Hozit Domain Hosting — Smart technology. Powerful results.010 502 2517 · info@hozit.co.za · 24/7 Support
Level 1 B-BBEE100% Black Owned24/7 SupportSouth African Technology Partner
Investigate Incidents, Preserve Evidence and Restore Confidence

Respond to cyber incidents quickly, preserve critical evidence and understand what happened

Hozit provides digital forensics and incident response services for ransomware, business email compromise, insider threats, malware infections, unauthorised access, data breaches and suspicious activity across endpoints, servers, email, cloud and network environments.

Service Overview

Professional IT support for growing and established organisations

Cyber incidents require fast, controlled and well-documented action. Poorly handled incidents can destroy evidence, increase downtime and make it difficult to determine the true cause and impact.

Digital forensics focuses on collecting, preserving and analysing evidence, while incident response focuses on containment, eradication, recovery and communication.

Hozit helps organisations investigate suspicious activity across endpoints, servers, email systems, Microsoft 365, Azure, AWS, applications and network infrastructure.

Our approach supports technical decision-making, management reporting, legal processes, insurance requirements and selected regulatory obligations.

All investigative activities are performed within an approved scope and according to agreed evidence-handling procedures.

Business Challenges

Common IT problems we help solve

Unclear incident scope

Organisations may not know which systems, accounts or data are affected.

Evidence destruction risk

Logs, volatile memory and temporary files may be lost during uncontrolled response.

Ransomware disruption

Encrypted systems can interrupt operations and create major financial exposure.

Business email compromise

Compromised mailboxes may be used for fraud, invoice manipulation or data theft.

Insider threat concerns

Suspicious employee or contractor activity can be difficult to prove.

Cloud investigation gaps

Relevant evidence may be distributed across Microsoft 365, Azure or AWS.

Weak chain of custody

Poor evidence handling can undermine legal or disciplinary processes.

No incident plan

Teams may respond inconsistently and make avoidable mistakes.

Delayed containment

Attackers may retain access while internal teams investigate.

Regulatory pressure

Data breaches may create notification, reporting and legal obligations.

What Is Included

Comprehensive managed IT support services

The final scope is tailored to the organisation's users, systems, locations, risks and internal capabilities.

Emergency incident triage

Assess the situation, immediate risks and required containment actions.

Incident response mobilisation

Activate the agreed response team, communication channels and responsibilities.

Incident scoping

Identify affected users, systems, locations, applications and data.

Containment planning

Define safe actions to limit further attacker activity or data loss.

Short-term containment

Coordinate immediate actions such as account restriction, endpoint isolation or firewall blocking.

Long-term containment

Support safer temporary operating controls while remediation continues.

Eradication support

Assist with removing malicious tools, access paths, persistence and compromised credentials.

Recovery support

Guide secure restoration of systems, services and business operations.

Post-incident review

Document lessons learned, gaps and improvement actions.

Digital evidence preservation

Preserve relevant files, logs, images and system data.

Chain-of-custody documentation

Record evidence handling, transfer, access and storage.

Forensic imaging

Create controlled forensic copies of approved storage devices.

Disk forensics

Analyse file systems, deleted files, user activity and artefacts.

Memory forensics

Analyse selected volatile memory for processes, connections and malicious activity.

Endpoint forensics

Investigate Windows, Linux and selected endpoint devices.

Server forensics

Analyse selected physical, virtual and cloud-hosted servers.

Network forensics

Review selected traffic, firewall, IDS, VPN and proxy evidence.

Email forensics

Investigate messages, headers, forwarding, mailbox rules and suspicious activity.

Microsoft 365 forensics

Analyse selected Entra ID, Exchange Online, SharePoint and OneDrive evidence.

Azure forensics

Review selected sign-in, administrative, network and resource activity.

AWS forensics

Analyse selected CloudTrail, IAM, network and workload evidence.

Mobile device forensics

Support approved investigation of selected mobile devices and artefacts.

