Active incident?
Don't fill out a form. Call or message us on WhatsApp right now — it's the fastest channel to start containing the damage.
Active incidents take absolute priority over any other work.
The first 30 minutes
- 1
Isolate, don't power off
If you suspect a security compromise, disconnect the affected device from the network (cable or WiFi), but leave it powered on. Shutting it down can wipe key evidence in memory.
- 2
Preserve the evidence
Take screenshots, note exact timestamps, save logs, and don't delete or reinstall anything yet. Every data point helps establish the real scope of the incident.
- 3
Don't act unilaterally on production
Avoid rebooting servers, mass-resetting passwords, or deleting accounts without coordinating: it can worsen the impact or erase the attacker's trail.
- 4
Contact DITAP immediately
Call or message us on WhatsApp using the number below. Tell us what you observed, when it started, and which systems appear affected.
- 5
Notify internally
Inform your technical lead and, if there are signs of data exposure, your legal or compliance team. The sooner those chains activate, the lower the risk.
- 6
Document every step you take
From this point on, every action — yours or DITAP's — gets logged with time and owner. That log is key for the post-incident review and, if applicable, regulatory reporting.
Not sure if it's a DITAP-side incident or something local to you?