DFIR Services in Delhi NCR · Government & Enterprise IR
Incident response and digital forensics for Delhi-NCR government, PSU and enterprise — CERT-In coordination, critical-sector handling, ransomware and breach forensics.
How a Macksofy dfir engagement runs in Delhi NCR.
Delhi NCR concentrates the incidents that draw national attention — government and PSU systems, critical-sector operators, and the large enterprises clustered in Gurugram's Cyber City and Noida's IT belt. When these are hit, the response has to satisfy CERT-In, the sectoral regulator, and — for protected systems — NCIIPC, all while containing a live attacker. Macksofy's DFIR practice delivers across the NCR with the forensic rigour and documentation discipline that government and critical-sector incidents demand, on retainer and on emergency call-out, as a CERT-In empanelled firm.
The first hours are run to two clocks: containment and the CERT-In six-hour notification under Direction 20(3)/2022. Our triage runs in parallel — scoping blast radius and preserving volatile evidence while drafting the notification and opening the containment plan with the in-house or empanelled-vendor IT team. For government and PSU environments we are deliberate about documentation from minute one, because the incident will be reviewed by CERT-In, possibly NCIIPC, the departmental authority, and sometimes a CAG-aligned audit. Acquisition is forensically sound with hashes and chain-of-custody so the evidence stands up to every one of them.
NCR incident patterns span a wide estate. Ransomware and human-operated intrusions against enterprise and PSU networks demand AD-forest forensics and lateral-movement timelines. Citizen-facing portal breaches demand web, API and database forensics and a fast read on whether citizen data was exposed. Critical-sector and manufacturing incidents (the NCR/Manesar auto and industrial belt) can cross from IT into OT, where we scope carefully and preserve evidence without disrupting a live process. BEC and data-theft against enterprise HQs round out the set. Each incident produces a documented timeline, a root cause, TTPs mapped to MITRE ATT&CK, and an indicator set for estate-wide hunting.
Reporting is built for the NCR's layered oversight. The CERT-In six-hour notification and follow-up; the NCIIPC reporting and coordination where the system is notified as protected; the sectoral-regulator incident note; the DPDP breach-notification trail to the Data Protection Board and affected principals where personal data is implicated; and the departmental/CAG-aligned documentation pack a government review will request. The technical report carries the forensic findings and root cause; the leadership report carries the one-page narrative, exposure and remediation commitments that a secretary or CISO can take upward without rewrite.
Eradication and recovery verify the attacker is gone before rebuild — no surviving persistence, no rogue account or trust — and pair recovery with hardening: identity and AD fixes, segmentation (including the IT/OT boundary where relevant), and detection-engineering so the incident's indicators become permanent SOC coverage. For retainer clients we run a post-incident tabletop and update the IR playbook against the real environment and the NCR's reporting obligations.
Procurement and readiness in the NCR favour a standing arrangement. A Macksofy IR retainer — structured to fit GeM, departmental and enterprise procurement — gives guaranteed SLAs, pre-agreed RoE, named responders who know the environment, and banked hours, converting a crisis into a call rather than an emergency tender. Onsite response is same-day across Gurugram Cyber City, Noida and central Delhi, with the wider NCR — Greater Noida, Manesar, Faridabad — reachable the same day, and remote forensic acquisition starting within the hour.
Five phases. Delhi NCR timeline.
Every Macksofy dfir engagement in Delhi NCR runs through the same phased protocol — adapted to Delhi NCR-specific procurement, regulator and delivery realities.
