Need remote support? Click here

CASE STUDY: INCIDENT RESPONSE

COMPROMISED AT 6:18AM. BACK BY 11:30.

A NZ business with a considered cybersecurity investment was compromised when stolen credentials were used to lock their servers with Bitlocker. A ransom note appeared on the admin desktop. Just over five hours later, they were back live, secure, and hardened. This is how it happened.

EVENTCredential-based ransomware compromise
FROMIndia (geo-spoofed via VPN)
FIRST SYMPTOM6:18am. Bitlocker ransom note
BACK TO BAU11:30am same day

THE CHALLENGE

A "KNOWN USER". STOLEN CREDENTIALS. LOCKED SERVERS.

At 6.18am, a NZ business with a considered cybersecurity investment was compromised. A "known user's" credentials, stolen during overseas travel, had been used from India to elevate privileges, lock the servers with Bitlocker, and leave a ransom note on the admin desktop. By the time the team arrived at the office, the business was effectively offline.

THE RESPONSE

ISOLATE. TRACE. REBUILD.

ACIT immediately isolated internet access and terminated the suspicious offshore connections. We ran forensic analysis on Watchguard endpoint logs to trace the intruder's path through the environment. Servers and firewalls were deep-reviewed and cleaned. MFA with geo-locking was added to VPN access. By 11.30am, just over five hours from first symptom, the business was back live and secure.

THE OUTCOME

BACK FAST. HARDENED HARDER.

Mission-critical data stayed protected. Downtime was minimal. The client moved forward not just back to where they were, but to a hardened posture, with clearer geo-controls, tighter MFA, and a team that had now lived through an incident and knew what to expect. The strongest defences are often built immediately after a real attack.

WHAT CHANGED

BY THE NUMBERS.

WHAT THE RESPONSE LOOKED LIKE

FOUR HOURS OF DECISIVE WORK.

CONTAIN

Isolate & stop the bleed

Internet access isolated immediately, suspicious offshore connections terminated. Stops the attacker doing anything else while we work out what they've already done.

TRACE

Forensic analysis

Watchguard endpoint logs reviewed to map exactly where the intruder went, what they touched, and what they tried. No assumptions, just evidence.

CLEAN

Servers & firewalls deep-reviewed

Every server and firewall examined and cleaned. The environment isn't trusted again until we're sure nothing has been left behind.

HARDEN

MFA + geo-locking on VPN

The vector that let them in is closed. Multi-factor authentication added across the board, with geo-locking so a credential alone can't be used from offshore.

"Live and secure by 11.30am, just over five hours from first symptom to business as usual."

— ACIT Incident Response, in one line

WOULD YOU BE BACK BY 11:30?

Most businesses find out the hard way. A security review tells you in advance, what your exposure is, what your response would look like, and what closing the gaps would cost.

Book a security review