Active incident
If you're under attack right now
Tell us in three fields. The report goes straight to our incident inbox, and a separate content-free alert is queued for our phones the moment it lands.
- Response
- Hours, CET business hours
- Coverage
- Not a staffed 24/7 SOC
- Direct
- [email protected]
Report it
Rough is fine — we would rather have three sentences now than a complete account in an hour. If you are already a customer, say so and we will pull your tenant up while we call you back.
Straight talk
We are not a staffed 24/7 SOC, and we will not pretend otherwise while you are counting minutes. We aim to respond within a few hours during CET business hours. If you need someone mobilised this minute — nights, weekends, or a national-scale event — your national CERT/CSIRT can do that and we cannot. In Sweden that is CERT-SE. Send this form as well; it costs you nothing and we will pick it up.
While you wait
Three things that are almost always right
Whatever this turns out to be, these hold. Everything beyond them depends on specifics we don't have yet, so we won't guess at them here.
Disconnect rather than shut down
Pulling a machine off the network contains it while preserving what is in memory. A shutdown throws that away — and it is often the evidence that explains how they got in. The exception is a machine visibly encrypting right now, where stopping it matters more.
Stop anything from being deleted
Logs, mailboxes, backups, cloud audit trails. Retention windows are usually short and they keep running during an incident, so the record you will want in a week may expire this week.
Start a timeline
When you first noticed, what looked wrong, who did what since. Written down as you go, it is worth more than anyone's recollection two days later.
Not an emergency? Start a conversation instead — that is the right door for a pentest, early access, or a question about how any of this works.