At 2:47am on a Friday, a mid-size logistics firm's on-call engineer got the alert every security team dreads: file servers encrypting themselves in real time. Here is exactly how our incident response team contained, eradicated, and recovered — and the lessons every team should take from it.
How the Breach Began
The attacker gained an initial foothold through a stolen VPN credential that lacked multi-factor authentication, then spent nine days moving laterally and mapping backup infrastructure before triggering encryption. By the time the alert fired, the ransomware had already reached three of the client's five file servers.
"The first hour of a ransomware event decides how the next two weeks go. Isolate first, investigate second — never the other way around."
— Alex Vance, Incident Response Lead
Containment in the First 24 Hours
Our team isolated affected segments from the network within 40 minutes of engagement, well before encryption could spread further. Immutable backups — untouched by the attacker — meant restoration could begin almost immediately rather than waiting on a ransom decision.
72 hrs
Total recovery time
$0
Ransom paid
0
Confirmed data exfiltrated
Lessons for Every Security Team
Full recovery took 72 hours end to end, with zero ransom paid and zero confirmed data exfiltration. The single biggest factor was immutable, network-isolated backups — every team we work with since has made that their first investment, ahead of any detection tooling.




