We guide a safe, monitored return to operations to detect any attempt to regain access.
06
We document root cause and improvements, and help you prepare information for regulators and stakeholders.
Deliverables
Reference frameworks
Frequently asked questions
Contact us immediately at +51 940-458-631 or contacto@kamayasecure.com. In the meantime, avoid shutting down or reinstalling affected machines: disconnect them from the network if possible and keep the logs, so valuable evidence is not lost.
Yes. Much of the containment and analysis can be done remotely, and we travel to your facilities when the investigation requires it.
We acquire and document evidence following chain-of-custody good practices (ISO/IEC 27037), so it can be presented to the authorities.
It depends on your sector and the data affected: for example, SBS-supervised entities and cases involving personal data under Law No. 29733 may have reporting obligations. We provide the technical support; the legal assessment belongs to your legal team.
With an up-to-date response plan, regular simulation exercises and a retainer that guarantees availability when you need it most.
Other services
We prepare your organization for ISO 27001, SBS Resolution No. 504-2021, PCI DSS and Law No. 29733, with controls that work in practice.
Outsourced security leadership: strategy, roadmap and board reporting, without the cost of a full-time executive.
Consulting to design and adopt a zero trust model: identity, segmentation and continuous verification.
Tell us about your objectives and constraints. We will send you a proposal with scope, rules of engagement, timeline and deliverables.