Cloud application forensics

Investigate activity within selected SaaS and hosted platforms.

Web server log analysis

Review selected access, error and application logs.

Database activity analysis

Review selected authentication, query and privilege evidence.

Active Directory investigation

Analyse account, group, authentication and policy activity.

Privileged account investigation

Review suspicious administrative and elevated activity.

User activity reconstruction

Reconstruct selected user actions across available evidence.

Timeline reconstruction

Develop a chronological view of relevant events.

Root-cause analysis

Identify the likely initial access point and contributing control failures.

Attack-path analysis

Map how an attacker moved across systems and accounts.

Persistence analysis

Identify mechanisms used to retain access.

Privilege escalation analysis

Determine how elevated access may have been obtained.

Lateral movement analysis

Determine how compromise spread between systems.

Command-and-control analysis

Review communications with suspected malicious infrastructure.

Data exfiltration analysis

Assess whether information may have been copied or transmitted externally.

Malware triage

Classify suspicious files and determine likely behaviour.

Malware analysis

Analyse selected malicious code, indicators and execution behaviour.

Ransomware investigation

Determine likely entry point, spread, impact and persistence.

Ransomware readiness review

Assess backup, segmentation, endpoint and response weaknesses after an event.

Business email compromise investigation

Investigate mailbox access, forwarding, impersonation and fraudulent activity.

Phishing incident investigation

Analyse malicious messages, links, attachments and affected users.

Credential theft investigation

Assess compromised passwords, tokens and authentication activity.

Account takeover investigation

Review suspicious logins, MFA changes and administrative actions.

Insider threat investigation

Analyse approved evidence relating to suspected internal misuse.

Unauthorised access investigation

Determine how access was obtained and what activity occurred.

Data breach investigation

Assess systems, records, exposure and possible information loss.

Website compromise investigation

Investigate malicious files, account misuse and web application activity.

Server compromise investigation

Analyse suspicious processes, accounts, services and network activity.

Cloud compromise investigation

Review selected identity, resource and configuration events.

Lost or stolen device investigation

Assess available evidence and possible data exposure.

Fraud investigation support

Analyse approved digital evidence linked to suspected fraud.

Invoice manipulation investigation

Review mailbox activity and communications associated with payment fraud.

Domain spoofing investigation

Assess lookalike domains, spoofed email and related abuse.

Log preservation

Secure relevant logs before retention periods or rotation remove evidence.

Security event correlation

Correlate evidence from multiple systems and sources.

Indicator-of-compromise extraction

Identify malicious domains, IP addresses, hashes, accounts and artefacts.

Threat intelligence enrichment

Use selected threat intelligence to add context to findings.

Compromise assessment

Assess whether selected systems show evidence of unauthorised activity.

Scope validation

Confirm whether additional systems or accounts require investigation.

Evidence integrity verification

Use hashes and controlled handling to support evidence integrity.

Legal hold support

Assist with preserving approved digital records for legal processes.

Litigation support

Provide technical analysis and reporting for approved legal matters.

Disciplinary investigation support

Support internal investigations with documented technical findings.

Expert technical reporting

Prepare structured findings for management, legal advisers or insurers.

Executive incident report

Summarise incident cause, impact, response and recommendations.

Technical forensic report

Document evidence sources, methods, findings and limitations.

Incident chronology

Provide a detailed timeline of relevant events.

Impact assessment

Evaluate affected systems, accounts, data and business operations.

Data exposure assessment

Assess whether sensitive or personal information may have been accessed.

POPIA breach support

Support technical fact-finding relevant to personal-information incidents.

Regulatory reporting support

Provide selected technical information for authorised reporting processes.

Cyber insurance support

Provide selected evidence, timelines and reports for insurer requirements.

Law-enforcement liaison support

Prepare approved technical evidence for engagement with authorities.

Stakeholder communication support

Assist with accurate technical updates for management and affected parties.

Incident communication templates

Prepare selected internal and external response communications.

