Incident response · 24/7

Under attack? Talk to a Fastnexa responder now.

Ransomware, stolen data, a taken-over email account, or a vulnerability being used against you: call or WhatsApp us and a security engineer will pick it up. We reply within 1 hour, 24/7. You don’t need to be a client.

While you wait for our call

  1. 1

    Disconnect, don't wipe.

    Unplug affected machines from the network or turn off their Wi-Fi. Only power them down if you cannot disconnect them. Don't reinstall or wipe anything yet; the evidence is on those disks.

  2. 2

    Don't pay, and don't reply to the attackers.

    Whatever the note says, a responder should see it before anyone answers it. Take a photo of it.

  3. 3

    Change passwords from a clean device.

    Reset the accounts you think are affected, starting with email and admin accounts, from a phone or computer that was not involved. Turn on two-step sign-in where it is off.

  4. 4

    Write down what you saw, and when.

    The first odd thing anyone noticed, what they clicked, which systems are affected. Times matter more than you would think.

Based on CISA’s #StopRansomware guide. If people are in danger or money is being stolen right now, also call the police and your bank.

Can’t call? Send this and we’ll call you.

Five fields. A responder calls the number you give within the hour.

We reply within 1 hour, 24/7. Non-clients welcome.

This lane is for attacks happening now. For anything else, the calmer form below reaches the same team.

Not an emergency

Worried about something you read on CyberBrief? Talk to an expert.

Whether a vulnerability affects you, what a breach at a supplier means for your data, or how a ransomware group gets in and how to close the door: ask the people who test company security for a living. We reply within 1 hour, 24/7.

Our first 10 founding clients get a full penetration test free until 31 December 2026. See the offer →

We reply within 1 hour, 24/7. Non-clients welcome.

Rather talk it through? Book a 30-minute call →