Cyberattack - a company case study with real lessons

Cybersecurity
August 7, 2026

At 8:17 a.m., the finance manager can’t open the shared folder with contracts. Ten minutes later, the sales team loses access to the CRM system, and a message about encrypted files appears on several screens. A cyberattack - a business case like this rarely starts with an obvious failure. It usually starts with a convincing email, a stolen password, or a device that hasn’t received a critical update.

For a small or medium-sized company, such an incident is not just a technical problem. It blocks sales, payments, customer service, and internal coordination. The crucial question is not whether the organization will be attacked, but how quickly it will recognize the threat, limit the damage, and regain control of its environment.

Cyberattack - a business case: how the incident begins

We consider a typical scenario for a company with about 60 employees, a central file server, cloud mail, and a hybrid work mode. An employee from the administrative team receives an email that looks like a notification from a courier. The sender’s address is similar to a real one, the text is well-written, and the attachment supposedly contains a delivery document.

After opening it, the user sees an empty file and continues working. However, in the background, malicious code collects access data and establishes a connection to an external server. The attackers do not encrypt the files immediately. They spend days scanning the network, looking for administrator accounts, shared folders, backups, and systems with valuable information.

This delay is the reason why many organizations believe that the attack occurred suddenly. In reality, the critical moment often occurs a week after the first compromised account. Once encryption begins, the business has hours, and sometimes minutes, to prevent it from spreading to other systems.

The first 60 minutes determine the extent of the damage

The most common mistake is for employees to try to “fix” the problem themselves. Restarting a computer, re-entering a password, or sending the suspicious file to colleagues can make the situation worse. When an incident is suspected, the first task is containment, not recovery.

The compromised device should be isolated from the network, without being shut down abruptly, unless otherwise instructed by specialists. This cuts off the ability of the attack to reach file servers, other workstations, and cloud accounts. In parallel, the IT team checks for active user sessions, unusual logins, changes in access rights, and signals from antivirus or monitoring systems.

The decision to stop an entire segment of the network always has a price. A temporary interruption of work can affect dozens of employees, but leaving a suspicious environment online can lead to the encryption of all company information. The choice depends on the evidence, the criticality of the systems, and the degree to which the network is segmented.

In this case, the IT team finds that the compromised user account was accessing the mail from an unknown location. An attempt to access the file server outside of normal business hours was also detected. The account is locked, its active sessions are terminated, and access to key shared folders is temporarily restricted. This does not resolve the incident, but it interrupts its most dangerous phase.

Diagnostics should provide facts, not assumptions

After the initial risk is contained, comes the hard part: what exactly is affected? It is not enough to remove the suspicious file from one computer. It is necessary to trace the attack path - from the first login to the systems that the attacker reached.

The team checks logs from the firewall, identity systems, mail, endpoints, and servers. They look for newly created accounts, unusual email forwarding rules, changes to groups with rights, mass file renaming, and links to unknown addresses. They compare times, IP addresses, and user actions to separate the real trace from the normal work noise.

There is also a business question here. If there are indications of access to personal data, contracts, financial information or customer records, management should be involved immediately. In certain circumstances, GDPR obligations, customer contracts or sector requirements may arise. The assessment should not be postponed, but neither should it be panicked before the facts are established.

Recovery does not start with pressing Restore

Backups are a basic protection, but only if they can be restored quickly and are protected from compromise. If the backup environment is constantly accessible with an administrative account from the main network, it can also be affected. If the copies are not tested, the company will only know if they are working at the most inopportune moment.

In this case, there are backups available, but the last backup job was successful 18 hours ago. The company must choose between a faster rollback to this copy and the risk of losing some of the latest changes. For critical data, it is possible to apply a more precise recovery, but it requires more time and careful checking for infected files.

It is a good practice to restore systems in order of priority. Identity and access, secure communication, core business applications and data without which work stops are restored first. Then come secondary services. Before each system is returned to a production environment, it should be checked for vulnerabilities, unauthorized changes and updates.

Not every attack requires a complete restoration of the entire infrastructure. Sometimes cleaning and reissuing accesses is enough. However, if compromised administrator credentials are suspected, the safer approach is to build a clean environment and replace passwords, keys and certificates. This is a slower option, but reduces the risk of the attacker remaining undetected in the system.

What changes the company after the incident

The real value of a company case study is not in the fact that work is restored, but in the changes afterwards. The company is introducing multi-factor authentication for email, VPN access, and administrative accounts. Rights to shared folders are reviewed because employees often have more access than they actually need.

The network is divided into separate segments so that a compromised user device does not directly reach servers and backup systems. Endpoints receive centralized management of updates and protection. Notifications are introduced for risky logins, changes to email rules, and attempts to access files in bulk.

Training for people is also changing. A one-time presentation once a year is not enough because phishing messages are constantly adapting. Short, regular training sessions with real-world examples are more useful: a fake invoice, a request to change a bank account, an urgent message from a manager, or an invitation to a shared document.

Finally, a response plan is created that indicates who makes decisions, who communicates with employees, how a system is isolated, and which business processes are restored first. The plan should not be in a folder that cannot be accessed in the event of a crash. It should be clear, up-to-date, and tested with a realistic scenario.

Prevention is a measurable operational effort

Security is not provided by a single product. It is a combination of monitoring, access control, secure backups, updates, clear procedures, and timely response. For an organization without an internal specialized team, this means the need for a partner who monitors the environment constantly, not only when a user has already reported it.

Helpdesk Bulgaria works with this approach: prevention and support are related processes. When devices, cloud services, network, and backups are managed in a coordinated manner, signs of risk are seen earlier and disaster recovery is more predictable.

A useful next step isn’t waiting for a warning message on your screen. Make sure you know where your backups are, who has administrative rights, and who will respond in the first hour of an incident. Three clear answers can save days of downtime.


Tags:
#cyberattack for companies#cyberattack response#ransomware case#IT incident management#cybersecurity for business
Share this article:

Get in touch

Related Articles

All posts