Service 02

Incident Response & Ransomware Negotiation

When you're breached, every hour costs you. We've been in the room before — with legal counsel, the board, and the threat actor. We run parallel tracks: technical containment and, when necessary, negotiation.

Why It Matters

Most IR firms investigate. We also negotiate.

The standard incident response model is sequential: investigate the intrusion, contain the damage, then figure out what to do about any ransom demand. That model was built for a different era. Modern ransomware operations are sophisticated businesses. The threat actor is negotiating while you're still trying to understand the scope of the breach. Running those tracks in sequence means you're always a step behind.

We run the technical and negotiation tracks simultaneously. While forensic investigation scopes the intrusion and containment work progresses, our negotiators — who understand ransomware operator behavior, their leverage dynamics, and their organizational pressure points — are managing the other side of the conversation. The two tracks inform each other in real time. What forensics finds about dwell time and data exfiltration affects negotiation posture. What negotiation surfaces about the actor's claims affects where investigation prioritizes next.

Our offensive background is a direct advantage in IR. When you've spent time building the tools and techniques these actors use, you read the forensic evidence differently. You recognize the tooling, understand the operational sequence, and can distinguish between an actor who is done and one who still has a foothold.

The median time between ransomware deployment and an organization's first substantive response action is measured in hours. Each hour of that gap translates directly to recovery cost, data exposure risk, and negotiation leverage lost. Speed is not a nice-to-have in incident response. It determines outcomes.

How We Engage

IR Retainer

A proactive relationship established before an incident occurs. Retainer clients receive priority access during active incidents, pre-approved response playbooks developed in advance for your environment, and quarterly readiness reviews that keep response plans current with your infrastructure and threat landscape. When an incident happens, we're not starting from zero — we know your environment and we're already authorized to act.

Emergency Response

Immediate engagement for active incidents, available 24 hours a day, 7 days a week. If you're mid-breach and don't have a retainer in place, reach us directly. We engage as quickly as practically possible and work alongside your existing internal or external IR teams. Emergency response is by definition reactive — a retainer removes that cost — but when it's needed, speed of mobilization matters.

Incident Types

From active ransomware to insider threat.

  1. 01

    Active Ransomware

    Containment, negotiation, and recovery sequencing run in parallel. We scope the intrusion, manage threat actor communications, assess data exfiltration claims, and sequence recovery actions to minimize business disruption while forensic investigation continues.

  2. 02

    Business Email Compromise

    Forensic investigation of the mailbox environment to determine the scope of access, timeline of account compromise, and what the actor may have seen, exfiltrated, or staged. Financial exposure assessment for fraud scenarios including wire transfer manipulation and vendor impersonation.

  3. 03

    Nation-State / Advanced Persistent Threat

    Long-dwell investigations where the adversary has been present for weeks or months before detection. We scope the full timeline of access, identify every system the actor touched, assess the completeness of exfiltration, and provide attribution support where evidence permits and operational requirements demand it.

  4. 04

    Insider Threat

    Investigation designed to scope the activity of a suspected malicious or negligent insider without alerting the subject during the investigative phase. Digital forensics across endpoint, cloud, email, and access control systems to build an evidentiary record that supports HR action, legal proceedings, or regulatory disclosure.

  5. 05

    Supply Chain Compromise

    Scoping the blast radius when a trusted third party — a software vendor, managed service provider, or contractor — is confirmed or suspected to be the initial access vector. Assessing which of your systems were exposed, what data or credentials may have been visible, and how to re-establish trust boundaries with affected third parties.

How We Work

Structured response under unstructured pressure.

Every incident response engagement moves through the same underlying structure: triage to establish scope and severity, scope definition to bound the investigation, containment to stop the bleeding, investigation to understand what happened and what was accessed, and recovery to return to operations on a defensible footing. The order and emphasis shift depending on what we find — but the structure is never abandoned just because the situation is chaotic.

We integrate directly with your legal counsel, communications team, and executive leadership from the first hour. Incident response is not a purely technical exercise. Decisions about notification obligations, public communications, and regulatory disclosure have to be made under pressure and with incomplete information. We support those decisions with the technical facts as we have them, clearly communicated in terms that are useful to non-technical decision-makers.

When ransomware negotiation is required, it runs as a parallel workstream managed by operators with direct experience of how ransomware groups structure their demands, their proof-of-data claims, their negotiation timelines, and their actual behavior when negotiation goes outside their expected parameters. Negotiation posture is informed continuously by what the technical investigation finds — the two streams are never siloed from each other.

Throughout the engagement, we produce structured updates at a cadence matched to the pace of the incident. The board and legal team get what they need to make decisions. The technical team gets what they need to execute. Documentation is built from the first hour, because the forensic record of the incident will matter long after the incident itself is resolved.

Get In Touch

Active incident or building an IR retainer?

If you're managing an active incident, use the email address below — it's monitored continuously. If you're thinking ahead and want to establish a retainer relationship before you need it, start with the form and we'll schedule a conversation about your environment and response requirements.

Start a Conversation →

For active incidents: hello@unknown2.com