Full network encryption in 20 minutes. Recovered in three weeks, with no ransom paid.
A mid-sized technology and IT services company operating from two office locations. An unpatched VPN vulnerability let attackers in. Within 20 minutes, every server, every workstation, and every backup was encrypted.
The problem
An unpatched VPN left the door open. Attackers were in and out in 20 minutes.
A known vulnerability in the company's FortiGate SSL VPN had gone unpatched for months. Attackers exploited it, moved directly to Active Directory, and stole credential access. Passwords were stored in a plain-text file on an IT admin's desktop. Within 20 minutes of gaining access, every server, every workstation, and every connected backup was encrypted. The entire business came to a standstill.
The solution
Full recovery in three weeks, built on five stages.
Uniware responded immediately. The recovery followed the NIST Cybersecurity Framework end-to-end, starting with a full assessment of what had been compromised and ending with ongoing monitoring controls in place.
- 1IdentifyMapped every compromised system, credential, and entry point before any restoration began.
- 2ProtectPatched the FortiGate SSL VPN vulnerability, rebuilt Active Directory, enforced MFA, and eliminated plain text credential storage.
- 3DetectDeployed SentinelOne EDR across all endpoints to scan for any remaining threats in the network. Introduced an immutable backup solution so backup data could not be compromised in a future attack.
- 4RespondRestored critical operations from clean backups within five days, prioritising the systems the business needed most to function.
- 5RecoverFull environment rebuilt and operational within three weeks. Network segmentation applied to contain any future incident.
Technologies used
FirewallBefore and after
Where the business was, and where it is now.
| Metric | Before | After |
|---|---|---|
| VPN security | Unpatched FortiGate SSL VPN | Vulnerability patched, remote access hardened |
| Credential management | Passwords in plain text file on desktop | MFA enforced, secure credential storage in place |
| Backup status | All backups encrypted within 20 minutes | Isolated backups restored, offline copies established |
| Network segmentation | Flat network, no containment | Segmented, limits lateral movement in future |
| Endpoint protection | TrendMicro antivirus | SentinelOne EDR with continuous monitoring |
The results
Critical operations in 5 days. Fully recovered in 3 weeks. No ransom paid.
- Critical operations restored within 5 days
- Full environment recovered in 3 weeks
- Zero ransom paid
- Ongoing managed security service agreement signed post-recovery
- Zero repeat incidents since recovery
Facing something similar?
Talk to the Uniware team about ransomware recovery and prevention, before an attack forces the conversation.
Book a Security Review