Skip to content
Macksofy Technologies
Delhi NCR · DFIR
CERT-In EmpanelledDelhi NCR

DFIR Services in Delhi NCR · Government & Enterprise IR

Incident response and digital forensics for Delhi-NCR government, PSU and enterprise — CERT-In coordination, critical-sector handling, ransomware and breach forensics.

01
0-hour
CERT-In report, on time
02
NCIIPC
Protected-system aligned
03
<0 hr
Remote acquisition start
04
0×7
Retainer response
DFIR in Delhi NCR

How a Macksofy dfir engagement runs in Delhi NCR.

Delhi NCR concentrates the incidents that draw national attention — government and PSU systems, critical-sector operators, and the large enterprises clustered in Gurugram's Cyber City and Noida's IT belt. When these are hit, the response has to satisfy CERT-In, the sectoral regulator, and — for protected systems — NCIIPC, all while containing a live attacker. Macksofy's DFIR practice delivers across the NCR with the forensic rigour and documentation discipline that government and critical-sector incidents demand, on retainer and on emergency call-out, as a CERT-In empanelled firm.

The first hours are run to two clocks: containment and the CERT-In six-hour notification under Direction 20(3)/2022. Our triage runs in parallel — scoping blast radius and preserving volatile evidence while drafting the notification and opening the containment plan with the in-house or empanelled-vendor IT team. For government and PSU environments we are deliberate about documentation from minute one, because the incident will be reviewed by CERT-In, possibly NCIIPC, the departmental authority, and sometimes a CAG-aligned audit. Acquisition is forensically sound with hashes and chain-of-custody so the evidence stands up to every one of them.

NCR incident patterns span a wide estate. Ransomware and human-operated intrusions against enterprise and PSU networks demand AD-forest forensics and lateral-movement timelines. Citizen-facing portal breaches demand web, API and database forensics and a fast read on whether citizen data was exposed. Critical-sector and manufacturing incidents (the NCR/Manesar auto and industrial belt) can cross from IT into OT, where we scope carefully and preserve evidence without disrupting a live process. BEC and data-theft against enterprise HQs round out the set. Each incident produces a documented timeline, a root cause, TTPs mapped to MITRE ATT&CK, and an indicator set for estate-wide hunting.

Reporting is built for the NCR's layered oversight. The CERT-In six-hour notification and follow-up; the NCIIPC reporting and coordination where the system is notified as protected; the sectoral-regulator incident note; the DPDP breach-notification trail to the Data Protection Board and affected principals where personal data is implicated; and the departmental/CAG-aligned documentation pack a government review will request. The technical report carries the forensic findings and root cause; the leadership report carries the one-page narrative, exposure and remediation commitments that a secretary or CISO can take upward without rewrite.

Eradication and recovery verify the attacker is gone before rebuild — no surviving persistence, no rogue account or trust — and pair recovery with hardening: identity and AD fixes, segmentation (including the IT/OT boundary where relevant), and detection-engineering so the incident's indicators become permanent SOC coverage. For retainer clients we run a post-incident tabletop and update the IR playbook against the real environment and the NCR's reporting obligations.

Procurement and readiness in the NCR favour a standing arrangement. A Macksofy IR retainer — structured to fit GeM, departmental and enterprise procurement — gives guaranteed SLAs, pre-agreed RoE, named responders who know the environment, and banked hours, converting a crisis into a call rather than an emergency tender. Onsite response is same-day across Gurugram Cyber City, Noida and central Delhi, with the wider NCR — Greater Noida, Manesar, Faridabad — reachable the same day, and remote forensic acquisition starting within the hour.

Engagement workflow

Five phases. Delhi NCR timeline.

Every Macksofy dfir engagement in Delhi NCR runs through the same phased protocol — adapted to Delhi NCR-specific procurement, regulator and delivery realities.

  1. Phase 01Hour 0–6

    Triage & scope

    • Parallel kickoff — blast-radius scoping, volatile-evidence preservation and the CERT-In six-hour draft at once
    • Documentation discipline established for CERT-In / NCIIPC / departmental / CAG review
    • Containment plan agreed with the in-house or empanelled-vendor IT team
    • Initial indicator set issued for estate-wide SOC hunting
  2. Phase 02Day 1

    Acquire & contain

    • Forensically-sound memory, disk, server and (where relevant) database/web acquisition with hashes and chain-of-custody
    • Account, session and access containment without tipping a destructive actor
    • AD-forest integrity and, for industrial sites, careful IT/OT boundary preservation
    • CERT-In notification filed; NCIIPC and sectoral notes prepared where applicable
  3. Phase 03Days 1–3

