All case studies
CybersecurityData Protection

Full network encryption in 20 minutes. Recovered in three weeks, with no ransom paid.

A mid-sized technology and IT services company operating from two office locations. An unpatched VPN vulnerability let attackers in. Within 20 minutes, every server, every workstation, and every backup was encrypted.

20 Min
Time from access to full encryption
5 Days
Critical operations restored
3 Weeks
Full environment recovered

Client overview

Technology and IT Services

A mid-sized technology and IT services company operating from two office locations.

LocationIndia
Timeline3 weeks, emergency response
Delivered byUniware Systems

Technologies used

Fortinet - Firewall

Veeam - Backup

SentinelOne - EDR

The problem

An unpatched VPN left the door open. Attackers were in and out in 20 minutes.

A known vulnerability in the company's FortiGate SSL VPN had gone unpatched for months. Attackers exploited it, moved directly to Active Directory, and stole credential access. Passwords were stored in a plain-text file on an IT admin's desktop. Within 20 minutes of gaining access, every server, every workstation, and every connected backup was encrypted. The entire business came to a standstill.

The solution

Full recovery in three weeks, built on five stages.

Uniware responded immediately. The recovery followed the NIST Cybersecurity Framework end-to-end, starting with a full assessment of what had been compromised and ending with ongoing monitoring controls in place.

  1. 1
    Identify
    Mapped every compromised system, credential, and entry point before any restoration began.
  2. 2
    Protect
    Patched the FortiGate SSL VPN vulnerability, rebuilt Active Directory, enforced MFA, and eliminated plain text credential storage.
  3. 3
    Detect
    Deployed SentinelOne EDR across all endpoints to scan for any remaining threats in the network. Introduced an immutable backup solution so backup data could not be compromised in a future attack.
  4. 4
    Respond
    Restored critical operations from clean backups within five days, prioritising the systems the business needed most to function.
  5. 5
    Recover
    Full environment rebuilt and operational within three weeks. Network segmentation applied to contain any future incident.

Technologies used

FirewallBackupEDR

Before and after

Where the business was, and where it is now.

MetricBeforeAfter
VPN securityUnpatched FortiGate SSL VPN Vulnerability patched, remote access hardened
Credential managementPasswords in plain text file on desktop MFA enforced, secure credential storage in place
Backup statusAll backups encrypted within 20 minutesIsolated backups restored, offline copies established
Network segmentationFlat network, no containmentSegmented, limits lateral movement in future
Endpoint protectionTrendMicro antivirusSentinelOne EDR with continuous monitoring

The results

Critical operations in 5 days. Fully recovered in 3 weeks. No ransom paid.

  • Critical operations restored within 5 days
  • Full environment recovered in 3 weeks
  • Zero ransom paid
  • Ongoing managed security service agreement signed post-recovery
  • Zero repeat incidents since recovery

What's next. Following recovery, the client moved to an ongoing managed security arrangement with Uniware, covering monitoring, alerting, and incident response support.

Facing something similar?

Talk to the Uniware team about ransomware recovery and prevention, before an attack forces the conversation.

Book a Security Review