# SoteriaSec | Incident Response and Digital Forensics

> We specialise in assisting organisations that require independent Digital Forensic and Incident Response services



- [SoteriaSec | Terms and Conditions](https://soteriasec.com/terms-and-conditions/) — Terms and Conditions Last updated: August 2026
1. Agreement and Acceptance By accessing and using this website, or by registering for and using any SoteriaSec Pte Ltd (SoteriaSec) hosted services or online products, you agree to be bound by these Terms and Conditions. These terms, together with any applicable service description, privacy policy, or data processing agreement provided by SoteriaSec, form the complete agreement between you (the User) and SoteriaSec and supersede all prior communications, negotiations, arrangements, and agreements, whether oral or written, relating to your use of the website or services.






- [Expert Witness Services](https://soteriasec.com/services/expert-witness/) — SoteriaSec provides independent cybersecurity Expert Witness services to law firms, barristers, insurers, and regulators across Australia and Singapore. Our experts have given evidence in Federal and District Courts in both civil and criminal jurisdictions and have served as independent technical Expert Witnesses in landmark regulatory proceedings invovling the Office of the Australian Information Commissioner (OAIC).
We operate as both independent Expert Witnesses — where our duty is to the Court; and as Consulting Experts, providing technical strategy and analysis to legal teams behind the scenes. Both roles draw on the same depth of experience in digital forensics, incident response, and cybersecurity operations.








- [Breach & Compromise Assessments](https://soteriasec.com/services/breach-assessment/) — Is Your Network Truly Secure? A breach does not always end when an attack is detected. Threat actors often establish long-term persistence within a network, lurking undetected for as long as possible while they compromise more systems and steal your data. Whether your organisation has suffered a ransomware attack, business email compromise (BEC), or unauthorised access to cloud or on-premise systems, a breach assessment helps determine if adversaries are still present, ensuring your business is truly secure.




- [Contact SoteriaSec](https://soteriasec.com/contact/) — 



- [SoteriaSec | Privacy Policy](https://soteriasec.com/privacy-policy/) — DATA PROTECTION NOTICE FOR CUSTOMERS This Data Protection Notice (“Notice”) sets out the basis on which SoteriaSec Pte Ltd (“we”, “us”, or “our”) may collect, use, disclose or otherwise process personal data of our customers in accordance with the Singaporean Personal Data Protection Act (“PDPA”). This Notice applies to personal data in our possession or under our control, including personal data in the possession of organisations in which we have engaged to collect, use, disclose or process personal data for our purposes.




- [About SoteriaSec](https://soteriasec.com/about/) — Welcome to SoteriaSec, your trusted partner in navigating the complex world of cybersecurity. Our team of seasoned professionals specialises in comprehensive Digital Forensics and Incident Response (DFIR) services, catering to organisations facing breaches or internal investigations.
We started as a team that wanted to provide dedicated incident response, digital forensics and security operations services to clients. This is the area we know best and what we do every day; we only provide cybersecurity services within these domains, so you know you are getting specialised staff with deep expertise.




- [SoteriaSec | Vulnerability Disclosure Policy](https://soteriasec.com/vulnerability-disclosure-policy/) — Vulnerability Disclosure Policy Introduction SoteriaSec is committed to ensuring the security of the company and our customers information. This policy is intended to give security researchers clear guidelines for conducting vulnerability discovery activities and to convey our preferences in how to submit discovered vulnerabilities to us.
This policy describes what systems and types of research are covered under this policy, how to send us vulnerability reports, and how long we ask security researchers to wait before publicly disclosing vulnerabilities.




- [Cloud Digital Forensics and Incident Response](https://soteriasec.com/services/cloud-forensics/) — SoteriaSec leads the industry in Cloud Digital Forensics and Incident Response, bringing over 20 years of cybersecurity expertise to our clients. Our team includes specialists who have worked for major US cloud companies in their incident response and investigation teams, providing unparalleled insight and experience.
Expertise in Cloud Incident Response Our deep understanding of cloud environments allows us to swiftly identify and respond to breaches. We are experts in handling Microsoft 365 and Google Workspace email compromises, offering precise and effective solutions to mitigate threats.




- [Cybersecurity Operations](https://soteriasec.com/services/security-operations/) — SoteriaSec specialises in empowering organisations to build robust Cybersecurity Operations, leveraging over 20 years of experience with security operations teams. Our services focus on creating effective detection and response teams, developing comprehensive Playbooks and Standard Operating Procedures (SOPs), and assessing detection coverage to protect your organisation against evolving threats.
Building and Enhancing Incident Response Capabilities We assist in building and optimising Incident Response capabilities, offering expertise in Security Operations Center (SOC) design and SOAR (Security Orchestration, Automation, and Response) automation to streamline and strengthen your Detection and Response teams or CSIRT. Our technical tabletop assessments ensure your team is prepared to handle real-world cyber incidents effectively.




- [Digital Forensics and Incident Response Training](https://soteriasec.com/services/dfir-training/) — SoteriaSec offers comprehensive Digital Forensics and Incident Response (DFIR) Training, led by experienced instructors who are both skilled practitioners and seasoned educators. Unlike theory-based lecturers, our instructors bring real-world experience into the classroom, providing hands-on, practical knowledge.
Onsite and Remote Training Options We offer both onsite and remote training to accommodate the diverse needs of our clients. Whether your team is in a single location or distributed globally, SoteriaSec delivers high-quality training tailored to your specific requirements.




- [Incident Response and Breach Investigations](https://soteriasec.com/services/incident-response/) — Incident Response and Breach Investigation At SoteriaSec, we provide comprehensive Incident Response and Breach Investigation services, with the capability to handle everything from large-scale compromises to targeted attacks on smaller businesses. Our experienced team operates rapidly across remote locations, ensuring immediate and effective responses to security incidents and minimising downtime and data loss.
Rapid Business Email Compromise (BEC) Investigations Specialising in swift BEC investigations, SoteriaSec helps organisations identify and mitigate email breaches quickly. Our deep expertise allows us to track unauthorised access, secure compromised accounts, and prevent further attacks, safeguarding your business&rsquo;s communications and reputation.




- [Internal Digital Forensics Investigations](https://soteriasec.com/services/internal-investigations/) — SoteriaSec offers expert Internal Digital Forensics Investigations, providing independent analysis and unbiased opinions to support your organisation. Our team has extensive experience delivering expert witness reports for mediation and civil disputes, ensuring your case is backed by reliable and professional opinion.
Comprehensive Evidence Collection and Analysis We specialise in covert evidence collection, ensuring thorough investigations while maintaining confidentiality. Our capabilities include gathering evidence from individual hosts and corporate cloud systems, allowing us to comprehensively understand an investigation. We perform targeted evidence collection, focusing on corporate-related data and avoiding non-corporate information to maintain privacy and relevance.



