Security incident

Think you've been breached?

Call us. If you would rather type, the form below is four fields — we do not need your org chart to start helping.

Call first — it is faster than typing(210) 802-4498

Monitoring pages an on-call engineer directly, day or night. If you reach voicemail, send the form as well — it alerts a different route.

We'll only use this to respond to your request. No newsletters unless you ask. Privacy policy.

You do not have to be a client. If you are in trouble and we are not the right people, we will tell you who is — a breach is not a sales opportunity.

Before you do anything else

  • Do not wipe or re-image the machine — that destroys the evidence needed to work out what was taken
  • Disconnect it from the network, but leave it powered on
  • Do not pay anything, and do not reply to the attacker
  • Change passwords from a DIFFERENT device, starting with email and banking
  • Write down what you saw and when — timestamps matter later
  • If regulated data may be involved, notification clocks may already be running