CX
Cobrix Solutions
Book Consultation(213) 214-1385

Incident Response

Containment, evidence preservation and recovery for California firms in an active security incident.

If you are in an incident right now

Call (213) 214-1385. Before anything else: disconnect affected machines from the network but do not power them off or reimage them. Powering down destroys volatile memory evidence. Reimaging destroys everything. Preserve first, investigate second, rebuild third.

Do not pay a ransom on impulse, do not post about the incident publicly, and do not email about it from the compromised environment. Attackers frequently sit in mailboxes reading the response.

What ransomware and breach response actually involves

Incident response is not one task. It is four running in parallel under time pressure, and most small firms discover mid-incident that nobody owns three of them.

1

Contain

Isolate affected systems from the network while preserving their state. Revoke active sessions and rotate credentials, starting with any account holding administrative rights.

2

Preserve

Capture logs, disk images and mailbox audit data before they roll off retention. In Microsoft 365 environments the audit log is often the only record of what an attacker touched.

3

Assess

Determine what data was accessed or exfiltrated. This decides your notification obligations, and it is the question your counsel and insurer will ask first.

4

Recover

Rebuild from known-clean backups, close the original entry point, and verify the environment before returning it to production.

California breach notification: the clock you are on

California Civil Code sections 1798.29 and 1798.82 require notice to affected residents in the most expedient time possible and without unreasonable delay. Breaches affecting more than 500 California residents must also be reported to the California Attorney General.

If the data includes Protected Health Information, HIPAA breach notification obligations run in parallel and have their own timelines. If you are a CPA firm, the FTC Safeguards Rule adds its own notification duty. These are separate clocks and they do not wait for each other.

The practical consequence: the evidence you preserve in the first hours determines whether you can scope the breach narrowly and defensibly, or whether you have to notify everyone because you cannot prove otherwise.

What Cobrix does in an incident

Cobrix is a California MSP and MSSP. In an incident we work the containment and recovery track, and we produce the documentation the other tracks depend on:

We coordinate with your legal counsel and cyber insurer rather than replacing them. Most policies require you to notify the carrier before engaging outside help — check your policy before you call anyone, including us.

The controls that prevent the next one

Every incident review we run ends in roughly the same place. The controls below are unglamorous and they are what actually separates firms that get hit from firms that get hit and lose a week.

Frequently asked questions

What should you do first after a ransomware attack?

Disconnect affected systems from the network but do not power them off or reimage them, because that destroys the evidence needed to scope the breach. Preserve logs and disk state, rotate credentials starting with administrative accounts, notify your cyber insurer before engaging outside help, and get legal counsel involved in the first hour.

How long do you have to report a data breach in California?

California Civil Code sections 1798.29 and 1798.82 require notification to affected residents in the most expedient time possible and without unreasonable delay. Breaches affecting more than 500 California residents must also be reported to the California Attorney General. HIPAA and FTC Safeguards obligations run on separate parallel timelines.

Should you pay a ransomware ransom?

Paying does not guarantee data recovery and does not prevent publication of exfiltrated data. Payments to sanctioned entities can create separate legal exposure. This is a decision to make with legal counsel and your insurer involved, never on impulse in the first hours.

Does cyber insurance cover incident response?

Most policies do, but nearly all require you to notify the carrier before engaging outside help, and many require you to use panel vendors. Check your policy before calling anyone. Engaging help outside the panel first can jeopardise the claim.

Can Cobrix help if we are not already a client?

Yes. Call (213) 214-1385. We will tell you honestly whether we are the right fit for the situation or whether you need a dedicated digital forensics firm, which is sometimes the correct answer for large or litigation-bound incidents.

Ready to Get Started?

Schedule a free consultation today.