Emergency, call now

Incident Response · 24/7

You got hacked. Goldoak takes over.

Ransomware, encrypted servers, an attacker in your network: when every minute counts, a senior analyst starts containment immediately. Remote, around the clock, with a single call.

Emergency hotline for businesses only. Billed from the first minute. Available 24/7/365.

If you are under attack right now

  1. Call, do not email.

    During an active attack every second counts. The hotline is staffed around the clock.

  2. Do not power off affected systems.

    Disconnect them from the network. Powering off destroys traces in memory that we need for the analysis.

  3. From here, Goldoak takes over.

    We tell you on the phone what to do next and start the initial analysis.

How an engagement works

No two attacks are alike. The process is. That is how we stay in control, even when everything at your end is on fire.

  1. Initial analysis and containment

    As soon as your emergency request comes in, a senior security analyst starts the initial analysis remotely. The threat is isolated first so the attacker cannot spread further.

    Immediately · Remote

  2. Establish visibility

    We roll out Spectacles across your fleet to see where the attacker is, what they are doing and which systems are affected.

    Hours to days

  3. Damage assessment and forensics

    How did the attacker get in, since when, what was exfiltrated? We preserve evidence in a court-admissible way and deliver the facts you need for insurers, authorities and customers.

    In parallel with containment

  4. Recovery

    Rebuild systems cleanly, reissue credentials, bring operations back up. In an order that does not invite the attacker back in.

    Days

  5. Remediation and hardening

    Close the gap the attacker used, and the next five along with it. So that this incident stays the last one.

    After the incident

Why Goldoak

Investigators, not salespeople

Our founder spent nine years with the police, most recently as a detective chief inspector in the Cybercrime Competence Center, and then supported hacked companies at one of the big audit firms.

Our own platform

We do not depend on the tools you happen to have. We bring Spectacles and roll it out in hours. That gives us visibility where there was none before.

Defend while it is happening

We do not just clean up afterwards. With visibility across the whole fleet we detect and isolate attackers while the attack is still in progress.

One call, one team

Containment, forensics, recovery and hardening from a single source. No three vendors blaming each other.

After the incident

The attack is over, the work is not. What we do for you after the acute phase.

  • Post-incident forensics: full report on entry point, spread and data exfiltration.
  • Support with notification duties (Swiss FADP) and communication with insurers and authorities.
  • Prioritised action plan you can hand straight to your IT partner.
  • Optional: Spectacles stays in operation so that any return attempt is spotted immediately.
  • Optional: penetration test or security health check to find the remaining gaps.

Frequently asked questions

What does an incident response engagement cost?

The emergency hotline is billed from the first minute, the engagement by effort. We tell you on the phone what to expect before we start. If you have cyber insurance, we clarify cost coverage with you.

Do I have to be a Goldoak customer?

No. Most emergency engagements start with a call from companies that did not know us before. Spectacles customers have the advantage that we have visibility immediately and do not need to roll out first.

Do you work remotely or on site?

Initial analysis and containment happen remotely because that is fastest. When necessary, we come on site. We are based in Emmenbrücke near Lucerne and work across Switzerland.

Should I pay the ransom?

We will not make that decision for you, but we give you the facts for it: what is actually encrypted, which backups exist, how credible the threat is. In most cases there is a better way.

I am not sure it is an attack. Should I still call?

Yes. A false alarm costs you a short phone call. A missed attack costs you the company. If it is not urgent, you can also book a consultation.

Active incident? Call now.

Around the clock, 365 days a year. Disconnect affected systems from the network, do not power them off, and call us.