404 Security Blvd, San Francisco, CA
+1 888 555 0199

At 2:47am on a Friday, a mid-size logistics firm's on-call engineer got the alert every security team dreads: file servers encrypting themselves in real time. Here is exactly how our incident response team contained, eradicated, and recovered — and the lessons every team should take from it.

How the Breach Began

The attacker gained an initial foothold through a stolen VPN credential that lacked multi-factor authentication, then spent nine days moving laterally and mapping backup infrastructure before triggering encryption. By the time the alert fired, the ransomware had already reached three of the client's five file servers.

"The first hour of a ransomware event decides how the next two weeks go. Isolate first, investigate second — never the other way around."

— Alex Vance, Incident Response Lead

Containment in the First 24 Hours

Our team isolated affected segments from the network within 40 minutes of engagement, well before encryption could spread further. Immutable backups — untouched by the attacker — meant restoration could begin almost immediately rather than waiting on a ransom decision.

Network segments isolated within 40 minutes of engagement
Forensic imaging captured before any remediation began
Restoration launched from untouched immutable backups
Credential rotation enforced across every affected account

72 hrs

Total recovery time

$0

Ransom paid

0

Confirmed data exfiltrated

Lessons for Every Security Team

Full recovery took 72 hours end to end, with zero ransom paid and zero confirmed data exfiltration. The single biggest factor was immutable, network-isolated backups — every team we work with since has made that their first investment, ahead of any detection tooling.

Have a Security Question for Our Analysts?