Home / Solutions / Incident Response

Investigation, containment and recovery

Security Incident Response

Understand what happened and organize the response.

Taura supports your team in investigating, containing and recovering from incidents. We assess the reach, preserve evidence and help decide what to do first.

What is incident response?

Incident response is the process of investigating an attack or data breach, containing its effects and restoring services while preserving evidence. Taura can support triage, evidence analysis, containment and recovery. Notifying regulators and data subjects is assessed together with the company's technical, legal and privacy teams.

NIST SP 800-61Digital forensicsANPD
Context

Situations where we can help

Suspected unauthorized accessInvestigation of the signs, affected systems and reach.
Ransomware or outageContainment and assessment of recovery options.
Compromised credentials or cloud accountsAnalysis of the attacker's actions and steps to limit the damage.
Suspected fraud in transactional flowsTechnical investigation of the logs and the scenario.
Scope

How the response unfolds

TriageFirst understanding of the event and the priorities.
ContainmentMeasures to limit the effects without losing evidence.
InvestigationTimeline and reach based on the available data.
RecoveryRemoving the causes and restoring services.
CommunicationTechnical input for the decision-makers.
Post-incidentRecord of the findings and what to do so it doesn't happen again.
Method

Preparation before the incident

Response planRoles, contacts and severity criteria.
ExercisesSimulations to test the plan.
ReviewLogs, backups and critical access checked.
FAQ

Frequently asked questions

Should I shut down the systems?

It depends on the scenario. Shutting down can stop the attack, but it also wipes evidence that exists only in memory. Before any irreversible step, bring in the people in charge and assess the containment options.

Do I need to notify the ANPD or the Central Bank of Brazil?

It depends on the incident, the data affected and how the rules apply to the company. For personal data, under the LGPD (Brazil's General Data Protection Law), the general rule considers relevant risk or harm and sets three business days. Regulated institutions also have their own obligations.

How do we prepare?

With a plan that defines roles, contacts, severity criteria and procedures, tested through exercises. Active logging, tested backups and MFA on critical access help a lot when something happens.

Leave your details and a Taura expert will get in touch to talk about what your business needs.

How can we help?
How did you hear about Taura? optional
WhatsApp