Joint Rapid Ransomware Response and Recovery Operation for an Australian Business

A complex Australian business fell victim to a ransomware attack, which halted their production. They also had some uncertainty about how effective their backups were. Notion Digital Forensics was contacted to provide guidance and expertise, working alongside the company's IT teams, MSP (Managed Service Provider), and MSSP (Managed Security Service Provider) to quickly recover from the incident.

A complex Australian business fell victim to a ransomware attack, which halted their production. They also had some uncertainty about how effective their backups were. Notion Digital Forensics was contacted to provide guidance and expertise, working alongside the company’s IT teams, MSP (Managed Service Provider), and MSSP (Managed Security Service Provider) to quickly recover from the incident.

Objectives

  1. Provide leadership and guidance based on “NIST Special Publication 800-61, Computer Security Incident Handling Guide” and Notion Digital Forensics Procedures (NDFP).
  2. Conduct rapid forensic analysis on affected servers to identify and eliminate malware.
  3. Collaborate with the company’s IT teams, MSP, and MSSP to expedite recovery and return to normal operations.

Approach

Notion Digital Forensics worked closely with the company’s specialist IT teams, MSP, and MSSP, providing leadership and expertise in handling the ransomware incident. We utilised a networked forensics system to perform fast forensic analysis on approximately 100 servers and workstations, swiftly tracking down malware infections.

Results

By leveraging our experience in incident response, we were able to reduce guesswork and guide the company’s IT teams, MSP, and MSSP, enabling them to get back online sooner than expected. While it’s possible that the company could have resolved the issue eventually, our involvement significantly accelerated the recovery process.

The teams appreciated Notion Digital Forensics’ professionalism and input during the incident response. Our expertise in leading incident response events and collaboration with the client’s IT teams, MSP, and MSSP proved invaluable in restoring operations quickly and efficiently, ultimately minimising the business impact of the ransomware attack.

About Notion Digital Forensics

Notion Digital Forensics are technical experts in cybersecurity, e-discovery, and digital forensic investigation and cyber-defence for business and lawyers.

Other Case Studies

Get expert advice for your case. Contact us now

or phone us on 02 8006-0855

Important Notice

Preserving Confidentiality

The case study presented above is based on real events. To protect the identities of the parties involved, we have altered certain facts and details. These changes may be minor or significant and may include the inclusion of false information. Our aim is to maintain confidentiality for those involved.

Seek Customized Advice

Cybersecurity and digital forensics are specialised fields with various options and trade-offs. The information provided on this website may not be applicable to your specific situation. It is highly recommended that you seek tailored advice from an expert before taking any action. We are cyber security specialists, but we may not be your cyber security specialists. Seek professional advice.