Preview of the redesign — live site remains at diversifiedtechsolutions.com
Active cybersecurity incident? Incident response & recovery 423-888-0252 · 828-484-1257

Emergency incident response

If the business is locked out, call now.

Ransomware, a tenant you no longer trust, email that is sending as you, servers that will not boot, or backups you are afraid to restore. We treat that as an emergency: contain it, get operations back, then close the hole.

What to do in the first hour

  • Call us. Do not wait to finish a written timeline.
  • Do not power-cycle everything “to see if it comes back.”
  • Have someone with admin access on the call.
  • Have someone who can approve spend on the call.
  • If counsel is involved, they can join from the first conversation. We treat it as confidential.

We scope the first block of work after that call. Emergency response is a project, not a monthly package. Ongoing vCISO or managed IT comes after the environment is livable.

Incident response work on servers and endpoints

What we handle

Incident containment

Stop the spread. Isolate what is still talking to an attacker. Reset the credentials that matter.

Ransomware recovery

Restore from known-good backups where they exist. Rebuild where they do not. Get the business operating again.

Compromise assessment

Find leftover access: VPN, RDP, Microsoft 365, planted admin accounts, forwarding rules — not just the locker screen.

Endpoint protection / EDR

Real detection on the machines that still matter, not a leftover antivirus checkbox.

Identity & email

Microsoft 365, MFA, privileged access, and the mailbox paths used in business-email compromise.

Security overhaul

Backups that restore, network rules that are honest, logging you can read, and a 30/60/90 plan.

How we price this

This is not hourly. We price the environment: machines, servers, sites, and accounts. You are buying the outcome and someone who will still pick up — not a timesheet.

Discovery call

What is down, what still works, who has authority, how many computers, servers, locations, and people are involved, and whether email is in scope.

Phase 1 — Contain and get you operating

Stop the spread, reset what is owned, restore the systems the business cannot wait on, and write down what we know and do not know.

Phase 2 — Lock it down so it does not reopen

EDR on remaining machines, identity and MFA cleanup, backups that restore, network rules that are honest, and a 30/60/90 plan.

Stay, if you want us

Managed IT or a vCISO retainer once operations are stable. That is a separate conversation, on purpose.

If we find a second site, dead backups, or an attacker still inside, we stop and change the scope. We do not silently eat it or pad a timesheet. You get a written estimate after discovery — a range, and a not-to-exceed unless we both agree to a change.

If you have cyber insurance, call the number on the policy as well. We can still contain and rebuild. A carrier may require their own forensic firm for the investigation invoice.

Do not wait for a perfect inventory.

Tri-Cities 423-888-0252 · Western NC 828-484-1257