Emergency response

Under attack?Call now.

Ransomware, account takeover, or a breach in progress. Minutes matter. EMPIST incident response starts with containment, then recovery. Available 24/7/365.

24/7/365 · Contain first · Recover next
Do this first

Phone first. Forms second.

If systems are encrypting, admins are locked out, or wire fraud is in motion, call. Do not wait for a callback window that never comes.

Emergency line

Active cyber incident. Choose the emergency option when prompted.

Call (866) 442-3018
While you reach us

What to do in the first minutes

Simple moves that protect recovery. Avoid panic wipes that erase the trail you need.

  • Call immediately

    Use (866) 442-3018 and choose the emergency option, or (312) 360-1900. Do not wait for email replies when systems are encrypting or accounts are hijacked.

  • Preserve what you can

    Do not wipe machines or reset everything before someone is guiding containment. Evidence and live sessions often matter for stopping the attacker.

  • Limit the blast radius

    If guided to do so: disconnect affected systems from the network, pause suspicious admin changes, and stop paying or negotiating until response is engaged.

If you are seeing this

Treat it as an active incident

  • Ransomware notes, mass file encryption, or sudden share lockouts
  • Business email compromise, wire fraud attempts, or executive impersonation
  • Impossible logins, MFA fatigue, or admin accounts behaving wrong
  • Widespread outage that looks like sabotage, not a normal IT failure
  • Law enforcement, insurer, or customer notice that suggests a breach
How EMPIST responds

Contain. Eradicate. Recover.

Right of the boom, in order. Speed protects the business. Investigation deepens after the bleeding stops.

  • Triage and contain

    Confirm what is happening, isolate paths the attacker is using, and stop the spread across identity, endpoints, email, and cloud.

  • Eradicate and recover

    Remove footholds, restore access and systems with intent, and get the business back online against clear priorities.

  • Stabilize and harden

    After the boom: close the path that worked and leave you stronger than before the incident started.

Want the full practice, including readiness before the next boom? See Incident Response.

FAQ

Quick answers while you call

Non-clients, ransom, and what happens next.

01Should I call even if we are not an EMPIST client?
Yes. Active incidents need containment now. We triage emergencies for organizations that need help, then clarify engagement as response starts.
02What number should I call?
Call (866) 442-3018 and choose the emergency option, or (312) 360-1900. Phone beats forms when minutes matter.
03Should we pay the ransom?
Do not decide that alone in the first minutes. Containment and counsel come first. Paying is a business and legal decision, not a default step.
04Is this the same as your Incident Response service page?
This page is the emergency path. Incident Response explains the full practice: left of the boom readiness and right of the boom recovery. Use this page when something is happening now.
05What happens after you contain the attack?
We move through eradication and recovery, then harden what failed. Longer-term defense in depth and SecureForward can follow once the business is stable.

Active incident? We are ready.

Call if you can. If you cannot, send details below and we will route this to incident response immediately.

24/7/365 incident pathSOC 2 Type II

Or send details now

We’ll route this to incident response right away.

Company size*