Under attack? Get emergency help now

Incident Response

Containing a ransomware outbreak at a manufacturing unit

Emergency response to a ransomware incident that had begun encrypting shared drives, with production restored inside 48 hours.

Client

Auto-component manufacturer (anonymised)

Duration

6 days

48 hrs

To production restore

0

Ransom paid

100%

Critical data recovered

The challenge

File shares and two ERP servers were encrypting rapidly. The plant risked halting a shift, and the team had no incident-response plan or reliable offline backup inventory.

What we did

  • Immediate containment: network isolation of affected VLANs and account lockdown
  • Forensic triage of endpoints, domain controller logs, and VPN authentication records
  • Backup integrity verification before any restoration attempt

Key findings

Critical

Initial access via an internet-exposed RDP host with a reused local admin password.

Critical

Flat network allowed lateral movement from office IT straight into plant systems.

High

Backup server joined to the same domain, leaving backups within blast radius.

Remediation

  • RDP removed from the internet; VPN with MFA introduced
  • IT/OT segmentation with strict inter-zone rules
  • Immutable, domain-detached backup tier with tested restore runbooks
  • EDR rolled out across all endpoints and servers