Story · Engineering · Ransomware
Out of business for two weeks. Insured again when it was over.
A threat actor spent weeks inside the network before doing anything visible. By the time we got involved, the firm had been effectively out of business for two weeks.
The situation
A long-established engineering firm doing public-sector infrastructure work, with decades of project records to protect.
Their firewall firmware was two and a half years out of date. A threat actor got in and embedded themselves. They sat inside the network for several weeks, reviewed the accounting system, and learned what the firm's cash flow looked like before doing anything visible. Then, they pushed the button on a planned and coordinated attack. The backup infrastructure was thin, and nothing was stored offsite, so every backup was deleted and everything was encrypted at once. The ransom demand was six figures.
According to our contact at the time, leadership of their existing IT provider never came onsite and never called. A junior technician was sent to rebuild computers one at a time. Much of the remediation attempt fell on internal staff. The firm was effectively out of business for two weeks before we arrived. Their cyber liability insurer brought in a forensics team, who negotiated the ransom down substantially before it was paid. Fortunately, the recovery key that was provided worked and they were able to start unlocking their files.
What we did
We got involved during week three and immediately started a triage operation. Our account manager described it as running into a burning building. We deployed a security stack and set of standards in under three weeks. This type of onboarding at the time would normally take up to six months to roll out across an environment like theirs. Going back to how things had been before the attack was not an option.
Then came the part nobody expects. The assumption was that no insurance carrier would write them again after a modest premium had produced a six-figure payout. We worked with their insurance broker and the several carriers they were quoting, documented every control we had deployed and when, and were an instrumental part in getting them insured again.
What changed
ResolvedThe firm is still in business and has had no incident since. As our support team began working with them after the incident was mitigated, their read was that the firm did not trust us because they did not trust anybody in our industry after such a negative experience. Over time, trust was gained and we continue to have a strong relationship as their IT vendor.
Order the internet circuit the week the lease is signed. Carriers take six to twelve weeks. Nothing else on a move fails as often.
The relocation checklist Did you knowA backup that has never been restored is a hope, not a plan. Ask for the date of the last tested restore.
What to actually testQuestions people ask about this
Would insurance have covered us?
Probably, and it will also ask you hard questions afterwards about the controls you said you had. The questionnaire is where most businesses discover the gap, which is why we would rather fill it in with you before renewal.
How long do attackers sit in a network before acting?
Often weeks. The encryption is the last step, not the first. By then they have read enough to price the demand against what you can pay.
Can a business get insured again after a ransomware payout?
This one did. Carriers want to see what changed: which controls are in place, and when each one was deployed. That record is what we put in front of the broker and the carriers they were quoting.

"Great to work with Zach. Excellent follow-up and directions. Even helped lower our bill from Xfinity!"
Client, 2024 surveyMore from the survey wall- A technician who knows your setup takes every request. Not a dispatcher, not a queue.
- Every closed ticket is surveyed and a partner reads every response.
- 99.5% of surveys come back positive.
- Family-owned since 2005. 21 years in the same corner of Wisconsin, not going anywhere.
"Thanks for the hard work. I was kept informed with regular updates until the concern was resolved."
Jeff, insurance brokerageWould your backups survive being deleted?
A protection assessment tells you what is exposed. What you do with it is your call.
Talk to a partnerTalk to a partner, not a sales script.
Tell us what is going on. A partner will call you back the same business day, look at what you have, and tell you honestly whether we are the right fit. No pricing pressure, no pitch deck.
