Support / Emergencies

Think you've been breached? Act now.

Minutes matter in a security incident. What to do next depends on one question: are you an RMON client?

  • (603) 642-4010
  • Option 1 for emergencies
  • Any hour, any day
  • Call back within one hour

RMON clients: call now, any hour

1. Call (603) 642-4010. During business hours a real person answers and opens the ticket.

2. After hours, choose option 1 for an emergency and leave a voicemail. That page goes straight to the on-call technician.

3. A technician calls you back within one hour on every managed plan. Most calls come back much sooner.

Routine first response and containment are part of your managed plan. If an incident needs a full forensic investigation, regulatory notifications, or extended remediation, we scope that response to the incident and run it with you.

While you wait for the call back

Disconnect the affected machine from the network. Do not power it off.

Do not wipe, reinstall, or "clean" anything. Evidence matters.

Write down what you saw and when. Screenshots help.

General guidance, not a substitute for the call. When in doubt, just call.

techrug DFIR Certified badge

RMON is techrug DFIR Certified for digital forensics and incident response. The containment steps above are run by a team certified in that discipline.

About the certification

Not an RMON client?

We will be straight with you: RMON is not an incident-response firm. Our emergency response covers current managed clients under their service plans, and taking on an unknown environment mid-incident would serve you badly. If you are in an active incident right now: call your cyber insurance carrier first (most policies direct the response and name the forensics firm), or engage a dedicated incident-response (DFIR) firm. CISA also maintains free resources and reporting channels at cisa.gov.

Emergency questions, answered

I am an RMON client. What counts as an emergency?
If you suspect a security incident, active data loss, or an outage stopping your business, call and choose option 1. When you are not sure, treat it as one. We would rather clear a false alarm than lose an hour.
Do you take incident-response engagements for non-clients?
No. RMON is a managed IT and security provider for its clients, not an on-call incident-response firm. Mid-incident, your cyber insurer or a dedicated DFIR firm is the right call. After stabilization, if you want a team that keeps you out of the next one, that is us.
What happens if we get breached?
You are not on your own. When something looks wrong, monitoring is designed to flag it fast, and our team moves to contain the threat, isolate affected systems, and restore from tested backups where you are on our backup plans. You get a clear, plain-English account of what happened and what changed. If an incident needs a full forensic investigation, regulatory notifications, or extended remediation, we scope that response to the incident and run it with you, rather than billing it as part of the monthly plan. The point is simple: a breach is the day you find out whether anyone is actually watching. With RMON, someone is.

After the dust settles

The businesses that call us after an incident all say a version of the same thing: never again. That is the work we are built for. Managed IT and layered security, watched around the clock, so the next incident is a non-event you read about in a report instead of living through.