Security · Incident Response
At the moment of a breach, a plan instead of panic
Preparation, 24/7 response and recovery for ransomware, account takeover and data leak scenarios: isolate, preserve evidence, clean, restore, report.
Response
24/7
Remote start
1 hour
Approach
Isolate · Evidence · Restore
What is done in the first hours determines the size of the loss
While ransomware encrypts the environment, the right step must be taken faster than the wrong one. The Sentinel incident response team steps in with a defined runbook: affected systems are isolated, evidence is preserved, the attacker’s access is closed, systems are restored from clean backups and the root cause is reported. The preparation package rehearses this process in advance.
Fast isolation
Separating affected systems and accounts from the network; stopping the spread.
Evidence and root cause
Preserving forensic evidence, finding the entry point, a report for legal notification.
Safe restore
Controlled restore from clean backups; hardening that prevents the same gap from being used again.
What is included
Components of the incident response service
Response plan
Roles, communication tree, decision points
24/7 call
On-duty security engineer
Isolation
Network, account and endpoint isolation
Forensic evidence
Imaging, log preservation, timeline
Cleanup
Malware removal, account resets, persistence cleanup
Restore
Controlled recovery from clean backups
Notification support
Technical report for KVKK 72-hour and customer notifications
Root cause report
Entry point, impact, preventive actions
Process
From the moment of the incident to closure
Response flow
Detection and call
Alert or notification
< 1 hour
Remote start
Isolate, prove, clean
Response by runbook
Controlled
Staged bring-up
Restore and report
Clean backup, root cause
The entry point is closed before restoring; otherwise the attacker comes back.
NIST IR · MITRE ATT&CK · KVKK notification
Packages
From preparation to ongoing service
Emergency
Immediate Response
A team that steps in at the moment of an incident, without a contract
Hourly
Per incident
- 24/7 call
- Remote start within 1 hour
- On-site team (Istanbul, Ankara)
- Root cause report
- Most popular
Preparation
Preparation + Response
Plan, drill and priority response
Annual
12 months
- Response plan and communication tree
- 1 tabletop drill a year
- Priority response and discounted hours
- Backup and isolation readiness check
Ongoing
Managed Detection
EDR/XDR monitoring together with response
Per device
12 months
- 24/7 EDR/XDR alert triage
- Automatic isolation
- Quarterly drills
- SOC as a Service integration
Frequently asked questions
The most common questions about incident response
Call 0850 885 16 44. Do not power off affected systems, disconnect them from the network; do not touch backup systems; consult us before changing passwords. The team starts remotely within an hour.
We do not recommend it; payment does not guarantee data recovery and may have legal consequences. With a clean backup, restore is usually possible; the decision is made together with your legal advisor.
It is needed for root cause analysis, insurance and legal notifications. Images and logs are taken before systems are rebuilt.
Yes. The Immediate Response package is offered without a contract; priority goes to existing preparation customers.
A tabletop drill is half a day: the scenario, decision points and communication tree are reviewed; gaps are written into the plan.
Related services
Together with incident response
Free IT Health Check
See your infrastructure through a sentinel’s eyes.
Current state assessment, risk inventory and a prioritized roadmap. No commitment.