Think you've been breached? Act now.
Minutes matter in a security incident. What to do next depends on one question: are you an RMON client?
- (603) 642-4010
- Option 1 for emergencies
- Any hour, any day
- Call back within one hour
RMON clients: call now, any hour
1. Call (603) 642-4010. During business hours a real person answers and opens the ticket.
2. After hours, choose option 1 for an emergency and leave a voicemail. That page goes straight to the on-call technician.
3. A technician calls you back within one hour on every managed plan. Most calls come back much sooner.
Routine first response and containment are part of your managed plan. If an incident needs a full forensic investigation, regulatory notifications, or extended remediation, we scope that response to the incident and run it with you.
While you wait for the call back
Disconnect the affected machine from the network. Do not power it off.
Do not wipe, reinstall, or "clean" anything. Evidence matters.
Write down what you saw and when. Screenshots help.
General guidance, not a substitute for the call. When in doubt, just call.

RMON is techrug DFIR Certified for digital forensics and incident response. The containment steps above are run by a team certified in that discipline.
About the certificationNot an RMON client?
We will be straight with you: RMON is not an incident-response firm. Our emergency response covers current managed clients under their service plans, and taking on an unknown environment mid-incident would serve you badly. If you are in an active incident right now: call your cyber insurance carrier first (most policies direct the response and name the forensics firm), or engage a dedicated incident-response (DFIR) firm. CISA also maintains free resources and reporting channels at cisa.gov.
Emergency questions, answered
I am an RMON client. What counts as an emergency?
Do you take incident-response engagements for non-clients?
What happens if we get breached?
After the dust settles
The businesses that call us after an incident all say a version of the same thing: never again. That is the work we are built for. Managed IT and layered security, watched around the clock, so the next incident is a non-event you read about in a report instead of living through.