24/7 Emergency Response — Active Now

Breached?
Don't Panic.
Call The Unit That's Done This 1,000 Times.

Texas-based incident response. AT&T vendor for TX state IR. SDVOSB-certified. No retainer required for active incidents. 24/7/365 — including weekends, holidays, and 2am.

📞 (800) 955-2596
Direct IR line. Answered live, every call, every hour.
Response SLA
30 Minutes
Availability
24/7/365
Retainer Required
No — ever
Credentials
SDVOSB · AT&T Vendor
Can't Call Right Now?

Submit an emergency intake.
We'll call you back immediately.

Fill out the form and we call your number within minutes. If you can call — call. It's faster. But if you're in a meeting or can't speak freely, this gets us moving.

📞 (800) 955-2596

Prefer to call? That line is answered 24/7 by a human.
No voicemail. No phone tree. No next-business-day callback.

Goes directly to John. Not a ticket queue.

First 60 Minutes

What happens the moment we're on the call.

The first hour defines how bad this gets. Every minute of unchecked attacker dwell time is additional encrypted data, additional exfiltration, additional blast radius. Here's what our team does immediately.

01
Scope
Determine the initial blast radius. Which systems are confirmed affected vs. suspected? Ransomware deployment or silent exfil? Active attacker or completed campaign? Scope determines every decision that follows.
02
Isolate
Network isolation of affected systems — unplug ethernet, disable Wi-Fi, cut VPN. Block known C2 channels. Prevent lateral movement to file shares, backups, and adjacent systems. We tell you exactly what to cut and what to leave running.
03
Preserve
Forensic imaging of affected systems before remediation. Volatile memory capture. Chain of custody documentation for legal, insurance, and regulatory proceedings. Evidence destroyed in the first hour is gone forever.
04
Notify Counsel
Legal privilege guidance on breach communications. Attorney-client privilege over IR findings where applicable. Breach notification clock identification — HIPAA, CJIS, CMMC, TX AG. Say nothing until you know what you're required to say.
05
IOC Hunt
Indicator of Compromise sweep across endpoints, logs, and network telemetry. Identify attacker tooling, persistence mechanisms, and additional backdoors. Eradication without IOC hunting leaves the attacker behind.
06
Eradicate
Remove attacker tooling and persistence from every confirmed system. Reset all compromised credentials. Rebuild from clean images where necessary. No shortcuts — partial eradication means a second breach.
07
Recover
Restore systems to production from verified clean backups under enhanced monitoring. Validate backup integrity before restoration. Confirm no reinfection on restored systems. Recovery without monitoring is just waiting for round two.
08
Post-Mortem
Full incident report: root cause, attack timeline, forensic findings, regulatory impact. Prioritized hardening roadmap. Insurance and legal documentation package. Every incident becomes institutional knowledge, not just a bad memory.
Scenarios We Handle

Which situation matches yours?

All of these qualify for immediate 30-minute response. No retainer, no pre-qualification.

This is a time-critical situation. Do NOT pay yet and do NOT wipe machines. First priority: determine if backups are intact and not also encrypted. We'll assess the ransomware variant, check for known decryption tools (many exist for older strains), determine whether exfiltration occurred before encryption, and evaluate your actual options — which may include recovery without paying. We coordinate with FBI and CISA when warranted. If payment is ultimately necessary, we advise on negotiation, verification, and legal coordination. Most ransomware victims who pay are re-targeted within 12 months. We work through root cause so that doesn't happen.

Silent exfil is often worse than ransomware because there's no visible indicator — just the quiet draining of IP, customer data, or regulated records. Common triggers: SIEM alert on large outbound transfer, an employee noticing unusual file access, or a third party reporting your data appeared somewhere it shouldn't be. We analyze network logs, endpoint telemetry, and access records to determine what was taken, when, how, and by whom — and whether this is still ongoing. Exfil with no ransomware deployment may indicate a threat actor still in the environment. Scope and containment come first.

BEC is the highest-revenue cybercrime category per FBI IC3 for the past five consecutive years. Common pattern: attacker compromises or impersonates an executive email, redirects a wire transfer. If the transfer occurred within the last 24–72 hours, FBI can sometimes claw back funds via SWIFT — this requires immediate action. We coordinate incident documentation for FBI IC3 report, preserve email headers and authentication records, assess whether the mailbox was actually compromised (vs. domain spoofing), determine attacker access scope, and lock down the email environment. Time is the critical variable: call us immediately before contacting the bank.

