defencia/knowledge/emergency & dfir
Incident readiness · First response · Preparation

Emergency Handling & DFIR

What do you do if your company is hit by a cyber attack? This is the starting point: how to prepare, what to have ready, and how to begin handling and reporting an incident.

PreparationFirst responseProcess

Where to start

No security in place at all? Then call a friend — that advice is meant 100% seriously. You would not start an expedition to a mountain top from day one without preparation.

Think of it like investing in a fire blanket and extinguisher even before you have escape plans and alarms — a basic readiness beats none.

What to have ready (physically & practically)

Preparing the digital toolbox

Write-block capability

To secure evidence correctly you must avoid writing to the disk you are securing — otherwise you contaminate the evidence. Write protection can be achieved in software or hardware.

ApproachHowCost
Software (live boot)Boot from USB with CAINE or Paladin — read-only by design.Free
Software (installed)Tools like Safe Block write-protect any device you connect (SATA + USB in one).Paid, cheaper than hardware
HardwarePhysical device inserted between disk and computer; works over USB, no real speed loss on USB 3.x.One-time investment (~3,000–8,000 DKK)
Examples: Weibetech FUD (reads serial/product name), and Tableau from Guidance Software at the higher end. Buy what fits YOUR task — you are building YOUR toolbox.