- Phase 01
Triage & scope
Hour 0–6- Parallel kickoff — blast-radius scoping, volatile-evidence preservation and the CERT-In six-hour draft at once
- Documentation discipline established for CERT-In / NCIIPC / departmental / CAG review
- Containment plan agreed with the in-house or empanelled-vendor IT team
- Initial indicator set issued for estate-wide SOC hunting
- Phase 02
Acquire & contain
Day 1- Forensically-sound memory, disk, server and (where relevant) database/web acquisition with hashes and chain-of-custody
- Account, session and access containment without tipping a destructive actor
- AD-forest integrity and, for industrial sites, careful IT/OT boundary preservation
- CERT-In notification filed; NCIIPC and sectoral notes prepared where applicable
- Phase 03
Analyse & investigate
Days 1–3- Timeline reconstruction, malware analysis and TTP mapping to MITRE ATT&CK
- Root-cause determination across initial access, persistence, escalation and lateral movement
- Citizen/customer-data exposure scoping for the DPDP and citizen-notification decision
- Web/API/database forensics for portal breaches; IT-to-OT path analysis where relevant
- Phase 04
Eradicate & recover
Days 3–7- Verified attacker eviction — no surviving persistence, rogue account or trust
- Recovery sequencing with hardening: identity/AD fixes, segmentation, IT/OT boundary
- Detection-engineering — incident indicators converted to permanent SOC coverage
- DPDP notification to the Data Protection Board and affected principals where required
- Phase 05
Report & learn
Week 2+- Technical, leadership and regulator-facing reports with evidence references
- CERT-In follow-up, NCIIPC coordination and departmental/CAG-aligned documentation pack
- Post-incident tabletop and IR-playbook update against NCR reporting obligations (retainer)
- Hardening roadmap tracked against leadership commitments
- Phase 01Hour 0–6
Triage & scope
- Parallel kickoff — blast-radius scoping, volatile-evidence preservation and the CERT-In six-hour draft at once
- Documentation discipline established for CERT-In / NCIIPC / departmental / CAG review
- Containment plan agreed with the in-house or empanelled-vendor IT team
- Initial indicator set issued for estate-wide SOC hunting
- Phase 02Day 1
Acquire & contain
- Forensically-sound memory, disk, server and (where relevant) database/web acquisition with hashes and chain-of-custody
- Account, session and access containment without tipping a destructive actor
- AD-forest integrity and, for industrial sites, careful IT/OT boundary preservation
- CERT-In notification filed; NCIIPC and sectoral notes prepared where applicable
- Phase 03Days 1–3
Analyse & investigate
- Timeline reconstruction, malware analysis and TTP mapping to MITRE ATT&CK
- Root-cause determination across initial access, persistence, escalation and lateral movement
- Citizen/customer-data exposure scoping for the DPDP and citizen-notification decision
- Web/API/database forensics for portal breaches; IT-to-OT path analysis where relevant
- Phase 04Days 3–7
Eradicate & recover
- Verified attacker eviction — no surviving persistence, rogue account or trust
- Recovery sequencing with hardening: identity/AD fixes, segmentation, IT/OT boundary
- Detection-engineering — incident indicators converted to permanent SOC coverage
- DPDP notification to the Data Protection Board and affected principals where required
- Phase 05Week 2+
Report & learn
- Technical, leadership and regulator-facing reports with evidence references
- CERT-In follow-up, NCIIPC coordination and departmental/CAG-aligned documentation pack
- Post-incident tabletop and IR-playbook update against NCR reporting obligations (retainer)
- Hardening roadmap tracked against leadership commitments
Which Delhi NCR verticals we deliver DFIR for.
Government & PSU
Enterprise-network and citizen-portal incident response with CERT-In, departmental and CAG-aligned documentation.
Critical-sector operators
Protected-system incidents with NCIIPC reporting and coordination alongside CERT-In.
Gurugram enterprise & fintech
Ransomware, BEC and data-theft response for Cyber City HQs with board-pack reporting and DPDP notification.
Noida IT/ITeS & e-commerce
Portal, order and partner-API breach forensics with rapid data-exposure scoping.
Manufacturing & auto (NCR/Manesar)
IT-to-OT incident handling with evidence preserved without disrupting a live process.
Healthcare & edtech (NCR)
PHI/PII-exposure incident response with HIPAA/DPDP breach-notification handling.
The Delhi NCR deliverable pack.
Every Delhi NCR dfir engagement closes with the pack below — regulator-ready evidence, technical detail and board-readable summaries.
- CERT-In six-hour notification record and follow-up closure
- Forensic evidence set with hashes and documented chain-of-custody
- Incident timeline and root-cause report mapped to MITRE ATT&CK
- NCIIPC reporting and sectoral-regulator incident note where applicable
- DPDP breach-notification trail to the Data Protection Board and affected principals
- Departmental / CAG-aligned documentation and evidence pack
- Eradication verification and hardening roadmap with detection rules
- Leadership one-pager and post-incident tabletop (retainer)
A Delhi NCR dfir case study.
Emergency IR + forensics — AD forest, application and database servers, the citizen portal; CERT-In + NCIIPC reporting, DPDP and departmental documentation
Six-hour CERT-In notification filed on time and NCIIPC coordination opened; root cause traced to an exposed RDP jump host and an unpatched edge appliance; attacker evicted, the AD estate hardened and segmented, and citizen-data exposure scoped and notified, with a full departmental evidence pack delivered.
Rated 4.9 ★ from 612 client reviews.
“We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.”
“The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.”
“Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.”
Questions Delhi NCR buyers ask before signing.
Other Macksofy engagements in Delhi NCR.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- 20,000+ professionals trained
- India + UAE engagements
