HOME / SERVICES / FIRST RESPONSE
FIRST RESPONSE
First Response is NEWORDER’s emergency cyber incident service. When something is happening in your environment right now, we triage what it actually is, contain the attacker’s access, and stabilise your systems, while preserving the evidence you will need afterwards. One call, any hour, any day of the year.
24/7/365 INCIDENT RESPONSE
IF IT IS HAPPENING NOW, CALL FIRST. READ SECOND.
First Response is what happens in the hours between discovering an incident and understanding it. It is a separate discipline from digital forensics. Forensics answers what happened and proves it. First Response stops the bleeding while the answer is still unknown.
Most damage in a cyber incident is done in the window where nobody is sure who is in charge. Systems get rebuilt, evidence gets destroyed, attackers keep their access, and the organisation makes irreversible decisions under pressure with incomplete information.
NEWORDER operators take that pressure off you. We triage what is actually happening, contain the attacker’s access, stabilise the environment, and preserve the evidence you will need later, in that order, with someone senior on the line the whole way through.
You do not need to be technical to make this call. You need to make it early.
WHAT TO DO IN THE NEXT TEN MINUTES
- Do not shut anything down. Powering off destroys memory evidence and can trigger encryption routines that have not yet run.
- Do not reimage or wipe. The affected machine is the evidence. Rebuilding it removes the only record of what happened.
- Disconnect from the network if you can. Unplug the cable or disable the wireless adapter. Isolation is not the same as switching off.
- Stop paying, stop replying. If this is a payment fraud or an email compromise, halt outbound payments and do not continue the thread with the attacker.
- Write down what you know. Time you noticed, who noticed, what they saw, what has been done since. This becomes the first entry in the incident record.
- Call us. +27 12 880 5830. Bring the person who noticed it to the call.
CORE CAPABILITIES
- Emergency Triage — Rapid determination of what is actually happening, how far it has spread, and whether the attacker still has access. Usually within the first hour of the call.
- Containment and Attacker Eviction — Cutting off access paths, disabling compromised accounts, isolating affected systems, and closing the route in, done in a sequence that does not tip off the attacker prematurely.
- Ransomware Response — Encryption scope assessment, backup integrity verification, recovery path planning, and negotiation posture advice. NEWORDER helps you understand your options before anyone decides anything irreversible.
- Business Email Compromise Response — Mailbox rule and forwarding audit, session and token revocation, payment instruction verification, and identification of every account touched.
- Evidence Preservation — Containment carried out so that it does not destroy the forensic record. This is the most common failure in self-managed incident response and the hardest to undo.
- Stabilisation and Recovery — Verified clean rebuild sequencing, so that systems come back in an order that does not reintroduce the compromise.
- Notification and Obligation Support — Practical guidance on POPIA and GDPR notification duties, timelines, and what you are required to establish before you notify.
- Incident Response Retainer — Pre-agreed scope, pre-agreed rates, pre-established access, and a number that already knows who you are. The difference between a two-hour start and a two-day start.
24/7/365 Availability
Incidents do not respect business hours. In practice they surface on Friday evenings, over long weekends, and in the middle of December. The line is answered every day of the year.
An Operator, Not a Ticket
You reach someone who can make decisions, not a queue. The person who takes the first call stays with the incident.
Containment That Preserves Evidence
Speed and evidentiary integrity are usually traded against each other. Because NEWORDER runs both First Response and digital forensics, they are handled by one team with one plan and no handoff gap.
Attacker-Side Understanding
Our responders run offensive operations for a living. They know where an attacker hides persistence, which access path gets used again after the obvious one is closed, and what a real eviction requires.
Plain Language Under Pressure
Incident calls include people with no security background. Nobody on a NEWORDER incident call is left guessing what was just said or what they are being asked to decide.
OTHER SERVICES
FREQUENTLY ASKED QUESTIONS
FAQ
We think something is happening but we are not certain. Should we still call?
Yes. An uncertain call costs you a conversation. A late call costs considerably more. A large share of incidents are caught early by someone who noticed something odd and was not sure it warranted escalation.
Are you actually available at 2am on a Sunday?
Yes. NEWORDER operates 24/7/365 incident response. The number is +27 12 880 5830 and it is answered every day of the year, not routed to a voicemail box until Monday.
We are not an existing client. Will you still take the call?
Yes. We will take the call, triage the situation, and tell you honestly what you are dealing with. Engagement paperwork is handled in parallel rather than as a precondition for the first conversation.
Should we pay the ransom?
That is a business decision, not a technical one, and it should not be made in the first hour. Before it can be answered sensibly you need to know the encryption scope, whether your backups are intact and uncompromised, whether data was taken as well as encrypted, and what your insurer and legal position require. NEWORDER helps you establish all four before you decide.
How is First Response different from digital forensics?
First Response is the emergency phase: triage, containment, stabilisation, while the situation is still live. Digital forensics is the investigative phase: proving what happened, to what, by whom, to a standard that survives legal and regulatory challenge. Most serious incidents need both, in that order.
What does an incident response retainer include?
A pre-agreed scope and rate card, guaranteed response commitment, pre-established technical and contact context, and an annual readiness review. The commercial value is that the first hours of an incident go to response rather than to procurement.
Do we have to notify the Information Regulator?
POPIA requires notification where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person. Establishing whether that occurred is part of the response. NEWORDER helps you determine what you are obliged to report, and what you must establish first, so notification is accurate rather than premature.
Our IT team has already started rebuilding the affected server. Is that a problem?
It complicates things, but it is recoverable. Stop the rebuild now, preserve whatever remains including backups, snapshots, and any logs still in retention, and tell us exactly what has been done. Being straight with us about actions already taken is far more useful than a tidy version of events.
TAKE ACTION
DO NOT WAIT UNTIL MONDAY
Cyber incidents get more expensive every hour they run unmanaged. If something is happening in your environment right now, call NEWORDER. If you are reading this because you have realised you have no plan, ask us about an incident response retainer before you need it.