SIRI Response — the first hour decides more than any control you bought beforehand.
Ransomware, breach investigation, containment and recovery — activated the moment an incident is confirmed. SIRI Response combines digital forensics and incident response into a single team, with CERT-In notification analysis running from the first hour, not after investigation concludes.
Detection is only useful if response is ready to move
Every hour an attacker stays active after detection is an hour of continuing damage.
An incident doesn't wait for a convenient time to happen, and the decisions made in the first hour — what to isolate, what to preserve, who to notify, whether to pay — shape the outcome more than almost anything decided in advance. SIRI Response is built to move the moment an incident is confirmed, combining investigation, containment and forensics under one team instead of coordinating separate vendors under crisis conditions.
Ransomware alone now accounts for 44% of confirmed data breaches, and the instinct to simply pay and move on is a weaker strategy than it appears — only around 60% of organisations that pay actually recover their data, in whole or in part. A tested response capability that can contain, investigate and recover without relying on an attacker's cooperation is the more reliable path, and it's also the one that produces defensible evidence and a notification that holds up to regulatory scrutiny.
SIRI Response's incident coordination runs technical containment and investigation, forensic evidence preservation, and India's CERT-In notification analysis as one workflow — with evidence handled to a standard that survives regulatory and legal scrutiny, and a direct line into SIRI Resilience once the incident is closed, so the same gap doesn't reopen.
What organisations get wrong
Four assumptions that make a bad incident worse
Most incident-response failures aren't about the technology — they're about decisions made under pressure with no plan already in place.
“We'll figure it out when it happens”
Deciding roles, escalation paths and vendor relationships during an active incident costs hours you don't have — and the six-hour CERT-In clock doesn't pause while you figure it out.
“Paying the ransom guarantees recovery”
Only around 60% of organisations that pay a ransom recover some or all of their data — payment is a gamble on an attacker's cooperation, not a reliable recovery plan.
“IT can handle containment on its own”
Containment without forensic preservation can destroy the evidence needed for investigation, insurance claims and regulatory notification — the two need to run together.
“We'll notify once investigation is complete”
CERT-In's six-hour window starts when you become aware of an incident, not once you understand its full scope — waiting for certainty before notifying is itself a compliance risk.
What SIRI Response covers
Investigation, containment and forensics as one connected capability
Activated the moment an incident is confirmed, with a direct line into SIRI Resilience once it's closed.
Containment, Recovery & Advisory
Containment, recovery-sequencing and advisory support for active ransomware incidents.
- Immediate containment
- Recovery-path advisory
- Business-impact triage
Breach Investigation
Root-cause investigation for confirmed or suspected data breaches, from entry point to full scope.
- Root-cause analysis
- Scope & impact assessment
- Timeline reconstruction
Containment & Eradication
Immediate action to stop lateral movement and limit how far an incident spreads.
- Lateral-movement containment
- Credential & access lockdown
- Eradication of persistence
Static & Dynamic Malware Analysis
Static and dynamic analysis of malicious code found during an incident.
- Static & dynamic analysis
- Indicator-of-compromise extraction
- Threat attribution context
Proactive Threat Hunting
Proactive search for indicators of compromise across the environment, beyond the known incident.
- IOC sweep across environment
- Persistence-mechanism hunting
- Dwell-time reduction
Digital Forensics & Evidence Preservation
Endpoint, network, cloud and mobile forensics — evidence handled to survive legal and regulatory scrutiny.
