I will respond to your hack, compromise, cyber security incident or data breach
Enterprise Security Architect, Cyber Essentials and ISO 27001 Specialist
Vetted by Fiverr Pro
Jon Jones was selected by the Fiverr Pro team for their expertise.
Vetted for
Support & IT
About this Gig
Vetted Pro
Your finance team just paid an invoice. The bank details were changed. The email came from your own domain. Except it didn't.
That's business email compromise, and I've just worked one end to end for an overseas marketing agency: hijacked mailbox, invoice with swapped bank details, a lookalike domain one letter off the real one, and a Managing Director who needed to know what to do next in plain English with numbered steps a non-technical owner can follow while I work the technical side.
What you get:
- Compromise assessment: what happened, what's still exposed, what to do next
- Containment: attacker locked out of email, cloud, servers or website, forwarding rules killed, sessions revoked, lookalike domain blocked
- Evidence preservation, not deleted: in case you're asked for evidence
- Bank, insurer, regulator, and authorities fraud reporting support
- Breach-data and dark web check on your domain, so you know what's already out there
- Plain-English write-up for your board or clients
Who I am: over 20 years in secure information technology, Certified Ethical Hacker, CISSP, CREST, and IASME-appointed Cyber Essentials Certification Body.
Device:
Desktop
•
Laptop
•
Server
•
Mobile
•
Router
Operating system:
Windows
•
Linux
•
IOS
•
Android
•
Ubuntu
My Portfolio
FAQ
What do you need from me to start?
Admin or read only access to whatever's affected (email, cloud, server, website) would be helpful, any suspicious emails as attachments or current evidence where possible, and ideally a contact who can make decisions. Access can be a temporary account you delete afterwards.
Can you check whether company data has been exposed?
Yes. I can check recognised breach-exposure sources for company domains, email addresses and credential indicators. This is a supporting check, not continuous dark-web monitoring, and results depend on the sources available.
Will you need administrator access?
Not always. Initial triage can begin with emails, headers, screenshots, logs and a guided call. Deeper investigation may require temporary authorised access or cooperation from your IT provider. Never paste passwords into the requirements form.
Is the report suitable for management or insurers?
Yes. Standard and Premium include clear findings, observed evidence, actions taken or recommended, remaining risks and next steps. It can support discussions with management, IT, insurers or legal advisers, but is not legal advice.
Will you fix and recover everything yourself?
Scope depends on the package, available access and your environment. I can guide or perform agreed containment and hardening steps, but some changes may need your internal or external IT team, cloud hosting provider, or DNS registrar, for example.