Board-level briefing

Explain incident impact, response and outstanding risk in business terms.

Remediation planning

Develop prioritised actions to close identified weaknesses.

Credential reset planning

Coordinate secure password, token and key changes.

Endpoint rebuild guidance

Define when systems should be cleaned, restored or rebuilt.

Server recovery guidance

Support secure restoration and validation of servers.

Cloud remediation guidance

Address compromised identities, permissions, services and configurations.

Firewall remediation guidance

Implement approved blocks, segmentation and access restrictions.

Email remediation guidance

Correct forwarding, mailbox rules, authentication and domain protections.

Backup integrity review

Assess whether backups are available, protected and suitable for recovery.

Recovery validation

Confirm that restored systems are secure and operating as intended.

Monitoring enhancement

Define additional logging, SIEM and alerting requirements.

Detection rule development

Create selected detection logic based on incident findings.

Incident response plan development

Document roles, procedures, escalation and communication requirements.

Digital forensics readiness assessment

Assess evidence sources, retention, logging and investigative capability.

Tabletop incident exercise

Test response roles and decision-making using a controlled scenario.

Ransomware tabletop exercise

Simulate ransomware response, communication and recovery decisions.

Business email compromise exercise

Test response to fraudulent email and account takeover.

Executive incident exercise

Prepare senior leadership for high-impact cyber incidents.

Incident response retainer

Provide pre-agreed access to response support and planning.

Continuous improvement review

Track remediation and strengthen response maturity over time.

Business Benefits

Why organisations choose managed IT support

Faster incident control

Structured triage and containment reduce confusion and delay.

Preserved evidence

Controlled collection and documentation support reliable investigations.

Clear root-cause insight

Forensic analysis helps determine how the incident occurred.

Improved recovery decisions

Evidence-based guidance helps teams restore systems safely.

Reduced repeat risk

Remediation actions address the weaknesses that enabled the incident.

Better legal and insurance support

Documented findings support approved external processes.

Improved regulatory readiness

Technical findings support selected breach and compliance obligations.

Stronger future resilience

Lessons learned improve detection, response and recovery capability.

Our Methodology

From discovery to ongoing improvement

1

Triage the incident

Confirm urgency, likely impact and immediate risks.

2

Authorise the investigation

Define scope, evidence sources, decision-makers and legal requirements.

3

Preserve evidence

Secure relevant systems, logs, files and forensic images.

4

Contain the threat

Coordinate actions to limit further damage or unauthorised activity.

5

Analyse the evidence

Examine endpoints, servers, email, cloud and network data.

6

Reconstruct the timeline

Identify initial access, attacker activity and affected assets.

7

Determine impact

Assess compromised systems, accounts, data and business operations.

8

Eradicate and recover

Remove persistence, close access paths and restore services securely.

9

Report findings

Provide executive, technical and evidence-based reporting.

10

Improve resilience

Implement lessons learned, monitoring and remediation actions.

Engagement Options

Flexible IT support models

Emergency incident response

Rapid support for an active or suspected cyber incident.

Digital forensic investigation

Focused evidence collection, analysis and reporting.

Ransomware response

Investigation, containment, recovery and remediation support.

Business email compromise response

Mailbox, identity and fraud-related investigation.

Insider threat investigation

Approved investigation of suspicious internal activity.

Cloud incident investigation

Forensic review of Microsoft 365, Azure or AWS environments.

Incident response retainer

Pre-arranged support, readiness and response access.

Forensics readiness service

Improve logging, evidence retention and investigative preparedness.

Technology Coverage

Platforms and technologies we support

Support is subject to the agreed scope, vendor requirements, licences and available technical documentation.

