Strategy & Governance

Managed Security

Cyber Defense

Governance, Risk & Compliance

Operations & People

Talk to us

Managed Security

Incident response, from the first hour.

Incident response services in India are usually bought on the worst day of the year, from whoever answers the phone. That is the most expensive way to buy anything. The organisations that recover fastest are the ones that agreed the terms, the contacts and the escalation path while nothing was on fire.

When something is on fire, the sequence is fixed and the clock matters: contain the spread, establish what actually happened, remove the attacker completely rather than partially, restore service, and write down what would have caught it sooner. We work that sequence with your team, and we keep the evidence intact while we do it, because the questions from your regulator, your insurer and your customers all arrive later.

Response is also the wrong place to start. Preparation (a plan that has been rehearsed, a compromise assessment that checks whether someone is already inside, and monitoring that would notice) is what makes the response short. If you have no detection today, begin with a managed SOC.

Why you need it

01 / 06

Why you engage before the incident.

01

The first hours decide the size of the breach.

Containment early limits what an attacker reaches; containment late means the difference between one compromised server and a restored-from-backup estate. Nobody negotiates a contract quickly at 2am, and the paperwork is what delays most engagements.

02

Panic destroys the evidence.

Rebuilding the affected server is the natural instinct and it deletes the answer to every question that follows: how they got in, how long they were there, what they took, and whether they are still inside. Volatile memory is gone the moment someone reboots.

03

You will have to explain it, precisely.

Regulators, insurers, enterprise customers and your own board will each ask what happened, when, to whose data, and what you did. Those answers come from forensic work performed at the time, not from recollection assembled a month later.

04

Removing an attacker partially is worse than not trying.

Cleaning one machine while a second persistence mechanism survives means the intrusion returns, now aware that it has been noticed. Eradication has to be scoped by evidence, and evidence takes investigation.

Instrument

02 / 06

Thirty days after an intrusion, twice.

Two organisations, one difference: whether anyone was ready. Scrub the timeline and watch the gap open.

What we deliver

03 / 06

What we do, and when.

01

Emergency response

Immediate triage when something is happening now: scoping the compromise, containing the spread, preserving evidence before it is overwritten, and giving your leadership a defensible picture within hours rather than weeks. If you are in an incident, call. The paperwork can follow.

02

Digital forensics

Disk and memory imaging with chain of custody maintained, log and timeline reconstruction, malware and persistence analysis, identification of the initial access vector, and a determination of what data was actually accessed rather than what theoretically could have been.

03

Threat hunting and IOC sweeping

Proactive hunting for indicators of compromise and indicators of attack across the estate, mapped to MITRE ATT&CK, searching for what the alerts did not catch rather than waiting for one to fire.

04

Incident response planning

A written plan with named roles, decision authority, escalation paths, out-of-hours contacts, legal and regulatory notification triggers, and communication templates. Then tabletop exercises, because a plan that has never been run is a document, not a capability.

05

Retainers

Pre-agreed terms, a defined response time, and a team that already knows your environment before the day it matters. Unused retainer hours convert to preparation work (hunting, tabletop exercises, plan review) so the arrangement earns its cost in a quiet year too.

06

Post-incident review

A full account of what happened and why, the detection and control gaps that let it run, and a prioritised remediation plan. Delivered as a document your board can read and your engineers can act on, not as a blame exercise.

How we run it

04 / 06

Six phases, in this order.

  1. 01

    Preparation

    Plan, roles, authority and contacts agreed and rehearsed. Logging and retention checked against what an investigation will actually need: the most common obstacle in a real incident is that the logs stopped thirty days ago.

    Before anything happens
  2. 02

    Detection and identification

    Confirming that this is an incident and establishing initial scope: which systems, which accounts, which data, and whether the activity is still live. Stakeholders are briefed at this point with what is known and what is not, kept clearly separate.

    Hour 0
  3. 03

    Containment

    Stopping the spread without destroying the evidence: network isolation, credential and session revocation, disabling the attacker's access paths. Short-term containment first, then a considered plan that does not tip off an adversary still inside.

    Hours 1-8
  4. 04

    Eradication

    Removing every foothold, not the first one found: malware, persistence mechanisms, created accounts, modified scheduled tasks, and the vulnerability or credential that granted the initial access. Scoped by what the forensics establish.

    Days 1-5
  5. 05

    Recovery

    Restoring service in a controlled sequence, from verified-clean backups where restoration is needed, with monitoring raised on the affected systems. Returning to production is a decision made on evidence, with criteria agreed in advance.

    Days 3-14
  6. 06

    Post-incident analysis

    The full timeline, root cause, what detection would have caught it earlier, and the control changes that follow, with the regulatory and contractual notification record assembled while it is still accurate.

    Weeks 2-4

Key benefits

05 / 06

What changes after.

The incident is shorter

Because the decisions, the contacts and the authority were agreed beforehand, and someone who has done this before is making the containment call in hour one.

You can answer the hard questions

What was accessed, when, by whom, and what you did: evidenced, dated, and suitable for a regulator, an insurer or an enterprise customer.

The same route closes behind you

Post-incident review turns one bad week into a specific set of control and detection changes, verified rather than promised.

Tools we use

06 / 06

Named, and used on your engagement.

No “latest tech tools”. These are the ones your report will cite, alongside the manual work that a tool cannot do for you.

Forensics and imaging

  • Velociraptor
  • KAPE
  • FTK Imager
  • Volatility
  • Autopsy

Analysis

  • Plaso / log2timeline
  • Timesketch
  • YARA
  • Sigma
  • CyberChef

Endpoint and network

  • osquery
  • Zeek
  • Wireshark
  • Suricata

Intelligence and tracking

  • MISP
  • TheHive
  • VirusTotal
  • MITRE ATT&CK

Frameworks

  • NIST SP 800-61
  • SANS PICERL
  • MITRE ATT&CK

Included in this service

Compromise assessment

Also

Incident response assumes you know something is wrong. A compromise assessment asks the question nobody wants to ask: is an attacker already inside, quietly, and has been for months?

