Skip to content
RESPONSE ACTIVATION · DFIR 24/7

Report a security incident

Fill in what you know now. Don't wait for the full picture, with the first three fields we can already start.

WHILE YOU WRITE
Isolate, don't power off

Disconnect the machine from the network. Powering off destroys volatile memory, where the best evidence usually lives.

DON'T TOUCH
No deleting or reinstalling

Not files, not accounts, not logs. Every premature cleanup reduces what we can reconstruct later.

PRESERVE
Screenshots and times

Photograph what's on screen and note the exact time of each observation. It becomes the timeline.

IF THERE IS EXTORTION
Don't reply yet

Don't answer the attacker or accept deadlines until we talk. The first reply conditions the whole negotiation.

MINIMUM TO START
Organization Contact What's happening
3 of 3 missing
INCIDENT DETAILS
It reaches the CROC shift directly. We reply to the address you provided.
Complete at least organization, contact and what is happening. If the situation is critical, skip the rest: call the 24/7 line.
IF YOU PREFER TO WRITE
Direct email
incidentes@cbrt.com.do
On-call phone: (809) 817-3906

The form is the recommended path: it arrives with the fields the analyst needs to start. If you can't use it, write and we respond anyway.

WHAT HAPPENS NEXT
01 Acknowledgment in minutes and a triage call with an on-call analyst.
02 Preservation and containment instructions for your team.
03 Formal activation: with a retainer, under 4 hours remote.
Confidentiality

The report is handled as TLP:RED until you authorize otherwise. We don't share your identity with third parties or in intelligence reports.

No retainer yet? →

We handle emergencies without a prior contract. The retainer only makes us start sooner.