- Chain-of-custody evidence handling
- Cloud, endpoint & mobile forensics
- Expert reporting for proceedings
Evidence, not guesswork
No IR plan vs. insurance IR panel only vs. SIRI Response — what actually differs
Having a plan on paper and having an activated, tested response capability are different things.
| Approach | No IR plan | Cyber-insurance IR panel only | SIRI Response |
|---|---|---|---|
| Activation time | Ad hoc, first call unclear | Depends on insurer approval | Direct, 24/7 |
| CERT-In six-hour notification support | No | Sometimes | Included |
| Forensic evidence chain of custody | Rarely documented | Depends on panel firm | Standard |
| Containment & investigation as one team | No | Depends on coordination | Yes |
| Post-incident resilience follow-through | No | Rarely | Direct handoff to SIRI Resilience |
Sources: CERT-In Directions 2022; IT Act 2000 s.70B(6); Bharatiya Sakshya Adhiniyam 2023 s.63; 2026 ransomware benchmark data. Summarised for comparison; confirm current obligations applicable to your organisation.
Numbers every board should know
What's actually driving incident outcomes
Of breaches involve ransomware
A 12% year-on-year increase in confirmed data breaches involving ransomware.
CERT-In notification window
From when you become aware of an incident, under the IT Act 2000 s.70B(6).
Typical cost per incident
Including recovery, downtime and reputational impact — before any ransom paid.
Of payers partly recover
Of organisations that pay a ransom recover some or all of their data — not a guarantee.
Compliance alignment
Standards & frameworks we align to
Our methodology is built around publicly recognised frameworks — not a proprietary checklist. Where a specific certification or attestation is completed and verified, it will be named here explicitly.
Framework references reflect publicly available versions as of publication and describe the standards our methodology is aligned to; they are not a claim of certification, attestation, or audit completion unless stated explicitly elsewhere on this site.
Why SIRI for incident response specifically
One team from the first call to the final report
Coordinating separate technical and forensics vendors mid-incident costs time you don't have.
From discovery to response, as one team
Containment, investigation and forensics run as a single connected capability, not separate vendors handed off between under crisis conditions.
Evidence built to survive scrutiny
Forensic work is handled to chain-of-custody standards aligned with the Bharatiya Sakshya Adhiniyam 2023, s.63, so it holds up in regulatory or legal proceedings.
Technical depth
Investigation is run by engineers who do the forensic work directly, not relayed through account managers from a subcontracted lab.
A direct line into resilience
Once an incident is closed, findings feed directly into SIRI Resilience so the same gap doesn't reopen the same way.
Who this is built for
Organisations SIRI Response is built for
How we work
From activation to post-incident hardening
Activate & Contain
Immediate engagement and containment to stop the incident from spreading further.
Hour 1Investigate & Eradicate
Root-cause investigation, forensic evidence preservation and eradication of persistence.
Days 1–7Recover & Notify
Recovery sequencing alongside CERT-In and regulator notification support.
Ongoing / 6-hr clockPost-Incident Hardening
Findings handed to SIRI Resilience to close the gap that allowed the incident.
Following weeksFrequently asked
SIRI Response, answered directly
How fast can you actually respond?
SIRI Response is built to activate as soon as an incident is confirmed, 24/7. For clients with a retainer or pre-agreed scope in place, activation is faster still, since roles, access and escalation paths are already defined.
Do you handle ransomware negotiation?
Containment, recovery-path advisory and coordination support are provided; where negotiation is being considered, SIRI Response advises on the trade-offs and sequencing rather than presenting payment as the default path, given that only around 60% of payers recover data in full.
Is the evidence you collect usable in court or a regulatory proceeding?
Forensic evidence is handled to chain-of-custody standards aligned with the Bharatiya Sakshya Adhiniyam 2023, s.63, and reported in a form intended to hold up to legal and regulatory scrutiny.
Do we need a retainer in place before an incident happens?
No, SIRI Response can be activated without a pre-existing retainer, but a retainer with predefined scope and access materially reduces activation time when it matters most.
What does the CERT-In six-hour window mean for us practically?
Under CERT-In's 2022 Directions, notification is required within six hours of becoming aware of a cyber incident. The notification needs to be accurate and complete enough not to worsen your regulatory position — SIRI Response's protocol produces CERT-In-ready notifications as a standard output of the engagement.
If something's happening right now, call
Activate incident response.
If you have an active incident, call the emergency line directly. Otherwise, start with a scoped readiness engagement.
Related