It is a point-in-time hunt across endpoints, servers, identity infrastructure and network telemetry, looking for dormant persistence, unusual authentication patterns, credential misuse, data staging and command-and-control traffic. Unlike monitoring, it examines the estate as it is now, including the systems no agent has ever been installed on.

The output is a straight answer with evidence: either indicators worth investigating, or a documented finding of nothing detected, with the coverage and limitations stated honestly. It is the right first engagement after an acquisition, after a breach at a peer or supplier, or when something has felt wrong for a while.

Included in this service

Business continuity and crisis management

Also

Technical response is one workstream. A serious incident also runs legal, regulatory, communications, customer, insurance and operational workstreams at the same time, and the organisations that cope have decided in advance who owns each of them.

We help build and rehearse that: business impact analysis to establish what must be restored first and how quickly, recovery objectives that are tested rather than assumed, a crisis management structure with clear decision authority, notification triggers mapped to your regulatory and contractual obligations, and holding statements written before anyone needs them.

Tabletop exercises are where this becomes real. Running a ransomware scenario through your actual leadership team reliably surfaces the same three gaps: nobody knows who can authorise disconnecting production, the out-of-hours contact list is stale, and the recovery plan depends on a system that is itself encrypted in the scenario.

Included in this service

Cyber insurance advisory

Also

Cyber insurance applications have become security questionnaires with a price attached. Insurers now ask for specifics (multi-factor authentication coverage, privileged access controls, backup immutability and tested restoration, endpoint detection coverage, patching cadence, email filtering) and both the premium and the eventual claim depend on the answers being accurate.

We help you answer them honestly and improve the answers that cost you money: assessing your current posture against what the market is asking, closing the controls that most affect terms, and documenting evidence so the application is defensible.

The part that matters most comes later. Claims are contested on whether the controls described in the application were actually in place at the time of the loss. Keeping that evidence current, and knowing your policy's notification deadlines before you are inside one, is the difference between cover and a dispute.

Why Aphelion

Shared

Four things you can check.

01

The work is done by people with names.

Darshap Nayak, formerly of KPMG, holds a master’s degree in cybersecurity and more than seven years in security operations. Jaimin Somani brings fifteen-plus years of academic and hands-on VAPT. Hemang Desai is an ICT network specialist from Australia. You will meet them, not a logo.

Meet the team
02

Evidence, not adjectives.

Every finding arrives with the reproduction steps, the affected asset and the fix, ranked by what it actually reaches in your environment, not by a CVSS number copied from a scanner. You get the report and the raw output, not a summary of a summary.

See how we test
03

Two offices, one practice.

Ahmedabad and Sharjah, working the same methodology on the same tooling. Indian data-residency requirements and UAE delivery are both ordinary here, and the AphelioNYX AD Pen-Test module runs entirely inside your perimeter when regulation says it must.

The platform
04

What we will not do.

Invent a statistic to make a slide land. Publish your name as a client without written permission. Print an award badge nobody awarded. Founded in 2024. We say so, and we attribute experience to the people who have it.

Ask us anything

100+ organizations secured

Across the globe, and across eight industries. We name a client only with their written permission.

  • Finance & Banking
  • Healthcare
  • Retail & E-commerce
  • Technology
  • SaaS
  • Hospitality
  • Manufacturing
  • Pharmaceuticals

AphelioNYX is SOC 2, ISO and GDPR compliant; attestations are available on request under NDA. We would rather hand you the report than print a badge.

Questions

FAQ

What clients ask about incident response.

We think we are in an incident right now. What do we do first?
Do not rebuild or reboot anything, because that destroys the evidence you will need. Isolate affected systems at the network level rather than powering them off, preserve logs before retention rolls them, stop using potentially compromised accounts and revoke their sessions, and start a written timeline of what you observe and what you change. Then call us. The contract can be signed while triage is already running.
How fast can you respond?
Retainer clients get a contractually defined response time and a team that already holds their architecture, contacts and escalation paths. Without a retainer, response begins as soon as scope and authorisation are agreed, which is usually the same day but depends on how quickly the paperwork can move on your side. That delay is the single strongest argument for a retainer.
Do we have to tell a regulator?
That depends on the data, the jurisdiction and the sector, and it is a legal determination rather than a technical one, so it is made with your counsel, using facts from the investigation. Our role is to establish those facts precisely, which data was accessed and when, and to record them in a form that supports whatever notification your obligations require. Indian entities should note CERT-In's short reporting timelines for specified incident types.
Should we pay a ransom?
It is a business and legal decision for your leadership, not a recommendation we make for you, and it carries sanctions and legal exposure that need counsel. What we contribute is the technical picture the decision needs: whether clean backups exist and restore correctly, what was actually exfiltrated as opposed to claimed, whether the decryptor for this variant is known to work, and how long each option realistically takes. Paying also does not remove the attacker.
What does a retainer include if nothing happens?
A defined response time, an onboarding exercise so we know your environment in advance, and agreed authorisation so no time is lost on contracting. Unused hours convert into preparation work: threat hunting, incident response plan development, tabletop exercises, log coverage review, or a compromise assessment. The intent is that a quiet year still buys you something.

Forty-five minutes. Your environment, not a slide deck.

A personalised walkthrough and a free readiness assessment against the frameworks you are actually being asked for. Pick a time that suits you, or write to us. We reply within one business day.