Incident Response
Containing a ransomware outbreak at a manufacturing unit
Emergency response to a ransomware incident that had begun encrypting shared drives, with production restored inside 48 hours.
Client
Auto-component manufacturer (anonymised)
Duration
6 days
48 hrs
To production restore
0
Ransom paid
100%
Critical data recovered
The challenge
File shares and two ERP servers were encrypting rapidly. The plant risked halting a shift, and the team had no incident-response plan or reliable offline backup inventory.
What we did
- Immediate containment: network isolation of affected VLANs and account lockdown
- Forensic triage of endpoints, domain controller logs, and VPN authentication records
- Backup integrity verification before any restoration attempt
Key findings
Initial access via an internet-exposed RDP host with a reused local admin password.
Flat network allowed lateral movement from office IT straight into plant systems.
Backup server joined to the same domain, leaving backups within blast radius.
Remediation
- RDP removed from the internet; VPN with MFA introduced
- IT/OT segmentation with strict inter-zone rules
- Immutable, domain-detached backup tier with tested restore runbooks
- EDR rolled out across all endpoints and servers
