GDF provides 24/7 incident response for ransomware, business email compromise, unauthorized access, data exposure, insider activity, cloud compromise, and destructive events. The response plan establishes decision authority, communications, evidence priorities, containment options, and known business constraints before systems are changed.
Early response has competing priorities
Disabling an identity, isolating a host, rotating a secret, or rebuilding a server may be necessary, but each action can change volatile evidence or alert an adversary. GDF works with the client's security, IT, counsel, insurance, and communications teams to sequence actions. Decisions and timestamps are recorded as the event develops.
For New York organizations, technical findings may inform legal and regulatory analysis under the SHIELD Act, NYDFS requirements, contractual terms, or sector rules. GDF supplies the facts and does not provide legal advice or decide whether notice is required.
Scope from identities to affected data
Response analysis may cover endpoints, servers, email, identity providers, cloud control planes, firewalls, VPNs, applications, backups, and security telemetry. The team tests possible initial access, persistence, privilege, lateral movement, command activity, data access, staging, exfiltration indicators, and destructive actions. Where evidence supports it, the report identifies a likely initial-access path and contributing conditions. Missing logs, overwritten telemetry, shared accounts, encryption, or incomplete coverage may prevent a definitive attribution or entry-path conclusion.
- Triage and containment support at any hour
- Forensic acquisition and time-sensitive log preservation
- Compromised identity and business email analysis
- Ransomware path, affected-host, and recovery validation
- Technical chronology and reporting for decision makers
Readiness is cheaper than improvisation
Incident readiness planning identifies call trees, evidence sources, log retention, backup access, insurer requirements, outside dependencies, and decision thresholds before a crisis. Tabletop exercises test actual roles and systems. After an event, corrective actions are assigned and tested where practical. The record states the retest date, approved scope, remaining gaps, and accepted residual risk.