Homepage > Continuous Operations > Digital Forensics & Incident Response
Sooner or later, most organisations face a serious cyber incident, and what happens in the first hour often decides the outcome. Without a clear escalation plan or an external team on call, every minute of delay compounds the financial loss, slows recovery, and increases your exposure under GDPR, DORA and NIS2. Monitoring just tells you something happened; it doesn’t actively respond to it, and that gap is where the real damage happens.
Your concerns, our answers
We’ve been hit by ransomware. Who do I call now?
Retainer customers can reach a live person on our 24/7 hotline within 30 minutes, and we open an incident management case within an hour.
Should I pay the ransom, or negotiate with the attackers?
We do not negotiate with attackers ourselves, in line with FIRST.org guidance. We help you assess your options and, if needed, bring in a trusted specialist partner who can handle negotiations within the legal framework, including sanctions screening.
We already have monitoring in place, isn’t that enough?
Monitoring alerts you to an incident; it doesn’t contain or investigate it. Our DFIR experts do both. Under NIS2, you must send an early warning within 24 hours, and we help you draft that initial report, as well as your notifications under GDPR and DORA.
You have cyber insurance and monitoring in place.
But what happens when an incident strikes?
Already run an internal SOC? We act as your Tier 3 escalation and forensic surge capacity, so you don’t have to do it yourself.
Choose your Services
Readiness assessments, response playbooks and clear escalation contacts, backed by monthly reviews with a dedicated delivery manager, so you’re fully prepared when an incident occurs.
30-minute human response. Incident management meeting within an hour. On-site support in Belgium within 4 hours when needed, all backed by clear SLAs.
No incident response agreement in place? We can still respond to an active incident on a time-and-materials basis, with hours agreed and tracked throughout the investigation.
In-depth forensic investigation, malware analysis and attack-timeline reconstruction, including support for legal, insurance or litigation proceedings.
Breach qualification, risk assessment and support preparing your notification to the data protection authority, coordinated with your DPO and legal advisors.
Consult the frequently asked questions
With an incident response retainer, a live person answers your call within 30 minutes and we hold a remote incident management meeting within about an hour. From there, we work in parallel on containment, investigation and your regulatory notification obligations. If the situation demands it, on-site support in Belgium follows within 4 hours.
No. We can respond to an active incident on an ad-hoc basis without a retainer. A retainer gets you a documented SLA, readiness playbooks and an agreed upon contact list before a crisis, rather than during one, when each second counts.
We support you throughout: qualifying the breach, assessing the risk, and preparing what you need to notify the data protection authority within the legal deadline. The final notification decision and liability remain yours. Not sure where your organisation stands on GDPR or NIS2? See our GRC page.
We can still help, but forensic depth entirely depends on visibility: without basic endpoint and network logs, we can usually confirm that an active incident occurred, but tracing its full root cause and blast radius becomes severely limited. However, our SOC or a readiness assessment can help close that gap.
Digital Forensics & Incident Response (DFIR) is part of Continuous Operations, Approach Cyber’s pillar for ongoing vigilance and validation, alongside our SOC, Phishing & Awareness, Vulnerability & Exposure Management, Managed Firewall Services and Offensive Security teams. Continuous Operations validates, in real time, what Strategic Advice designed and Adaptive Security enforced.
TRUSTED ACROSS BELGIUM AND SWITZERLAND
Our team will help you start your journey towards cyber serenity