Case Study

How a Proactive Security and Backup Strategy Saved a Firm from a Ransomware Disaster

Introduction

Ransomware attacks are getting more sophisticated, and with their multi-stage attacks, they are affecting more businesses and organisations across Australia. Experiencing a ransomware attack is more a question of "when" than "if." And when it happens, a proactive managed cyber security approach combined with a robust backup strategy is essential for quick recovery from an IT disaster.

In this case study, we will compare two companies: Firm A and Firm B.

Both faced a similar ransomware attack but experienced different outcomes due to their cyber security strategies. Their response shows the difference between a manageable disruption and a serious business threat, and why the level of managed security you have in place matters. 

In a nutshell


Organisation

Firm A (Managed Security Basics)

Firm B (Managed Security Proactive)

Detection Time

Next Day

Real-time

Downtime

7 days

Under 2 days

Backups

Encrypted but unrecoverable

Isolated & fully restorable

Recovery Cost

Significant (data recovery + lost productivity)

Minimal

The Challenges

Firms A and B were both targeted by a highly advanced ransomware attack.

This complex malware compromises servers and use various methods to infiltrate and encrypt sensitive business data, while also deleting on-site and cloud backups. If not addressed promptly, this kind of ransomware attack could severely disrupt operations and cost the organisations both profit and reputation.

Here’s how each firm responded to the ransomware attack based on their respective cyber security and backup strategies.

Scenario Comparison

Firm B: With Managed Security Proactive

Firm B was on OSIT's Managed Security Proactive tier which layers various protection on top of the essentials.

Using SentinelOne and proactive monitoring, Firm B detected the ransomware in real-time.

The ransomware attempted to launch from the server but was blocked.

The attacker tried to bypass security by launching a new virtual machine to attack from the compromised server.

SentinelOne minimised the damage by initiating rollbacks and file restoration.

Outcome

The ransomware attack was contained within hours with minimal disruption, despite its complexity.

Firm A: Without Managed Security Proactive

Firm A had Managed Security Basics (MFA, antivirus, anti-spam, encryption), but without proactive protection.

Firm A did not detect the ransomware attack until the next day.

With no monitoring and prevention during out-of-office hours, the attackers had enough time to infiltrate Firm A's network overnight

There was no rollback feature, so they had to rely on backups for recovery.

Outcome

The ransomware attack led to serious downtime and costly recovery work. It also made one thing clear: without proactive protection like Managed Detection and Response (MDR), the business was left far too exposed.

Backup Strategy Impact

Firm B: With Isolated Backups


The attacker can't access the backup server because it wasn’t joined to the domain.

The NAS was only accessible via the backup server, so ransomware (or other types of cyber attacks) couldn’t access it.

On-site backups remained safe and ready to restore immediately.

Outcome

Quick and easy recovery, with minimal downtime.

Firm A: Without Isolated Backups


Firm A relied on a single server to manage everything, including backups.

The ransomware easily accessed the backups because they were on a domain server.

 All data backups stored on server-attached HDDs were encrypted and unrecoverable.

Outcome

Major data loss and delayed operational recovery + costly recovery.

The Results

Given the increasing frequency of ransomware attacks, taking a proactive approach to cybersecurity and backup strategies can significantly mitigate the impact of an attack. Similar to Firm B’s proactive method with isolated backups, they transformed a potentially devastating ransomware incident into a manageable event with little to no downtime.

In contrast, Firm A’s experience with Managed Security Basics shows that basic protection alone may not be enough to stop fast-moving attacks after hours, and that isolated backups are just as important as detection.

Although both Firms A and B had immutable backups, Firm B didn't need to use theirs. When Firm A's server-attached HDD backups could not be recovered, the immutable backup became their last line of defence and helped avoid further downtime and added recovery costs.

Proactive security and backup solutions are now essential for any SME, especially considering how frequently ransomware attacks target them.

Don’t wait for an attack to occur. Start implementing a proactive managed IT security plan today with your trusted IT professionals.

Our Recent Blogs

Check out our recent blogs below, or browse our full range of blog articles for more insights, guidance and support content.

Is Your IT Holding You Back? 9 Signs You Need to Upgrade to Modern IT Infrastructure Solutions

Is Your IT Holding You Back? 9 Signs You Need to Upgrade to Modern IT Infrastructure Solutions

Your IT should support your business, not hold it back from its real potential. For many small and...
Boost Efficiency and Compliance: Establish Data Governance in Your SME with Microsoft Purview

Boost Efficiency and Compliance: Establish Data Governance in Your SME with Microsoft Purview

Establishing data governance in your SME is no longer an option. In today's digital age,...
Why You Need Cyber Security in Your Perth Business

Why You Need Cyber Security in Your Perth Business

The never-ending rise of cyber threats has transformed how businesses approach technology –...
Cyber-Security-Service-Popup-1-1

Fortify your business with immutable backups

Never worry about downtimes and the repercussions of cyber risks again.

Strengthen your cyber defences with an expert team of Australia-based IT experts, ready to reduce your IT security headaches.