
Incident response & forensics
When Crisis Strikes, Call the Triad.
A breach is not a technical problem. It is a business crisis. Every minute of delay increases cost, damage, and regulatory exposure. We contain threats fast, preserve evidence forensically, and guide you through recovery with precision.
- Retainer clients
- ≤ 2 hours
- Non-retainer
- ≤ 6 hours
Priority response targets. Timelines depend on client cooperation and incident complexity.
The regulatory clock
The first 72 hours
Hour 0
You become aware
Call or WhatsApp the Triad line. Preserve logs; don’t wipe or reboot affected systems.
≤ 1 hour
Retainer activation
IR team mobilization for retainer clients, per the SLA template.
≤ 6 hours
CERT-In report
Reportable incidents must be notified to CERT-In within 6 hours of awareness.
≤ 72 hours
Data Protection Board
Where personal data is involved, the breach is notified within the timeline prescribed under the DPDP Rules 2025.
The Triad IR Protocol
Six phases · scroll sideways ›
1
Retainer phase
Preparation
- IR plan development
- Playbook creation
- Contact tree establishment
- Tabletop exercises
2
Phase 2
Detection & Analysis
- Hotline activation
- Initial triage & scoping
- Evidence preservation
- Threat actor profiling
3
Phase 3
Containment
- Short-term: stop the bleeding
- Long-term: secure the perimeter
- Communication protocol activation
4
Phase 4
Eradication
- Root cause elimination
- Backdoor removal
- Malware analysis & cleaning
5
Phase 5
Recovery
- System restoration
- Validation testing
- Return-to-operations
6
Phase 6
Post-Incident
- CERT-In notification within 6 hours of awareness of a reportable incident
- Data Protection Board breach notification (where personal data is involved)
- Lessons learned workshop
- Hardening recommendations
- Insurance documentation support