Insider threats — whether malicious or negligent — require careful handling. A rushed deprovisioning or confrontation without documentation creates legal risk. We forensically image the relevant devices and accounts before HR or legal action, establish a complete access and data transfer timeline, identify what was taken or compromised, and provide chain-of-custody documentation appropriate for legal proceedings. This applies to departing employees taking IP to a competitor, disgruntled employees with elevated access, or authorized users who accidentally exposed data. We work in coordination with your legal counsel — not around them.

OT and ICS incidents are categorically different from enterprise IT breaches. SCADA networks were designed for reliability, not security — they were never meant to be internet-connected, but most now are. When you see unexpected PLC behavior, HMI anomalies, historian data inconsistency, or unusual network traffic between OT and IT zones, treat it as an active intrusion until proven otherwise. Colonial Pipeline's 6-day shutdown wasn't caused by ransomware on the OT network — it was caused by a business decision made in uncertainty. We scope OT/IT convergence exposure, assess whether OT systems are actually compromised or whether the IT breach is being contained away from operational systems, coordinate with TSA pipeline security directives and CISA ICS-CERT, and support safe continued operations during investigation. Do NOT take operational systems offline without IR guidance — the consequences of incorrect isolation in OT environments can be severe.

A breach discovered weeks after it occurred may mean your regulatory notification clock is already running. HIPAA requires notification within 60 days of discovery — OCR interprets "discovery" as when you knew or should have known. CJIS incidents require notification to the FBI CJIS Division and state CSO within specific windows. CMMC Level 2 incidents require reporting to DoD and may trigger contract implications. We document the discovery timeline, assess what must be reported, to whom, and by when, prepare the technical components of the notification package, and support legal and compliance counsel in meeting deadlines. Missing regulatory reporting windows creates compounding liability.

Right Now — Before You Call

What to do (and not do) in the next 10 minutes.

The wrong moves in the first few minutes destroy forensic evidence, spread the infection, and reduce your options. The right moves take under 5 minutes.

DO NOT
🚫
Do NOT pay the ransom yet
Payment doesn't guarantee decryption, often funds re-targeting, and has legal implications. We'll evaluate actual recovery options first.
🚫
Do NOT wipe affected machines
Wiping destroys forensic evidence needed for insurance claims, legal proceedings, and root-cause analysis. Preserve first, remediate after.
🚫
Do NOT shut down servers
Shutdown destroys volatile memory — RAM contains running processes, encryption keys, and attacker tooling that's invaluable for forensics. Isolate from network instead.
🚫
Do NOT post on social media
Public disclosure before you understand scope triggers regulatory clocks, alerts the attacker, and can violate insurance policy terms. Keep it internal until we advise.
DO
DO disconnect affected machines from the network
Unplug the ethernet cable. Disable Wi-Fi. Do NOT shut down. Isolation stops lateral spread while preserving volatile memory for forensics.
DO photograph ransom notes and error screens
Use your phone to photograph anything on screen. Ransom notes often contain the ransomware variant, which determines your decryption options.
DO document the timeline of what you noticed
Write down: when you first noticed, what you saw, what actions were taken, and by whom. This becomes your incident timeline for insurance and legal.
DO call us — (800) 955-2596
Answered live, 24/7. Tell us what you're seeing. We'll tell you exactly what to do in the next 30 minutes while we mobilize a response.
Why CoreRecon

Texas IR team. Not a national help desk.

National MSSPs staff overnight calls with Tier 1 analysts following playbooks. We're a Texas-native IR team with 30 years of combined experience — we've been on both sides of these incidents.

🏛️
AT&T TX State Vendor
Approved vendor for Texas state incident response engagements. Established relationship with TDEM, CISA Region 6, and FBI Dallas Cyber Division for coordinated responses.
🎖️
SDVOSB Certified
Service-Disabled Veteran-Owned Small Business. Eligible for SDVOSB set-asides. Government and defense contractor IR engagements handled with appropriate clearance coordination and reporting workflows.
🗺️
TX-Native Response Reach
Physical response capability across Travis, Harris, Bexar, and Dallas counties. Remote response anywhere in Texas within 30 minutes of call initiation. No 3rd-party subcontractor dispatch.
⚖️
Forensic & Legal Handoff
Established chain-of-custody workflow. Forensic imaging with documentation admissible in civil proceedings. Pre-built coordination templates for cyber insurance, legal counsel, and law enforcement.
🧠
30-Year Team Experience
Combined team experience in network security, digital forensics, and incident response. Sectors: healthcare, municipal government, oil & gas, defense contractors, and law firms. We've seen your scenario before.
📋
Regulatory Compliance IR
HIPAA breach notification, CJIS incident reporting, CMMC breach documentation, and Texas AG notification support. We know what the regulators require and help you meet it on deadline.
The IR Timeline

What the next 7 days look like.