Digital Forensics Incident Response Forensic Imaging Chain of Custody Disk Forensics Memory Forensics Endpoint Forensics Network Forensics Email Forensics Mobile Forensics Windows Linux macOS Active Directory Microsoft Entra ID Microsoft 365 Exchange Online SharePoint OneDrive Microsoft Azure AWS CloudTrail Firewalls VPN SIEM EDR Antivirus Web Servers Databases Ransomware Investigation Malware Analysis Business Email Compromise Phishing Investigation Insider Threat Timeline Analysis Root-Cause Analysis Data Breach Investigation POPIA ISO 27001 NIST Incident Response MITRE ATT&CK Evidence Integrity Incident Reporting Recovery Planning
Industries

Managed IT support across key sectors

Why Hozit

A practical technology partner for your organisation

Structured response process

Incidents are handled through clear triage, containment, analysis and recovery phases.

Evidence-focused approach

Relevant evidence is preserved and documented carefully.

Broad technical coverage

Investigations can include endpoints, servers, networks, email and cloud.

Business-focused reporting

Findings are explained in terms of operational and organisational impact.

Integrated remediation support

Hozit can assist with servers, firewalls, cloud, email and recovery.

Readiness and prevention support

Post-incident improvements reduce the likelihood of recurrence.

Example Scenarios

How managed IT support can be applied

These are illustrative examples and are not presented as named customer case studies.

Ransomware attack

Investigate initial access, spread, affected systems and recovery requirements.

Compromised Microsoft 365 mailbox

Review sign-ins, forwarding rules, impersonation and fraudulent activity.

Insider data theft concern

Analyse approved endpoint, file, email and access evidence.

Website compromise

Identify malicious files, attacker activity and affected accounts.

Lost executive laptop

Assess encryption, account exposure and possible data-access risk.

Cloud account takeover

Review identity, privilege, resource and data-access activity.

Frequently Asked Questions

Managed IT support FAQs

What is digital forensics?

Digital forensics is the controlled collection, preservation and analysis of digital evidence.

What is incident response?

Incident response is the process of identifying, containing, eradicating and recovering from a cyber incident.

When should we contact Hozit?

Contact Hozit as soon as suspicious activity, ransomware, account compromise or data exposure is detected.

Can you respond to ransomware?

Yes. We can assist with triage, containment, investigation, recovery guidance and reporting.

Can you investigate business email compromise?

Yes. We can review sign-ins, mailbox rules, forwarding, messages and related account activity.

Do you investigate Microsoft 365 incidents?

Yes. Selected Entra ID, Exchange Online, SharePoint and OneDrive evidence can be analysed.

Can you investigate AWS and Azure?

Yes. Selected cloud identity, administrative, network and resource activity can be reviewed.

Do you preserve evidence?

Yes. Relevant evidence can be preserved using controlled and documented procedures.

What is chain of custody?

Chain of custody records who collected, accessed, transferred and stored evidence.

Can you analyse employee devices?

Yes, where the organisation has appropriate authority and the devices are included in the approved scope.

Do you provide forensic reports?

Yes. Reports can include evidence sources, findings, timelines, impact and recommendations.

Can your reports support legal matters?

Technical reports can support approved legal, disciplinary or insurance processes.

Can you determine whether data was stolen?

We assess available evidence for signs of access, copying or transmission, but conclusions depend on log and evidence quality.

Will you help us recover systems?

Yes. We can support secure restoration, validation and remediation planning.

Should we switch off affected devices?

Avoid unnecessary action until incident-response guidance is available, because volatile evidence may be lost.

Can you help with POPIA breach investigations?

Yes. We can provide technical fact-finding relevant to personal-information incidents.

Do you provide incident response retainers?

Yes. Retainers can include readiness activities and pre-arranged response access.

Can you conduct tabletop exercises?

Yes. We can facilitate ransomware, email compromise and executive incident scenarios.

How long does an investigation take?

Duration depends on incident complexity, evidence volume, system availability and scope.

How do we request assistance?

Provide a summary of the incident, affected systems, known dates, current actions and responsible contacts.

Related Services

Build a stronger technology environment

Improve the reliability and security of your IT environment

Speak to Hozit about your users, infrastructure, support challenges and technology priorities.

Request an IT Assessment
Request a Quote WhatsApp