    Analyse & investigate

    • Timeline reconstruction, malware analysis and TTP mapping to MITRE ATT&CK
    • Root-cause determination across initial access, persistence, escalation and lateral movement
    • Citizen/customer-data exposure scoping for the DPDP and citizen-notification decision
    • Web/API/database forensics for portal breaches; IT-to-OT path analysis where relevant
  4. Phase 04Days 3–7

    Eradicate & recover

    • Verified attacker eviction — no surviving persistence, rogue account or trust
    • Recovery sequencing with hardening: identity/AD fixes, segmentation, IT/OT boundary
    • Detection-engineering — incident indicators converted to permanent SOC coverage
    • DPDP notification to the Data Protection Board and affected principals where required
  5. Phase 05Week 2+

    Report & learn

    • Technical, leadership and regulator-facing reports with evidence references
    • CERT-In follow-up, NCIIPC coordination and departmental/CAG-aligned documentation pack
    • Post-incident tabletop and IR-playbook update against NCR reporting obligations (retainer)
    • Hardening roadmap tracked against leadership commitments
Industries served

Which Delhi NCR verticals we deliver DFIR for.

Government & PSU

Enterprise-network and citizen-portal incident response with CERT-In, departmental and CAG-aligned documentation.

Critical-sector operators

Protected-system incidents with NCIIPC reporting and coordination alongside CERT-In.

Gurugram enterprise & fintech

Ransomware, BEC and data-theft response for Cyber City HQs with board-pack reporting and DPDP notification.

Noida IT/ITeS & e-commerce

Portal, order and partner-API breach forensics with rapid data-exposure scoping.

Manufacturing & auto (NCR/Manesar)

IT-to-OT incident handling with evidence preserved without disrupting a live process.

Healthcare & edtech (NCR)

PHI/PII-exposure incident response with HIPAA/DPDP breach-notification handling.

What ships

The Delhi NCR deliverable pack.

Every Delhi NCR dfir engagement closes with the pack below — regulator-ready evidence, technical detail and board-readable summaries.

  • CERT-In six-hour notification record and follow-up closure
  • Forensic evidence set with hashes and documented chain-of-custody
  • Incident timeline and root-cause report mapped to MITRE ATT&CK
  • NCIIPC reporting and sectoral-regulator incident note where applicable
  • DPDP breach-notification trail to the Data Protection Board and affected principals
  • Departmental / CAG-aligned documentation and evidence pack
  • Eradication verification and hardening roadmap with detection rules
  • Leadership one-pager and post-incident tabletop (retainer)
Recent Delhi NCR engagement

A Delhi NCR dfir case study.

NCR public-sector body — ransomware across a Windows AD estate behind a citizen portal
Scope

Emergency IR + forensics — AD forest, application and database servers, the citizen portal; CERT-In + NCIIPC reporting, DPDP and departmental documentation

Outcome

Six-hour CERT-In notification filed on time and NCIIPC coordination opened; root cause traced to an exposed RDP jump host and an unpatched edge appliance; attacker evicted, the AD estate hardened and segmented, and citizen-data exposure scoped and notified, with a full departmental evidence pack delivered.

What clients say · Trusted India + UAE

Rated 4.9 ★ from 612 client reviews.

CERT-In Empanelled
Govt of India · MeitY
EC-Council ATC
Authorized Training
ISO 27001 Certified
Info Security Mgmt
We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.
AK
Aisha Khan
Information Security Manager · Listed Fintech · BKC, Mumbai
The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.
IK
Inspector K. Joshi
Cyber Cell · Maharashtra Police · Mumbai
Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.
VI
Vivek Iyer
DevSecOps Lead · Healthcare SaaS · Hyderabad
FAQ

Questions Delhi NCR buyers ask before signing.

Yes. We file the CERT-In six-hour notification under Direction 20(3)/2022 and, where the affected system is notified as a protected system, run the NCIIPC reporting and coordination alongside it — plus any sectoral-regulator note — as one coordinated response, with the documentation each reviewer expects.
More services in Delhi NCR

Other Macksofy engagements in Delhi NCR.

DFIR in other cities

Same engagement, other Macksofy metros.

Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • 20,000+ professionals trained
  • India + UAE engagements
Human verification· Cloudflare Turnstile

By submitting this form you agree to be contacted by Macksofy. We typically respond within a few business hours and never share your details. Protected by Cloudflare Turnstile and rate limiting.