From the moment you call to full recovery and hardening recommendations. No ambiguity, no "we'll assess and get back to you." This is how we run it.

1
0–30 Minutes
Initial Triage Call
You're on the phone with an analyst. We scope the incident, determine attack type, walk you through immediate isolation steps, and build the preliminary incident timeline. We also assess whether law enforcement notification is warranted.
2
30 Minutes – 2 Hours
Active Containment
Remote or on-site containment of affected systems. Forensic imaging begins. C2 channels blocked. Network segmentation assessed. Backup integrity verified. Blast radius confirmed. Regulatory clock assessment completed.
3
2–24 Hours
Eradication
Attacker tooling and persistence mechanisms removed. Compromised credentials reset. Affected systems remediated or rebuilt from clean images. Backups validated. Preliminary forensic analysis delivered.
4
24–72 Hours
Recovery
Systems restored to production. Operations resumed under enhanced monitoring. Regulatory notification packages prepared for legal review. Insurance claim documentation completed.
5
Week 2
Post-Incident Report + Hardening
Full post-incident report: root cause, attack timeline, forensic findings, recommendations. Prioritized hardening roadmap delivered. Ongoing monitoring options presented — so this doesn't happen again.
What Attackers Count On

207 days. That's how long you've had them.

IBM X-Force puts average attacker dwell time at 207 days — nearly seven months of undisturbed access before detection. Attackers count on three things going their way.

The 207-Day Window

207 days of undetected dwell time means your data has been mapped, your credentials harvested, your backups inventoried, and your blast radius maximized — all before you know anything happened. The ransomware note isn't the beginning of the attack. It's the end.

MSPs Without IR Muscle

Most managed service providers are not incident response firms. Their playbook is to re-image machines and restore from backup — which works for a hard drive failure, not an advanced persistent threat. Without forensics, root cause stays unknown. The attacker comes back through the same door in 90 days.

Legal-First Response

Organizations that call their lawyer before they call IR lose 12–18 hours getting clearance to act. Legal counsel is essential — but they're not trained to scope incidents or contain attackers. The attorney needs the technical findings; the technical team needs to be moving while the attorney advises. These tracks run in parallel, not sequentially.

IR Retainer Options

No retainer required. But having one changes the math.

We respond to active incidents without a retainer — always. But organizations with a pre-negotiated retainer get priority scheduling, discounted rates, and a team that already knows their environment.

Sentinel IR
$5,000
Annual prepaid hours
  • 8 prepaid IR hours
  • 30-min response SLA
  • Remote containment & triage
  • Priority case queue
  • Rollover unused hours
  • Pre-engagement environment intake
Best for: small businesses, law firms, credit unions
Most Popular
Fortress IR
$15,000
Annual prepaid hours
  • 30 prepaid IR hours
  • 30-min response SLA + on-site option
  • Remote + on-site containment
  • Forensic imaging included
  • Insurance coordination support
  • Quarterly environment review
  • Rollover + annual reset
Best for: healthcare, municipalities, defense contractors
Command IR
$50,000
Annual prepaid hours
  • 120 prepaid IR hours
  • Named analyst assignment
  • 24/7 direct analyst cell
  • Full forensic + legal package
  • Tabletop exercises included
  • OT/ICS response capability
  • Regulatory notification drafting
  • Priority scheduling, no queue
Best for: oil & gas operators, large municipalities, multi-site healthcare
Pay-As-You-Go Emergency Rate

No retainer? No problem. Active incident response billed at $350/hr for remote and $450/hr for on-site response. Minimum 4-hour engagement. SOW signed after scope call — we move before paperwork is fully executed in active breach scenarios.

No-Retainer Crash Response

Call (800) 955-2596. We triage the incident on the first call at no charge. If you need IR engagement, we scope and quote within the first 30 minutes. No retainer. No prior relationship required. Active breach = call now.

After We Stop the Bleeding

We monitor so it doesn't happen again.

Most organizations who experience a breach are breached again within 12 months through the same or adjacent vector. Our managed SOC catches what your team misses — 24/7, at $89–$129/endpoint. No enterprise contract. Month-to-month.

See ongoing monitoring plans →

Or start with the free security assessment — delivered in 14 days, no credit card.

Highest-Intent Free Tool
Build Your NIST 800-61r3 Incident Response Plan — Free
8 inputs. Custom IR plan with regulation-specific notification timelines, containment playbooks, and pre-populated contact trees. Audit-ready, email-gated PDF.
Generate My IR Plan →
Free Preparedness Tool
Run Your Ransomware Tabletop Exercise Before You Need IR
Custom 8-inject scenario. 5 inputs. Board-ready runbook in 2 minutes. Required by cyber insurers. Free.
Generate Runbook →