DFIR & ForensicsManufacturing / industrialEmergency response over ~4 business days, then a standing retainer
Ransomware recovery for a mid-market manufacturer, with no ransom paid
Mid-market industrial manufacturer, ~500 staff, multi-site plants
Ransomware detonated across a manufacturer's network overnight, encrypting servers and halting production. We took the callout, contained the intrusion in under six hours, and ran a forensically sound recovery from clean backups — restoring critical production within 72 hours without paying the attacker. A retainer now keeps a known responder one call away and shortens the next incident before it starts.
Representative engagement — the client is confidential, and the figures and the quoted comment illustrate typical outcomes for the work described.
- Ransom paid
- $0
- recovered from clean backups
- Time to containment
- under 6 hours
- from callout
- Critical production restored
- 72 hours
- highest-priority systems first
- Data recovered from validated backups
- 96%
- known-good, persistence-checked
The challenge
- Ransomware encrypted servers across multiple sites overnight and stopped production lines, with downtime costing five figures an hour.
- The attacker demanded payment, and leadership wanted recovery without funding a criminal operation or breaching policy.
- The team needed to know how the attacker got in and whether they were still present before bringing systems back.
What we did
- Deployed emergency breach response immediately, isolating affected segments and identity to stop lateral spread.
- Ran ransomware response and containment, then digital forensics to establish the entry point, dwell time and scope of access.
- Validated backups were clean and free of attacker persistence before any restoration began.
- Rebuilt from known-good backups in priority order, bringing critical production systems back first.
- Put an incident-response retainer in place with a known team, documented playbooks and a guaranteed response window.
The outcome
- The intrusion was contained in under six hours from callout, halting further encryption.
- Critical production was restored within 72 hours and no ransom was paid.
- Forensics identified the initial access vector and confirmed the attacker was fully evicted before recovery completed.
- Twelve months on, with the retainer and hardening in place, there has been no repeat incident.
“We called at 2am with plants down and no idea how bad it was. They had the bleeding stopped before the morning shift and had us making product again in three days — without us ever touching the ransom.”