Incident Response & DFIR

Your incident is in Europe. So is your response team.

ByteRay is a Munich-based DFIR team, listed by the German Federal Office for Information Security (BSI) as a qualified APT response provider under Section 3 BSIG. We contain, investigate and document security incidents — on site across the DACH region and the EU, remote worldwide, reporting in English and German.

qw
vc
mshm
Government-vetted
Listed by Germany's federal cyber agency (BSI) for APT response
Fully certified team
CISSP · CySA+ · PMRP · CCFA · CCFR · CCFH · CCSE
We build on Falcon
Foundry apps & Fusion SOAR playbooks
24/7 from Germany
SLA response from 60 minutes
Working with us from abroad

Why organisations outside Germany call a Munich team

Most of our clients are German-speaking. The ones who are not usually arrive with the same problem: the incident sits inside a European entity, and the response has to work under European rules, in European jurisdictions, with evidence that holds up here.

BSI-listed for APT response

The German Federal Office for Information Security keeps a list of vetted providers for responding to advanced persistent threats under Section 3 BSIG. ByteRay is on it. For regulated entities and public-sector suppliers in Germany, that listing is often a procurement condition rather than a marketing line.

Reporting in English and German

One investigation, both languages. Findings are written for the people who have to act on them — your board, your insurer, your regulator, your counsel — without a translation round in between.

Evidence stays in the EU

Images, telemetry and case data are processed on European infrastructure. The GDPR is the ground the work is built on, not a clause bolted on at the end.

On the ground, not just on the call

Munich-based, with responders on site across Germany, Austria and Switzerland, and remote response worldwide. Someone can stand in the room where the affected systems are.

Scope

What we take on once an incident is live

Incident response is not a single task. Depending on where you are when you call, we take over parts of the work or all of it — alongside your own team, not around it.

Containment

Cutting off the attacker's access and movement without destroying the evidence you will need afterwards. The two goals conflict more often than people expect.

Digital forensics

Endpoints, servers, cloud workloads and identity systems: what was reached, by whom, from when — and what left the building.

Malware analysis

Static and dynamic analysis of the samples found in your environment, including tooling an attacker built for your case specifically.

Threat hunting and compromise assessment

Whether an attacker is still present, and whether this incident is the first one — or simply the one you happened to notice.

Log and SIEM analysis

Rebuilding the timeline from whatever telemetry exists, including sources that were never set up with forensics in mind.

Recovery and hardening

Getting operations back, and closing the path that was used before somebody walks down it a second time.

Documentation

Reports for management, insurers and supervisory authorities — and, where it goes that far, for proceedings in a German court.

When we get the call

Four situations that bring international clients to us

You have a German or EU subsidiary

Your global SOC sees the alert. What it cannot do from another continent is walk into a Munich data centre at two in the morning, talk to local IT in German, or hand your German counsel a report they can actually use. That is the gap we fill — next to your existing team, not instead of it.

Your regulator expects a recognised responder

NIS2, DORA and the BSIG have moved incident response from good practice to documented obligation. We work inside those reporting duties and produce the evidence they ask for, in the form they ask for it.

You already run CrowdStrike Falcon

We work inside your existing tenant: no second agent, no parallel tooling, no waiting for a rollout before the investigation can start. Falcon is where our team is deepest — but the work does not depend on it, and we respond in environments built on anything else just as readily.

You want the retainer before you need it

The worst possible moment to negotiate contracts, data processing agreements and system access is during an active incident. A retainer settles all of that while nobody is under pressure.

How to reach us

You do not need a contract to get help

There are two ways this starts. One of them is better, but neither of them is a closed door.

Emergency call, no prior relationship

Our DFIR hotline is staffed around the clock and takes calls from organisations we have never worked with before. We triage first and sort out the paperwork second — during an active attack, the order matters.

Incident response retainer

Agreed response times, an environment we already know, and legal and commercial terms cleared in advance. Hours you do not spend on incidents go into preparation — hardening reviews, tabletop exercises, readiness checks — instead of quietly expiring.

Active incident right now?
+49 89 2000 7683
Staffed around the clock. Call rather than write.
Team and credentials

Who actually shows up

ByteRay is a specialist team, not a general consultancy with a security practice attached. The people who write the report are the people who ran the investigation.

BSI-listed
Qualified APT response provider under Section 3 BSIG
2 per week
Average DFIR engagements across the team
30,000+
Systems protected through services we operate
Munich, DE
EU jurisdiction, EU data processing
Certifications held across the team: CCFA · CCFR · CCFH · CCSE · CCCS · CISSP · CySA+
Questions we get from abroad

The practical answers first

Do you take on clients outside Germany?

Yes. On-site response across the DACH region and the EU, remote response worldwide. The practical limits are travel time and language, not willingness.

In which languages do you report?

English and German. Both versions come from the team that ran the investigation, not from a translation service that has never seen the environment.

Do we need an existing contract to call the hotline?

No. The hotline takes calls from organisations we have never worked with. Commercial terms are settled alongside the response rather than ahead of it.

Do we have to be a CrowdStrike customer?

No. Falcon is where our team is deepest and we can work directly inside your existing tenant, but incident response is not conditional on your toolset.

Where is the evidence stored?

On European infrastructure, under the GDPR, with retention periods agreed as part of the engagement rather than left open.

Can you support insurance claims and regulatory notifications?

Yes. Reports are written with those readers in mind, including the early-warning deadlines that apply under NIS2 where your entity falls in scope.

z
z
z
z
i
i
z
z
Talk to a responder, not a
call centre.
Whether you are running an incident right now or preparing for one: the hotline reaches our DFIR team directly, around the clock. With or without a contract.
Prefer to book a slot right away?
Book an intro call