24/7 incident response
24/7 Incident Response, New York
Round-the-clock incident response across the five boroughs, Westchester and Long Island. Manhattan on-site dispatch, with remote preservation of cloud tenants and endpoint telemetry starting on the initial call.
The engagement
What the New York Incident Response engagement covers
In a New York incident, the first few hours decide what the record looks like. Endpoint EDR telemetry commonly rotates on a 30 to 90 day cycle. Cloud mailbox audit logs default to 90 or 180 days depending on tenant licensing. Slack and Teams retention varies widely by tenant configuration. If preservation is not in motion by the time the incident response engagement letter is signed, meaningful portions of the record can age out before the analysis begins.
The engagement starts with a triage call to the Manhattan intake at (212) 561-5860. Remote preservation of the affected tenants (Microsoft 365, Google Workspace, Okta or Entra ID, EDR consoles) is initiated on that call. On-site examiners are dispatched into Manhattan, Brooklyn, Queens, Bronx, Staten Island, Westchester and Long Island for the evidence that has to be collected in person.
The work is scoped to answer the specific incident questions counsel and the CISO actually need answered: was there unauthorized access, when did it start, what was accessed, was anything exfiltrated, is the actor still in the environment, and what is the safe path to eradication and recovery. The technical timeline is written to feed New York SHIELD Act and NYDFS 500.17 notification analysis without generating premature conclusions.
Scope
Triage and preservation
Immediate remote preservation of cloud tenants and EDR telemetry. Endpoint isolation via the client's EDR console where the environment supports it. Preservation of identity-provider logs (sign-in, audit) and email gateway logs.
Cloud tenant analysis
Microsoft 365 sign-in and audit log analysis (Unified Audit Log, Azure AD sign-in and audit logs), Google Workspace login and admin audit analysis, mailbox rule and delegation analysis, OAuth application consent grants, and inbox forwarding to external addresses.
Endpoint and identity
EDR telemetry analysis (CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, Sophos, Palo Alto XSIAM), lateral movement analysis, credential-theft analysis (LSASS access, DPAPI, Kerberos ticket activity), and persistence analysis (scheduled tasks, services, registry run keys, WMI event subscriptions).
Ransomware and extortion
Ransomware family identification, encryption scope analysis, decryption feasibility review, exfiltration assessment, and threat-actor communication support coordinated with counsel. GDF does not itself negotiate ransom; where negotiation is undertaken by an outside specialist, GDF supports the technical side.
Business email compromise
Timeline reconstruction from tenant audit logs, identification of the initial-access vector, identification of malicious inbox rules and OAuth consent grants, review of downstream financial instructions, and identification of secondary compromised accounts.
Eradication and recovery support
Written remediation plan with control owner, eradication step, verification step and recovery sequencing. Post-incident hardening recommendations prioritized against what the incident actually exposed, not against a generic maturity model.
Evidence commonly reviewed
Evidence reviewed
- Cloud tenant audit logs (M365 UAL, Azure AD, Google Workspace admin audit)
- EDR telemetry (process, network, file, module events)
- Identity provider logs (Okta system log, Entra ID sign-in and audit logs)
- Email gateway logs and message tracking
- Ransomware payloads and threat-actor communications
- Network flow data and firewall logs where available
What you receive
Deliverables
- Written technical timeline of the incident
- Affected-data assessment feeding counsel's notification analysis
- Written remediation plan with control owner and verification step
- Post-incident report suitable for the board committee that receives the CISO report
- Where the matter reaches litigation or regulatory action, an expert-report-ready record of the technical work
Engagement workflow
How the engagement runs
First-call triage
On the initial call the engagement is stood up with a written incident-response engagement letter, a designated case lead on both sides, and an out-of-band communication channel (typically Signal for principal contact plus a separate collaboration workspace for the response team). Remote preservation of cloud tenants and EDR telemetry begins on the call; on-site dispatch to the New York City metro is scheduled where the incident requires it. Where counsel is retained, the engagement is structured to preserve applicable privilege.
Preservation and containment
Preservation is prioritized against the systems most likely to lose the record: EDR telemetry windows (Defender for Endpoint, CrowdStrike, SentinelOne), M365 unified audit logs, cloud audit logs (CloudTrail, Azure Activity, GCP Cloud Audit), authentication logs, and any short-retention security data. Containment is coordinated with the covered entity's own IT and security team; where the environment lacks the internal capacity to contain, the engagement scope is expanded to cover containment directly, and the containment steps and their timestamps are captured for the record.
Forensic analysis and reconstruction
Forensic analysis reconstructs the incident along four axes: initial access, execution, lateral movement and exfiltration or impact. Evidence is drawn from EDR telemetry, host artifacts (event logs, MFT, registry, prefetch, USN journal, jump lists, browser artifacts), memory where captured, cloud audit logs, authentication logs and network telemetry where available. Findings are written contemporaneously so the technical record is durable regardless of who is on the response call at any given hour.
Affected-data assessment
Where the incident may have touched personal information, an affected-data assessment is prepared to be a usable input to counsel's notification analysis under NYDFS 500.17, the New York SHIELD Act (899-aa) and any applicable federal or state requirement. The assessment separates observed fact (what data was demonstrably accessed or exfiltrated) from inference (what data may have been accessible during the incident window). The notification determination itself is a matter for counsel and the covered entity.
Remediation and closeout
Remediation guidance is written with control owner, verification step and closeout criteria, and remediation status is tracked to closure. The post-incident report is written for the audience that actually reads it: an executive summary calibrated to business impact, a technical narrative that a security team can act on, an appendix of indicators of compromise and detection guidance, and a lessons-learned section that ties observed gaps to specific control improvements. Where the matter later reaches litigation or regulatory action, the technical record is prepared to be usable as expert-report input.
Frequently asked
Common questions on New York Incident Response
How fast can you engage on a New York incident?
Remote preservation of cloud tenants and EDR telemetry typically starts on the initial call. On-site dispatch to Manhattan, Brooklyn, Queens, Bronx and Staten Island addresses is typically within a few hours of the call. Westchester and Long Island dispatch adds travel time but is same-day.
Do you support NYDFS 500.17 72-hour notification analysis?
The technical timeline and affected-data assessment are prepared to be usable inputs to counsel's 500.17 analysis. GDF does not itself make the notification determination, which is a matter for counsel and the covered entity.
Do you support New York SHIELD Act (899-aa) analysis?
Yes. The affected-data assessment identifies what categories of information were accessible or accessed, which is a core input to the SHIELD Act notification analysis. Counsel makes the notification determination.
Do you handle ransomware negotiation?
GDF does not itself negotiate ransoms. Where a specialist negotiator is engaged, GDF supports the technical side (payload analysis, decryption feasibility, exfiltration assessment) and coordinates the eradication and recovery workstream.
Can you support litigation that follows an incident?
Yes. The incident record is documented from day one so that if the matter reaches litigation, arbitration or regulatory action, the technical facts are available in a form that can carry expert testimony. Retention of GDF as testifying expert is set by counsel.
Talk with an examiner
Discuss the matter and the next step.
Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.
24/7 hotline: 1-800-868-8189