Business email compromise
The bread and butter. Someone gets tricked and money moves.
TriageIt rarely looks like an attack. It looks like a normal invoice from a supplier you have paid a hundred times before.
Security engagement
Something already happened. We find out how, stop the damage, and make sure it cannot happen the same way twice. When a Lafayette or Acadiana business calls after an incident we go on site, and we do the same anywhere in Louisiana.
A mission critical call goes to the top of the list at no extra charge.
Traced after the factMethodology
Call and you go to the top of the list. No extra fee, no tier to argue with, no ticket to file first.
One of us picks up, and you are on the calendar immediately.
The whole shop looks at your problem before anyone drives out, so the technician who arrives already has the full picture.
Attack, insider, or honest mistake. Those three go very different directions.
How it got in, if there was a way in at all.
Speed and remediation. Get you working again.
If the damage looks criminal, we keep notes and hold what evidence we can while we remediate.
New protections, a new process, and your people taught to spot it next time.
The argument
Social engineering is the worst kind of attack because it puts a person into fight or flight and convinces them they have no choices left. A good deal of what we do in that first hour is hand those choices back.
We are not just a technician for the client. We are 50 percent technician and 50 percent counselor. We have to hear you and take the weight off your shoulders, then fix the problem.
A fraudulent transfer can sometimes still be stopped or clawed back.
The trail is fresh, so the vector gets traced rather than guessed at.
Evidence is preserved while we remediate, in case the matter turns legal.
The fix goes in while everybody still remembers exactly what they saw.
Money that moved days ago is usually money that is gone.
Logs roll over, mailboxes get tidied, and the trail thins out.
Somebody deletes the evidence while trying to clean up.
The same trick gets run again, because nothing about it changed.
Very little can happen now that has not already happened. What is still open is what you do in the next hour.
Business email compromise brings most people here. Somebody gets tricked, money or data moves, and the business finds out afterwards. It is far less often dramatic ransomware than people expect.
If it is happening right now
Tell us clearly what you saw and when. If we tell you to unplug something or not to click something, do it immediately. And if somebody is still in contact with you, pressuring you or narrowing your choices, give them nothing. That call works the same from Lafayette, from anywhere in Acadiana, or from the other side of Louisiana.
What you receive
Getting you working again comes first, always. Everything else happens alongside that rather than instead of it. Incidents get worked on site, in Lafayette and at addresses across Louisiana.
Remediation and hardening run at $150 an hour, the same as any other call. If you have your own IT team we hand off the findings or work alongside them.
What it costs
There is no incident retainer here and no tier of support to buy your way past. You call the main line, one of us picks up, and you are on the calendar.
Behind the scenes the whole shop does an all hands on your problem, so the technician who drives out arrives with the full range of the team behind them. One person shows up. Everybody has already looked at it.
After hours and weekend work is billed at time and a half, holidays at double time. The call where you describe what happened is not billed at all.
Remediation handoff
Once the bleeding has stopped, the work carries on into making sure the same thing cannot happen twice. New protections, a new process, and your people taught to recognise the trap next time.
One case ended with two factor plus two verbal authorizations required on every transfer going forward. That change cost nothing to make and it is the part of the engagement that actually paid for itself.
See how On-Demand IT worksField findings
It is far less often dramatic ransomware than people expect. This is what we actually get called for.
The bread and butter. Someone gets tricked and money moves.
TriageIt rarely looks like an attack. It looks like a normal invoice from a supplier you have paid a hundred times before.
We traced one $90,000 loss back to a compromised vendor mailbox and lookalike addresses that swapped a lowercase L for an I. At a glance they were identical.
Finding the vectorThe lookalike address is the detail people never forgive themselves for, and they should. At a glance it is identical. That is the entire point of it.
A disgruntled employee, usually with access that was never closed when it should have been.
TriageAlmost always access that should have been removed when somebody left. The same gap a penetration test finds, used by somebody who already knew it was there.
Not a client finding. This is the shape our Security Alerts take, and the same plain language we use on the phone.
Any business that pays suppliers by transfer and accepts banking changes over email.
Call the supplier on a number you already had before the email arrived, not the one in the signature. Then require a second verbal authorization on every change from here on.
Drawn from our own incident work. No client names, no dates.
Before the trail gets colder
The clearer the picture you can give us, the more prepared we are when we arrive. There is no charge for telling us what you saw.
AI forensics
More small businesses are bolting AI onto their operations every month, and when one of those systems fails it fails in a way nobody in the building can explain. It looks like a break-in, or it looks like the thing has lost its mind. It is usually neither.
The work is the same work as any other incident. We recover the machines, reconstruct the timeline out of what the system left behind, and find the cause. Once you can see it the answer is usually mechanical and dull, and that is the good news. A theory cannot be fixed. A cause can.
Read the case: An AI didn't go rogue. It was left holding a mop.
Coverage
Lafayette is home base and Acadiana is the everyday radius. For this work we drive most of Louisiana, so Baton Rouge and Lake Charles are ordinary trips rather than exceptions. Anything past that gets sorted out on the phone before anybody leaves.
Each city page says what this work looks like in that town.
Lafayette Parish
Across Louisiana
Questions
The questions people ask when they call us in a panic, answered honestly.
Sometimes. A fraudulent ACH can occasionally be stopped or clawed back if we catch it fast enough. Sometimes it is gone. Either way the faster you call, the more options stay on the table.
That is the question we most want to hear. Every incident we work ends with new protections, a new process, and your team taught to recognise the trap.
Sometimes. We trace the vector and work out how it happened. Attribution is not always possible, and we will be straight with you about what we can and cannot determine.
Breathe. Very little can happen now that has not already happened. Tell us clearly what you saw and when. If we tell you to unplug something or not to click something, do it immediately. And if somebody is pressuring you or narrowing your choices, give them nothing.
Network forensics is what we do in house: traffic, logs, and what moved across the network. When a case needs disk imaging or phone extraction, we bring in a forensics partner we trust.
Yes. Incident work runs from Lafayette out through New Iberia and the rest of Acadiana, and we go statewide for it. Part of the first hour happens over the phone and over a remote session while somebody is heading your way.
No contract required
Scoped and quoted before it starts, billed hourly, and the work is yours when it is done. No retainer, no monthly fee, no managed services agreement.
We are based in Lafayette and serve all of Acadiana, and the statewide coverage is real: we drive most of Louisiana for on-site work.