
Ransomware recovery after full encryption
After full encryption: secure the rebuild and protect it for the long term.
An industrial company was hit by a ransomware attack with full encryption. ODCUS led the threat-management stream during the rebuild.
Starting point
The IT infrastructure had to be rebuilt from scratch. At the same time, the restored systems had to be secured immediately so the incident would not repeat.
Approach
- Priority management for the rebuild of the IT infrastructure
- Threat and risk analysis after the attack
- Implemented protective measures, including Microsoft Defender configuration
- Connected an external SOC team for continuous monitoring
- Analyzed and remediated vulnerabilities
- Strategy and roadmap for security beyond the recovery phase
Result
- A controlled, prioritized rebuild instead of firefighting
- A secured infrastructure with monitoring and incident response
- A connected SOC for continuous monitoring
- A roadmap that carries beyond the recovery
Frameworks and tools used
Microsoft DefenderMITRE ATT&CKZero TrustIncident Response