Service
OperationalCyber incident response in Namibia: investigation and containment when it matters
Structured response to confirmed security incidents for Namibian organisations: investigation, scope, containment guidance and a written post-incident account.
Overview
The worst moment to work out who to call is during an incident. Organisations that handle incidents well have almost always decided in advance who investigates, who authorises containment, who informs customers, and where the evidence goes.
Namibia has had public reminders of what this looks like. The Namibia Airports Company suffered a cybersecurity incident involving unauthorised access to internal systems and the alleged exfiltration of roughly 500 gigabytes of data by a ransomware group. Telecom Namibia previously had over 626 gigabytes exposed. These are national organisations with resources, and it still happened.
Tech49Originals provides incident response both as part of a managed service and as a standalone engagement for Namibian organisations. We establish what happened, determine how far it spread, recommend containment, and preserve evidence in a form that survives later scrutiny from a regulator, an insurer or a court.
Destructive containment actions are never taken without your explicit authorisation. Isolating a server stops an attacker and may also stop your business, and that trade-off is yours to make with the facts in front of you.
Suited to
- Namibian organisations experiencing a suspected or confirmed compromise
- Businesses hit by ransomware needing scope determination and recovery support
- Organisations building an incident response capability before they need it
- Boards requiring an independent investigation of a security event
- Institutions facing notification obligations to a regulator or affected customers
What you receive
Deliverables
Specific and contractible, rather than a description of effort.
- Rapid triage and severity assessment
- Forensic investigation and timeline reconstruction
- Scope determination across the estate
- Containment and recovery recommendations
- Evidence collection and preservation to an evidential standard
- Written post-incident report with root cause and corrective actions
- Support for regulatory and stakeholder notification decisions
Delivered on
The platform capabilities behind this service
What the technology contributes, so the boundary between software and human work is explicit.
- Operational
Incident Response
A defined path from alert to containment to closure, with analysts who investigate before they escalate.
Explore - In deployment
Threat Hunting
Analyst-led search for activity that did not trigger an alert, supported by fleet-wide query and remote forensic collection.
Explore - Operational
SIEM & XDR
Collects security telemetry from servers, endpoints, network devices and cloud workloads into one correlated detection engine.
Explore
Common questions
Incident Response in Namibia: what buyers ask
- We think we have been breached. What do we do right now?
- Contact us and preserve evidence: do not wipe or rebuild affected machines, and do not power them down if they are still running, because volatile evidence is lost when you do. Disconnecting a host from the network is usually safer than switching it off. We will triage, establish scope, and give you containment recommendations before anything irreversible is done.
- Should we pay a ransom?
- We do not advise paying, and we do not negotiate ransoms. Payment funds further attacks, provides no guarantee of recovery, and roughly a fifth of organisations that pay never recover their data. It also does not remove the attacker from your network. Our focus is establishing scope, containing the intrusion, and recovering from backups where they exist. Where they do not, we say so plainly.
- Do we need to report a breach in Namibia?
- Namibia’s data protection framework is advancing toward a regime with a Supervisory Authority and notification obligations, and the Cybercrime Bill establishes a Cybercrime Directorate under CRAN alongside a national incident response function. Sector regulators including the Bank of Namibia and NAMFISA also have supervisory expectations. We support the decision with evidence, and we recommend taking legal advice on your specific obligations.
- Can you help if we are not already a monitoring customer?
- Yes. Incident response is available as a standalone engagement to any Namibian organisation. Investigation is harder without existing telemetry, because there is less history to reconstruct from, but forensic artefacts on affected hosts frequently carry enough to establish what happened and how far it reached.
- How quickly can you respond?
- Triage begins on contact. Because the team is in Windhoek, engagement does not wait for another timezone to open, and for confirmed incidents we work to the escalation timings agreed in your service arrangement. For organisations without an existing arrangement, we prioritise by severity and business impact.
Related
Services often taken together
- Operational
Managed SOC
A staffed security operations centre in Windhoek monitoring your endpoints, servers and network around the clock, so you do not have to build one.
Explore - In deployment
Threat Hunting
Analyst-led hunts across your Namibian estate for intrusions that never triggered an alert, delivered as a scheduled engagement or on suspicion.
Explore - Operational
Security Assessment
An independent review of your current security posture, producing a prioritised and costed improvement plan rather than a list of findings.
Explore
Get started
Scope incident response for your organisation
Tell us what you run and what concerns you. We will come back with a scoped proposal rather than a generic price list.