Most of our clients are German-speaking. The ones who are not usually arrive with the same problem: the incident sits inside a European entity, and the response has to work under European rules, in European jurisdictions, with evidence that holds up here.
The German Federal Office for Information Security keeps a list of vetted providers for responding to advanced persistent threats under Section 3 BSIG. ByteRay is on it. For regulated entities and public-sector suppliers in Germany, that listing is often a procurement condition rather than a marketing line.
One investigation, both languages. Findings are written for the people who have to act on them — your board, your insurer, your regulator, your counsel — without a translation round in between.
Images, telemetry and case data are processed on European infrastructure. The GDPR is the ground the work is built on, not a clause bolted on at the end.
Munich-based, with responders on site across Germany, Austria and Switzerland, and remote response worldwide. Someone can stand in the room where the affected systems are.
Incident response is not a single task. Depending on where you are when you call, we take over parts of the work or all of it — alongside your own team, not around it.
Cutting off the attacker's access and movement without destroying the evidence you will need afterwards. The two goals conflict more often than people expect.
Endpoints, servers, cloud workloads and identity systems: what was reached, by whom, from when — and what left the building.
Static and dynamic analysis of the samples found in your environment, including tooling an attacker built for your case specifically.
Whether an attacker is still present, and whether this incident is the first one — or simply the one you happened to notice.
Rebuilding the timeline from whatever telemetry exists, including sources that were never set up with forensics in mind.
Getting operations back, and closing the path that was used before somebody walks down it a second time.
Reports for management, insurers and supervisory authorities — and, where it goes that far, for proceedings in a German court.
Your global SOC sees the alert. What it cannot do from another continent is walk into a Munich data centre at two in the morning, talk to local IT in German, or hand your German counsel a report they can actually use. That is the gap we fill — next to your existing team, not instead of it.
NIS2, DORA and the BSIG have moved incident response from good practice to documented obligation. We work inside those reporting duties and produce the evidence they ask for, in the form they ask for it.
We work inside your existing tenant: no second agent, no parallel tooling, no waiting for a rollout before the investigation can start. Falcon is where our team is deepest — but the work does not depend on it, and we respond in environments built on anything else just as readily.
The worst possible moment to negotiate contracts, data processing agreements and system access is during an active incident. A retainer settles all of that while nobody is under pressure.
There are two ways this starts. One of them is better, but neither of them is a closed door.
Our DFIR hotline is staffed around the clock and takes calls from organisations we have never worked with before. We triage first and sort out the paperwork second — during an active attack, the order matters.
Agreed response times, an environment we already know, and legal and commercial terms cleared in advance. Hours you do not spend on incidents go into preparation — hardening reviews, tabletop exercises, readiness checks — instead of quietly expiring.
ByteRay is a specialist team, not a general consultancy with a security practice attached. The people who write the report are the people who ran the investigation.
Yes. On-site response across the DACH region and the EU, remote response worldwide. The practical limits are travel time and language, not willingness.
English and German. Both versions come from the team that ran the investigation, not from a translation service that has never seen the environment.
No. The hotline takes calls from organisations we have never worked with. Commercial terms are settled alongside the response rather than ahead of it.
No. Falcon is where our team is deepest and we can work directly inside your existing tenant, but incident response is not conditional on your toolset.
On European infrastructure, under the GDPR, with retention periods agreed as part of the engagement rather than left open.
Yes. Reports are written with those readers in mind, including the early-warning deadlines that apply under NIS2 where your entity falls in scope.