48h
To full containment
0
Ransom paid
7 days
To safe restoration
The Challenge
Critical patient systems were encrypted overnight. The client needed to contain the spread, understand how attackers got in, and preserve court-admissible evidence — all while restoring care operations.
Our Approach
Our incident-response team isolated affected segments, imaged endpoints and memory, and reconstructed the attack timeline from logs and malware artefacts while maintaining strict chain-of-custody.
The Outcome
We traced the intrusion to a phishing-delivered loader and an unpatched VPN appliance, eradicated persistence, and guided a clean restore from validated backups. A forensic report supported the client's cyber-insurance and legal proceedings.