← ResourcesCybersecurity

A client got hit with ransomware at 11pm. Here's the hour that saved them.

Ransomware doesn't wait for office hours. A real account of how monitoring, standby engineers and tested backups turned a disaster into a Tuesday.

Ransomware never seems to strike at a convenient time. In our experience it’s almost always after hours — evenings, weekends, the middle of the night — precisely because attackers know that’s when nobody’s watching.

So here’s roughly how one of these plays out when the right things are in place. Details are anonymised, but the shape of it is real and familiar.

11:04pm — the alert

An endpoint on the client’s network starts behaving strangely: a process rapidly touching hundreds of files. Nobody’s in the office. But our monitoring is, and SentinelOne — the endpoint protection we deploy — doesn’t wait to ask permission. It automatically isolates the affected machine from the network, stopping the encryption from spreading. That automated first move, in the seconds before any human is involved, is often the whole ballgame.

11:12pm — a human is on it

The alert reaches our standby engineer. This is the bit a lot of businesses don’t have: at 11pm, someone whose job it is to respond actually responds. They confirm it’s a genuine ransomware attempt, check that the isolation held, and start working through the containment steps — which accounts are involved, what was reachable, what needs locking down.

11:40pm — assessing the damage

One machine encrypted. The spread stopped at the network’s edge because of the isolation. Now the question everyone dreads: the data. And here’s where a decision made months earlier pays off — the client had tested, off-site backups. Not “we have backups somewhere,” but backups we’d actually restored from in a drill, kept separate from the main network so the ransomware couldn’t reach them.

The next morning — a Tuesday, not a catastrophe

The affected machine is wiped and rebuilt. Data is restored from the clean backup. The team logs in and works. There’s a post-incident review, some tightening of controls, a security-awareness refresher on the phishing email that started it. But the business didn’t stop, didn’t pay a ransom, and didn’t lose data.

Why it went the way it did

None of this was luck. It came down to three things that were in place before the attack:

  • Automated endpoint protection that acts in seconds, not minutes.
  • Someone actually watching and on call after hours, when attacks happen.
  • Tested, isolated backups — the difference between “restore and carry on” and “pay the ransom and pray.”

The businesses that come through ransomware well aren’t the ones that were never targeted. Everyone gets targeted eventually. They’re the ones who’d quietly done the unglamorous work in advance.

If you’re not confident all three of those are true for your business right now, that’s exactly what a free Cyber Health Check is for — better to find out on a calm afternoon than at 11pm.

Keep reading