1. Home
  2. Services
  3. Incident response and fraud takedown
Intelligence and response · IR-04

Incident response and fraud takedown

Fast containment, clear communication and a documented closure.

We support the organisation during a security incident: containment, eradication and recovery, with clear prioritisation criteria and communication that management can understand. We also handle the takedown of fraudulent domains, websites and profiles impersonating the company, coordinating with registrars, hosting providers and INCIBE-CERT, and prepare the documentation for mandatory notifications.

  • DeliveryRemote or on-site
  • AvailabilityOn demand
  • ComplementsIR-01 and IR-02

In a nutshell

  • DeliveryRemote or on-site
  • AvailabilityOn demand
  • ComplementsIR-01 and IR-02
  • Takedown and notificationsEvery finding is reproduced and validated by hand, with reproducible evidence.
  • Results in DARKFORGEFindings, evidence and reports in your private space, in real time.

What's included and what you receive at the end.

An engagement with a scope, a schedule and a final report, designed to answer a specific question. Everything in the report has been discussed beforehand: the final document confirms, it does not reveal.

What's included

  • Triage, containment and eradication
  • Takedown of fraudulent domains and sites
  • Coordination with INCIBE-CERT, providers and registrars
  • Support with regulatory notifications (GDPR, NIS2, DORA)

Deliverables

  • Incident report
  • Evidence dossier
  • Closure report
Notification deadlines we help you meet
  • GDPR: notification to the Spanish data protection authority (AEPD) within 72 hours and communication to those affected when the risk is high
  • NIS2: early warning within 24 hours, notification within 72 hours and final report within one month
  • DORA: initial notification within 4 hours of classifying the incident as major, intermediate report within 72 hours and final report within one month
Indicative deadlines: the specific obligation depends on the type of entity, the incident and the applicable regulation.

How we work

The same method on every project, so results are comparable with each other and over time. Every finding is scored with CVSS and put in context according to the affected asset, how easy it is to exploit and the real impact on the business.

Phase 1

Scope and rules of engagement

Objectives, assets, time windows, emergency contacts and formal written authorisation.

Phase 2

Reconnaissance

We map the attack surface and inventory the assets, both known and discovered.

Phase 3

Analysis and controlled exploitation

We validate every finding manually, with no denial of service and no unnecessary data extraction.

Phase 4

Report and presentation

An executive report for management and a technical report for the team, with a prioritised remediation plan.

Phase 5

Retest and follow-up

We verify the fixes and update the status of every finding in DARKFORGE.

Guarantees across all services

Authorisation and contract

No test starts without express written authorisation and a signed scope.

Confidentiality

Non-disclosure agreement, safekeeping of information and secure deletion at closure.

No impact on operations

Agreed time windows, no denial of service and a permanent emergency contact.

Data in the European Union

Evidence and reports hosted and processed in the EU, on our own platforms, aligned with NIS2, DORA, ENS, ISO/IEC 27001 and GDPR.

Related services.

Services are combined into annual programmes with a single point of contact and a shared calendar, and any of them can be contracted as PTaaS with continuous testing and unlimited retesting.

Let's talk about your security.

Request a no-obligation initial assessment and we will propose the service that best fits your organisation.

Talk to usCall