Skip to main content
Cybersecurity Breach

How quickly should we act on a suspected breach indicator?

Immediately. Every hour of delay after an initial indicator is observed is additional time the attacker has to move laterally, exfiltrate data, or prepare for ransomware deployment.

Can we investigate a breach internally without outside help?

What logs should we check first when investigating unusual activity?

Is it possible to have been breached without any visible symptoms?

What is the first call we should make if we suspect a breach?

John Angelotti

John Angelotti is the President of DCG Technical Solutions, beginning his technology journey on a Commodore 64 and at swap meets with his mother. For more than two decades, he has helped businesses grow through secure, strategic, and cost-effective IT leadership.

At DCG, he works to ensure clients can grow without worrying about downtime. As the leader of a security-forward MSP, he develops tailored solutions that safeguard each client’s operations and reputation.

John is known for making complex technology easy to understand and guiding organizations through key improvements, from cloud migrations to cybersecurity hardening. Outside of work, he enjoys building things with his hands, archery, hiking, and competitive custom car audio.