Let's talk about your project
DOKI / Cybersecurity

Cybersecurity · Incident response

When a breach is suspected we first establish the facts, then stop the spread, then bring systems back safely. Every step is time-stamped; at the end you receive a report explaining what happened and what must change.

  • Incident triage
  • Containment plan
  • Recovery plan
  • Incident report
01 / What this service includes

An ordered plan instead of panic.

01

First assessment

We establish what is affected, whether the incident is still ongoing and which evidence must be preserved. A hasty restart often wipes the most valuable trace.

02

Containment

Affected accounts are disabled, suspicious connections cut and leaked keys rotated. The aim is to shrink the attacker's room to move while keeping your business running as far as possible.

03

Recovery and report

Systems return from backups verified to be clean, or by rebuilding. The incident report contains the timeline, the root cause and the steps to prevent a repeat.

02 / How it works

The four stages of a response

The stages run in order; the next one does not begin until the previous is complete, and every transition is recorded.

  1. Detection and assessment
  2. Containment
  3. Eradication and recovery
  4. Report and lessons learned
03 / Scope

Let's define the scope together.

We clarify the scope, deliverables and acceptance criteria together in the first meeting. The written quote lists that scope item by item; if the scope changes, the quote is updated as a new version.

Only explicitly authorized assets and agreed scope are assessed.

Deliverables

  • 01Incident triage
  • 02Containment plan
  • 03Recovery plan
  • 04Incident report
04 / Process

How we move forward, step by step.

Each step ends with something concrete in your hands; we move on with your approval.

  1. 01

    Assessment

    We assess the current state against agreed criteria and note gaps with evidence.

  2. 02

    Containment

    We isolate the affected systems and stop the incident from spreading.

  3. 03

    Recovery

    We bring systems back from a safe point and verify the return to normal step by step.

  4. 04

    Reporting

    We share what was done, the result and the next step in a plain report.

05 / Decision details

What to know before you ask for a quote.

What is included, what we need from you, timing and payment, all in one place. The exact scope and price are set in the written quote.

Included

  • Clarifying the incident, stopping the spread and restoring your systems.
  • Incident analysis (forensics) and a final report.
  • Every step is logged with a timestamp.

What we need from you

  • Do not delete logs or rebuild the affected systems.
  • Authorised access to the affected systems.
  • What was noticed, and when.

Timing and delivery

  • The scope and duration of the response are agreed in writing in the first call.

What sets the price

  • An annual retainer or a one-off emergency response.
  • How long the response takes and how many systems are affected.
  • We respond to every request within 12 hours.
  • Meetings are held in Turkish; correspondence and deliverables are handled in the language of your choice with translation support.
  • We work in person in Istanbul and remotely across Türkiye and worldwide.
06 / FAQ

The questions on your mind.

Tell us what you need; we will define the scope together.

Tell us about your project
How soon will I hear back after applying?

We work 24/7; every request gets a reply within 12 hours at the latest. The scope and duration of the response are agreed in writing in the first call.

Is permission needed before testing?

Yes. Only systems you are authorised for and have approved in writing are assessed.

Will testing affect my live system?

Scope, time window and methods are agreed in advance; risky steps require your separate approval.

Let's begin

Let's talk about your project.

Tell us what you need; we will define the scope together.