SOC operating 24/7 · Bangkok, UTC+7 zcr.ai — our platform ↗
Emergency · answered 24/7

Under attack?

Call now +66 86-940-1383

One number. It rings the SOC shift that is on duty right now.

A responder within four hoursMeasured from your call, not from a triage queue.

The SOC is staffed 24 hours a day, every day, from Bangkok (UTC+7). Thai and English. You do not need a contract, an account or a purchase order to make this call.

Who is calling

Two kinds of people call this number. Both get answered.

You are a partner

Call the same number. Tell us which customer, what the environment is, and what you have already done.

We join your incident behind your incident commander. Your customer keeps talking to you. Our name is not on the ticket, not on the report, and not in the room.

You are an organisation under attack

Call the same number. We will not ask whether you are a partner before we help you.

We take the call, help you stabilise, and stay with you through the first hours. After that we bring in the partner who looks after you, because they hold the relationship and they are the ones who will still be there next month. If you do not have a partner, we introduce you to one.

This is not a sales queue. Nobody is going to ask for a budget before telling you to unplug a machine.

Before anyone calls you back

What to do in the next ten minutes

Do these while the phone is ringing. They cost nothing, they slow the attacker down, and they protect the evidence you will need later.

  1. Do

    Disconnect affected machines from the network. Do not power them off.

    Pull the network cable or switch off the wireless. Leave the machine running. Memory holds evidence that disappears the moment you shut down, and it is often the only place the attacker’s tooling still exists.

  2. Do

    Stop your backups.

    Pause backup jobs and replication now. A running backup will overwrite your last clean copy with encrypted files. If backups sit on a NAS or a mounted share, disconnect it.

  3. Do not

    Do not pay anything yet.

    Do not contact the attacker and do not pay. That is a decision for later, with your insurer and your lawyer in the room. Nothing about it improves in the next ten minutes.

  4. Do not

    Do not wipe, reinstall or clean anything.

    A reimaged machine is a destroyed crime scene, and reinstalling rarely removes the access the attacker still holds elsewhere. Leave it disconnected and leave it alone.

  5. Do

    Write down the times.

    Note when you first saw something wrong, what you saw, and every action you take from now, with the clock time next to it. This becomes the timeline your insurer and any regulator will ask for.

  6. Do

    Move the conversation somewhere the attacker cannot read.

    If your email or chat may already be compromised, coordinate by phone or on personal devices. Assume they are reading. Do not discuss the response in the systems under attack.

  7. Do

    Keep the logs.

    Firewall, VPN, Active Directory, EDR and mail. Raise the retention setting or export now — the default is often seven days, and the window you need is usually the one about to roll off.

After you make contact

What happens once someone picks up

  1. The SOC shift on duty answers.

    A person, not a queue. We take the basics: what you are seeing, when it started, and who in your organisation can authorise action on your systems.

  2. We tell you what to stop doing.

    Containment advice comes before anything commercial. If there are steps you can take yourself in the next few minutes, you get them on that call, whether or not anything is ever signed.

  3. We open an incident and hand it to the response team.

    A responder is with you within four hours of the call — measured from when you ring, not from when a ticket gets triaged. On that first call we tell you what happens next and when we will contact you again.

  4. We agree scope in writing before we touch a system.

    What we may do, on which machines, and which partner the work is contracted through. Short and written down. Cyber Defense does not contract with end customers, so if you do not already have a partner we introduce one before paid work starts. This step never blocks step two — advice comes first and always has.

  5. We bring in the partner who will look after you afterwards.

    Recovery, rebuild and everything that follows is long-term work, and we operate through partners. Once you are stable we hand you to the partner who already holds your account, or introduce you to one who can take it on.

Have these ready

Three things that make the first call faster

  • A phone number that will actually be answered for the next few hours.
  • Someone who can authorise action on the affected systems.
  • Roughly what you are seeing — a ransom note, locked files, an alert, an email from someone claiming to have your data.
Call now · +66 86-940-1383
Not an emergency today

The cheapest incident is the one where the paperwork was signed months ago

Partners hold an incident response retainer with us so the call at 2am starts with an investigation instead of a purchase order. Scope, rates and contacts are settled while everyone is calm.